Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
LI

Sr. Compliance Officer

LanceSoft Inc
🇨🇦 Canada
Hybrid
Senior
3 weeks ago
$52.63 / hour
  • Regulatory Compliance
  • Risk Management
  • Change Management
  • Disaster Recovery
  • GDPR
  • CCPA
  • SOC2
  • FedRAMP
  • PCI DSS
  • AWS
  • Azure
  • GCP
  • CISA
  • CISM
  • CRISC
  • NIST
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Job Title:  Senior Cloud Services Compliance Officer
Location:   Ottawa ON,K2V 1C2, Hybrid - 3 days per week in the office
Duration:   12+ months
Payrate:     $45/hr. - $52/hr. on (W2)
Shift:          9:00 a.m. – 5:00 p.m. EST
 
Position Summary
  • The Senior Cloud Services Compliance Officer is responsible for leading and overseeing compliance initiatives for Cloud Services for a cloud services domain level, with a focus on managing complex audit processes, customer security and compliance assessments, regulatory compliance, and internal security and privacy programs.
  • This individual will collaborate with senior management of a business units, and external stakeholders to ensure compliance with internal policies, industry standards, and regulatory requirements across multiple jurisdictions.
  • The Sr. Compliance Manager will also play a critical role in supporting strategic direction for compliance practices, driving continuous improvement, and ensuring robust risk mitigation in Cloud Services operations.
 
Key Responsibilities:
1. Cybersecurity Compliance Programs:
  • Serve as the point of contact for managing all compliance and audit activities related to assigned Cloud Services, acting as a trusted partner to the assigned Cloud Services.
  • Lead interactions with both internal and external auditors (including external regulatory bodies, internal Client auditors, and third-party auditors), ensuring efficient and effective audit processes.
  • Support the development, implementation, and maintenance of compliance programs to meet the organization's strategic objectives and regional regulatory requirements.
 
2. Audit Strategy and Execution:
  • Lead the preparation and execution of internal and external audits across assigned Cloud Service, ensuring compliance with established corporate policies/standards, industry standards, and regulatory requirements.
  • Develop and implement audit strategies for the assigned Cloud Services, ensure audits are proactive, risk-based, and aligned with business priorities, while ensuring a continuous improvement approach.
 
3. Advanced Compliance and Risk Management:
  • Lead and enhance the risk management and improve controls for assigned Cloud Services, ensuring compliance with both internal policies and external regulatory requirements.
  • Support and improve the Cloud Services Change Management, Business Continuity Plan (BCP), and Disaster Recovery (DR) related controls to ensure compliance with corporation policies/standards and business continuity regulations and best practices.
  • Maintain and update key governance, risk management and compliance documentation, including ISMS 27001, IS27017/18 mandatory documents, ensuring alignment with corporate policy and evolving industry standards.
 
4. Policy Development and Process Improvement:
  • Support the develop, review, and implement cybersecurity compliance policies, standards and procedures to ensure continuous improvement of internal controls, audit readiness, and risk mitigation.
  • Recommend and drive the implementation of cybersecurity policies and standards aimed at improving Cloud Services’ compliance posture, ensuring policies are aligned with business objectives and regulatory expectations.
  • Regularly assess and refine compliance workflows to optimize efficiency and alignment with evolving compliance frameworks.
 
5. Global Compliance Management:
  • Partner with cross-functional teams in analyzing cybersecurity compliance requirements cross functions, ensuring adherence to local and international regulations (e.g., GDPR, CCPA, etc.).
  • Support the development of global compliance strategies, ensuring supported Cloud Services units are aware of evolving global cybersecurity and privacy laws and that cross-border data transfers are compliant with corporate policies and standards.
 
6. Support and Advisory for Cloud Services Units:
  • Provide cybersecurity compliance guidance and support to sales, presales, product management, and other business units on cybersecurity compliance-related matters, including RFPs, RFIs, security & compliance questionnaires, and client security inquiries.
  • Be the primary advisor to assigned Cloud Services on complex compliance and security topics, providing recommendations for risk mitigation, process improvements, and regulatory adherence.
 
7. Customer and Stakeholder Engagement:
  • Engage directly with key customers to address complex compliance and security questions, and to support ongoing trust-building initiatives.
  • Ensure the communication of compliance requirements and audit results to relevant stakeholders, including customers, partners, and regulators.
 
8. Continuous Monitoring and Reporting:
  • Oversee the ongoing monitoring of compliance programs to ensure that they remain effective and aligned with the organization’s security goals and business objectives.
  • Develop and provide regular compliance reports to senior management, highlighting audit results, risk areas, and the status of corrective actions.
 
Minimum Requirements:
  • 7+ years of experience in cybersecurity compliance and certifications, preferably within cloud services environments.
  • Proven experience independently leading and conducting internal and external audits, including risk assessments and remediation activities.
  • Strong knowledge and experience working with industry-leading information security standards, such as: IS27001, IS27017/27018, SOC2, FedRAMP, CSA, PCI-DSS and Data Privacy Regulations (e.g. GDPR)
  • Solid understanding of cloud environments (e.g., AWS, Azure, GCP) and cloud security fundamentals.
  • Demonstrated ability to effectively communicate and collaborate with a broad range of internal and external stakeholders, including business units, senior leadership, auditors, and regulators.
 
Top Required Skills
  • 7+ years of experience in cybersecurity compliance, certifications, and audit management within cloud-services environments.
  • Strong attention to detail, excellent organizational and multitasking skills, and the ability to work independently while leading and conducting internal and external audits. (looking for 5 years of experience leading audit)
  • Senior-level capability to quickly learn new processes, take ownership of the audit lifecycle, and manage audits independently from planning through completion.
  • Demonstrated ability to communicate effectively and collaborate with a broad range of internal and external stakeholders.
  • Strong knowledge of and hands-on experience with leading information security standards and regulatory frameworks, including IS27001, IS27017/27018, SOC 2, FedRAMP, CSA, PCI DSS, and data privacy regulations such as GDPR
  • They will be part of an international team of 10. For this assignment, their primary responsibility will be supporting Canadian audits, while also collaborating with global stakeholders.
 
Preferred Qualifications
  • Experience: 7-10 years of experience in cybersecurity compliance, risk management, or information security. Experience in cloud computing or SaaS environments is highly preferred.
  • Certifications: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or similar certifications are strongly preferred.
  • Expertise in Standards & Frameworks: Strong knowledge and practical experience with IS27001, SOC 2, PCI DSS, and other relevant frameworks (e.g., GDPR, NIST).
  • Leadership Skills: Proven experience in leading complex audits, with the ability to work closely with senior leadership, legal, data privacy, operations, and technical teams.
  • Communication Skills: Excellent written and verbal communication skills, with the ability to present complex compliance and audit findings to both technical and non-technical stakeholders.
  • Strategic Thinking: Ability to take a strategic approach to compliance management, with a focus on risk mitigation, continuous improvement, and aligning compliance initiatives with business goals.

Sr. Compliance Officer · LanceSoft Inc

Auto apply with Likeremote