Job Description
📋 Description Support governance and policy management: assist policy creation and maintenance. Contribute to risk assessments: help identify risks and track treatment plans. Assist with audits: gather evidence and coordinate for ISO 27001, SOC 2, PCI DSS. Aid in vendor risk assessment: monitor third-party security controls and maintain risk reports. Cross-functional collaboration: align security controls with business objectives. Handle customer inquiries: respond to security/privacy RFIs and RFPs. 🎯 Requirements Typically 3+ years of relevant work experience. IT risk management, governance, or similar InfoSec role. Experience supporting security policies, risk assessments, or audits for SaaS. Cloud security familiarity (AWS, Azure, GCloud). Knowledge of GDPR and data privacy laws (CCPA, PIPEDA). ISO/IEC 27001 family, ISO 9001, SOX, DORA, NIST CSF, SOC 2 & PCI DSS. 🎁 Benefits Hybrid work: three days in the office (Tue-Thu) with flexibility. ESPP at 15% discount. Health benefits. Paid vacation, Docebo Days, floating holidays, and your birthday off. Family-first benefits for time with your kids. Employee Resource Groups and company-wide events.