03 Oct
|
Docebo
|
Toronto
Artificial Intelligence. We’re an AI-powered learning platform that helps organizations create, deliver, and manage training all in one place.
But our real mission goes deeper: we help teams move faster, work smarter, and focus on the work that truly matters. Our platform is built with intelligent, time-saving tools that personalize learning, eliminate busywork, and turn training from a checkbox into a superpower. Join 900+ Docebians around the world and help us reinvent the way people learn, because learning never stops.
As our Information Security Compliance Specialist , you will be the front-line champion and strategist safeguarding Docebo's security posture and driving customer trust. You will bridge the gap between technical rigor and client confidence, translating complex compliance frameworks (like NIS2, NIST, GDPR, ISO, SOC, and FedRAMP) into competitive advantages. In this role, your work directly accelerates deal cycles, empowers our sales and legal teams, and ensures our global SaaS ecosystem remains fortress-secure.
Champion Customer Trust: Respond to prospect and customer security requests, review RFIs/RFQs, and deliver flawless responses regarding Docebo's compliance and security posture.
Drive Compliance & CAPs: Tackle customer security questionnaires head-on and collaborate internally to establish Corrective Action Plans (CAPs) for outstanding requirements.
Power Legal Alignment: Partner with the Docebo legal team to review Customer Agreements, Terms & Conditions, and Data Processing Addendums, seamlessly mapping client requirements to standard processes.
Spearhead Audit Readiness: Lead and support annual customer audits while partnering with the GRC team during SOC2, ISO (27001, 9001, 42001), and NIS2 assessments.
Automate for Efficiency: Leverage AI tools and basic programming capabilities to automate internal processes and optimize compliance workflows. Organize internal compliance documentation and publish up-to-date materials directly to Docebo’s "trust pages" using platforms like Vanta.
Evaluate Vendor Risk: Support third-party vendor risk assessments, monitor security controls, and maintain management reporting dashboards to mitigate external supplier risks.
Proven SaaS Expertise: 4+ years of hands‑on experience supporting security activities, audits, and compliance in SaaS environments, backed by a Bachelor's degree in Computer Science or a related field. Solid working knowledge of cloud environments (AWS, Azure, GCloud) alongside data privacy regulations like GDPR, CCPA, and PIPEDA.
Framework Fluent: Deep familiarity with security and compliance standards including ISO/IEC (27001, 27017, 27018, 27701, 9001, 42001), SOC 2, PCI, NIS2, and CFR21 Part 11.
Technical Savvy & Automation Mindset: Basic coding skills and hands‑on experience with modern security governance platforms like Vanta and 1UP.
Articulate Communicator: Exceptional written and verbal English communication skills, with a knack for translating complex technical concepts into explicit customer answers.
Bonus Points Certified Specialist: Holding certifications such as CISA, CIPP (or CIPT),
or CompTIA Security+.
Advanced Academic Background: Specialized degree focus in Information Security or Auditing. Step 1: We’ll kick things off with a 30‑minute video call with a member of our Talent team. A 60‑minute video call with the hiring manager, where they’ll dig deeper into your experience, approach, and what excites you most about this opportunity.
A 45‑minute practical case study/technical discussion with key members of the Compliance & GRC team. A final 30‑minute chat with our Security Leadership team to discuss long‑term vision, growth, and team alignment. Great work can happen anywhere but coming together helps us go further.
Our team spends three days a week in the office (Tuesday‑Thursday) to collaborate, solve problems, and learn from each other. With flexibility the rest of the week, it’s a balance designed to help everyone do their best work and keep growing.
Rewarding Impact: We lead with competitive pay to reward the impact, skills and traits that fuel our success. We build a culture of trust and empowerment by designing our rewards and benefits with transparency, equity, and flexibility, enabling our people to do their best work and stay for the long haul. Rest, Relax, Repeat: Rest and recharge with paid vacation days, two company‑wide Docebo Days, floating holidays for cultural celebrations, and your birthday off!
Fun fact: we had 30 Docebian babies join the family in 2025!
Connections That Count: Connect with global communities through our Employee Resource Groups (including PRIDE, DWA, BIDOC and Green Ambassadors) and company‑wide events that keep the fun rolling all year long. #
📌 Information Security Compliance Specialist (Toronto)
🏢 Docebo
📍 Toronto