- Company Name
- Gore Mutual Insurance
- Job Title
- Manager, Security Compliance & Engineering
- Job Description
-
Job title: Manager, Security Compliance & Engineering
Role Summary: Lead the organization’s security governance, compliance, and engineering functions, managing a technical team to implement and maintain secure policies, frameworks, and tooling across cloud and on‑prem environments, while overseeing third‑party risk management and project delivery.
Expectations: Deliver end‑to‑end security program excellence, ensuring alignment with NIST, CIS, PCI‑DSS, AMF, and PIPEDA; maintain regulatory compliance, reduce third‑party vulnerabilities, modernize security posture, and drive executive‑grade security strategy, roadmap, and reporting.
Key Responsibilities:
• Manage company‑wide security governance and compliance program.
• Create, review, implement, and update security policies and procedures aligned with Enterprise Security Risk Framework.
• Conduct internal compliance assessments against PCI‑DSS, AMF, PIPEDA, and other standards.
• Monitor IT systems for policy compliance and oversee vulnerability and threat assessments.
• Operate and evolve the 3rd Party Risk Management Framework, coordinate with ERM, conduct vendor assessments, and advise remediation.
• Lead security engineering initiatives: design and deploy solutions, maintain architecture diagrams, and collaborate on product decisions.
• Provide technical design input, define strategy, OKRs, priorities, and key metrics for the Security Engineering team.
• Hire, develop, and lead an inclusive, high‑performing technical team.
• Keep threat intelligence feeds current, manage vulnerability management program, work with infrastructure teams on patch SLAs.
• Oversee delivery of security projects across the technology stack, applying PM practices, tracking via JIRA or equivalent, and reporting progress and risks.
Required Skills:
• 10+ years in technical security management, with 5+ years in hands‑on cybersecurity solution implementation, administration, and operation.
• 3+ years of GRC experience in large business environments.
• Broad cybersecurity domain expertise: threat hunting, vulnerability management, forensics, penetration testing.
• Security design and architecture in cloud (Azure, AWS), including posture management.
• DevSecOps knowledge and ability to embed security in SDLC pipelines.
• Privileged access management experience.
• Proficiency with Microsoft security stack (Defender, CoPilot for Security, M365 E5, Purview).
• Leadership skills: people management, performance development, inclusive team building.
• Strong communication for strategy, roadmap, metrics, and stakeholder engagement.
Required Education & Certifications:
• Diploma or bachelor’s degree in Information Technology, Computer Science, or Cybersecurity Management.
• Relevant industry certifications (e.g., CISSP, CISM, CISA, CCSP, CEH, OSCP, Azure/AWS security certifications) preferred.