- Company Name
- Morson Edge (Canada)
- Job Title
- Senior Compliance Officer
- Job Description
-
**Job Title:** Senior Compliance Officer
**Role Summary:**
Lead and manage cybersecurity compliance for cloud services, overseeing internal and external audit cycles, risk management, policy development, and regulatory adherence across multiple jurisdictions. Serve as the primary compliance liaison for auditors, regulators, and business stakeholders, driving continuous improvement in security controls and audit readiness.
**Expectations:**
- Ensure 100 % compliance with applicable security standards (ISO 27001, ISO 27017/18, SOC 2, FedRAMP, PCI DSS, GDPR, CCPA).
- Deliver timely audit reports, risk mitigation plans, and remediation status updates to senior leadership.
- Maintain robust governance, risk, and compliance documentation.
- Advise cross‑functional teams on compliance requirements and support customer security engagements.
**Key Responsibilities:**
- Act as main point of contact for all cloud‑services compliance and audit activities.
- Plan, coordinate, and execute internal and external audits; lead engagements with regulatory bodies, internal audit, and third‑party auditors.
- Develop, implement, and sustain cybersecurity compliance programs aligned with corporate objectives and regional regulations.
- Design risk‑based audit strategies and drive continuous improvement initiatives.
- Lead risk management initiatives; enhance security controls, change management, BCP, and DR processes.
- Maintain ISMS documentation (ISO 27001) and related artifacts (ISO 27017/18).
- Support policy development, review, and implementation of compliance standards, procedures, and workflows.
- Collaborate with cross‑functional teams to assess and address global compliance and privacy requirements.
- Provide compliance guidance to sales, presales, product, and other business units; support RFPs, RFIs, and customer security questionnaires.
- Engage with customers on compliance inquiries and trust‑building initiatives.
- Oversee continuous monitoring of compliance programs; prepare and present compliance reports to senior management.
**Required Skills:**
- 7+ years in cybersecurity compliance within cloud services or SaaS environments.
- Proven experience leading internal/external audit cycles and risk‑based remediation.
- Deep knowledge of ISO 27001/17/18, SOC 2, FedRAMP, CSA, PCI DSS, GDPR, CCPA, and NIST frameworks.
- Solid understanding of AWS, Azure, GCP security fundamentals.
- Strong stakeholder management and communication skills, capable of translating technical findings for non‑technical audiences.
- Strategic mindset focused on risk mitigation and continuous improvement.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Computer Science, or related field.
- Professional certifications: CISA, CISM, CRISC, or equivalent strongly preferred.
---