PACT is a General Partnership of Alberici, Amico, Kenaidan and Obayashi delivering the Toronto Pearson Accelerator program. The Manager, Security & Compliance owns PACT's information security programme, combining ownership with hands-on execution: the role personally operates controls, collects evidence, authors policy and works in the Microsoft 365 tenant, and carries no direct reports. The role owns the ISO/IEC 27001:2022 certification initiative targeted at Q1 2027 and the parallel SOC 2 Type 2 initiative, run as one control programme with two reporting outputs, and contributes to security architecture and strategy through input into platform security standards and the multi-year security roadmap.
Because member companies second staff and retain the endpoints they issue, endpoint management, HR and office physical security are not centralized, and control ownership splits across PACT tenant-managed, inherited, shared and client-owned scopes.
RESPONSIBILITIES
Programme Ownership and ISMS Documentation
- Own the ISO/IEC 27001:2022 certification initiative to the Q1 2027 target and the SOC 2 Type 2 initiative
- Run both as one control programme with two reporting outputs, sharing roughly 75-80 percent of control intent
- Author, approve, publish, version-control and maintain the information security policy suite, retaining acknowledgement records
- Author and maintain the Statement of Applicability across the applicable control set, justifying inclusion, exclusion and inheritance
- Operate the document-control procedure, competence matrix, improvement log and corrective-action register in a governed SharePoint library
- Represent certification and attestation status accurately in internal, member-company, client and external communications
- Report status to the IT Steering Committee and provide input to security budget, tooling spend and vendor selection
Risk Management and Control Operation
- Define a risk methodology covering acceptance criteria, impact and likelihood scales, ownership and treatment options
- Establish and maintain the risk register through formal risk assessment, sustained as a live record
- Produce and track the risk treatment plan, verifying control effectiveness rather than accepting reported completion
- Operate annual and event-triggered reassessment on new SaaS, tenant change, incident, audit finding or joint-venture change
- Maintain the evidence inventory, coordinate the quarterly privileged, guest and application access review cycle, and review logs
- Ensure audit logging and retention across the tenant meet certification and investigative requirements
- Ensure backup and recovery controls are evidenced, covering schedule, immutability, retention and restore testing
- Maintain the information asset register and baseline configuration review, recording drift and approvals
Third-Party and Member-Company Assurance
- Maintain the supplier security register and review cadence covering the ICT supply chain and managed service provider
- Review Entra application registrations as privileged suppliers, documenting owner, purpose, permission scope and review date
- Maintain the control-ownership split across PACT tenant-managed, inherited, shared and client-owned scopes
- Collect and refresh member-company attestations for inherited endpoint, AV/EDR, patching, physical security and HR controls
- Coordinate shared controls with member-company IT and security teams, covering classification, awareness and business continuity
- Maintain the joiner, mover and leaver process with each member company, and manage dual member-company and PACT identities
Security Architecture, Operations and Tenant Hardening
- Provide input into platform security architecture, security standards and the multi-year security roadmap
- Assess new platforms, integrations and tenant changes against security architecture principles and target-state control design
- Operate and evidence the Entra ID Conditional Access posture: MFA enforcement, legacy authentication blocking and glass-break accounts
- Hold the managed detection and response provider to service expectations for Microsoft 365 monitoring and response
- Tune Microsoft Defender for Office 365 anti-phishing, anti-malware, Secure Links and Safe Attachments with the Azure 365 Administrator
- Define Purview label, DLP and retention policy requirements configured by the Azure 365 Administrator, and drive classification roll-out with the SharePoint Administrator
- Govern privileged access, with privileged access management deployed and operated by the Azure 365 Administrator
- Coordinate patch and vulnerability activity, act as security voice in change advisory, and direct the managed service provider
Incident Response, Awareness and Improvement
- Author and publish the incident response plan, event triage matrix, vendor runbook and evidence-preservation procedure
- Publish and promote a security event reporting channel for all users, with defined response expectations
- Run and document tabletop exercises and lead post-incident review through to verified corrective-action closure
- Administer the security awareness platform and monthly programme, harvesting completion and new-hire onboarding records
- Deliver awareness uplift for privileged users and leadership, and coordinate analytics governance with the Manager, Data & Innovation
- Own and govern the AI-use policy through access gating and record-keeping, with Copilot platform readiness and licensing owned by the Azure 365 Administrator
Certification, Audit Readiness and Reporting
- Engage external assessors and consultants, and prepare for Stage 1 and Stage 2 certification assessment
- Liaise with external consultants and the certification body, assembling evidence packs and tracking findings to closure
- Drive SOC 2 Type 2 readiness across the Security, Availability and Confidentiality criteria and operate quarterly self-assessment
- Prepare for, coordinate and remediate against audits without performing the ISMS internal audit, as Clause 9.2 requires independent auditors
- Support the internal audit programme hosted under Quality / QMS or co-sourced externally
- Report quarterly on phishing-simulation click rate, MFA and phishing-resistant coverage, patch mean-time-to-remediate by severity, audit-log retention coverage, evidence completeness and corrective-action closure
Qualifications
- 7-10 years experience in information security, IT compliance, governance risk and compliance, or audit
- Bachelor's degree in information technology, information security, risk management or a related discipline preferred
- Demonstrated ownership of an ISO 27001 ISMS or equivalent such as SOC 2, NIST CSF or ISO 27002
- Hands-on Microsoft 365 security administration across Entra ID Conditional Access, Microsoft Purview and Microsoft Defender
- Contribution to security architecture, security standards and multi-year security roadmap development at manager level
- Practical risk assessment experience, including facilitating workshops and maintaining a risk register and treatment plan
- Policy authoring through approval and publication, and evidence collection for an external certification body
- Third-party and vendor security assessment experience, with input to vendor selection and security budget
- Experience reporting to a steering committee and coordinating across organisations that do not report to the role
- Certification such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, CISSP or SC-400 preferred
- SOC 2 Type 2 readiness, major capital program delivery, joint-venture or multi-employer environments, and PIPEDA exposure considered assets
Key Deliverables
- ISMS documentation set and information security policy suite published and maintained under document control
- Statement of Applicability authored and maintained across the applicable control set, with inheritance justified
- Live risk register and risk treatment plan maintained through formal risk assessment and scheduled reassessment
- Incident response plan published, event reporting channel operating, and response tested through regular tabletop exercise
- Security architecture input and multi-year security roadmap maintained and reviewed with the IT Steering Committee
- Evidence inventory maintained, quarterly KPI reporting into management review, and readiness sustained against the Q1 2027 target
WORKING CONDITIONS The position will be based at our office in Mississauga, Ontario, with visits to the Airport site as required. Your work schedule will be Monday to Friday during regular office or site hours. At times, operational needs may require work outside these hours, with reasonable notice provided.
All schedule or on‑call adjustments will comply with applicable employment standards legislation. It is mandatory for all employees to complete a Criminal Background check and successfully attain a Restricted Access Identity Card (RAIC) upon joining the company.
PACT is an equal opportunity employer and is committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act. We are committed to providing an inclusive and barrier free candidate experience and work environment. If you require accommodation to apply or if selected to participate in an assessment process, please advise Human Resources.
📌 Security & Compliance Manager (Ontario)
🏢 PACT
📍 Ontario