Senior Information Security, Risk & Compliance Specialist
Who we are:
Who you are:
The Senior Information Security, Risk and Compliance Specialist collaborates with cross-functional teams at Geotab to ensure security compliance, promote security best practices, and mitigate security risk throughout the organization. Key accountabilities include leading and overseeing internal and external security audits against systems, processes, and network infrastructure, managing compliance with regulatory frameworks including SOC 2 Type 2, ISO 27001, NIST SP 800-53, and FedRAMP, developing and maintaining security policies, standards, and governance documentation, conducting hands-on technical security risk and supply chain risk assessments, assessing and managing third-party and vendor security risk across the organization.
What you'll do:
The Senior Information Security, Risk and Compliance Specialist collaborates with cross-functional teams at Geotab to ensure security compliance, promote security best practices, and mitigate security risk throughout the organization. Key accountabilities include leading and overseeing internal and external security audits against systems, processes, and network infrastructure, managing compliance with regulatory frameworks including SOC 2 Type 2, ISO 27001, NIST SP 800-53, and FedRAMP, developing and maintaining security policies, standards, and governance documentation, conducting hands-on technical security risk and supply chain risk assessments, assessing and managing third-party and vendor security risk across the organization.
How you'll make an impact:
-
Provide information assurance and subject matter expertise in support of panels, committees, and working groups.
-
Ensure security compliance with legal and regulatory standards including SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP.
-
Lead and oversee internal and external security audits against systems, processes, and network infrastructure; coordinate evidence collection, auditor liaison, and remediation tracking.
-
Develop, update, and revise information security policies, standards, and procedures.
-
Serve as a subject matter expert in security risk management with hands-on experience in technical security risk assessments and supply chain risk assessments.
-
Assess and manage third-party and vendor security risk including vendor assessments and ongoing monitoring.
-
Collaborate with and advise internal departments to improve security-related risks and embed security controls into business processes.
-
Act as a technical mentor and SME to junior team members; serve as a point of escalation for complex security issues and initiatives.
-
Continuously develop expertise across Geotab's security programs, internal systems, and data infrastructure, leveraging that knowledge to provide informed, practical security consulting to business and technical stakeholders.
-
Adopt and champion the use of AI tools and techniques to enhance security workflows, automate compliance tasks, and improve risk analysis capabilities; proactively learn and apply evolving AI capabilities.
-
Support Geotab global strategic initiatives and contribute to the maintenance of the departmental SOPs.
-
Consistently demonstrate Geotab's Core Values in all daily work and interactions.
What you'll bring to the role:
-
5-8 years of experience in security evaluation/analysis and/or risk assessments within a technology-focused industry.
-
Working knowledge of system and network security engineering best practices.
-
Deep familiarity with security compliance frameworks including SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP; including certification/accreditation processes and industry reporting requirements.
-
Experience leading end-to-end security audits including planning, evidence collection, auditor liaison, and remediation tracking.
-
Demonstrated experience in third-party and supply chain risk management programs.
-
Expertise in common security tool use and GRC platforms.
-
High accuracy and meticulous attention to detail; able to work under pressure and respond to fast-changing priorities and deadlines.
-
Highly organized with the ability to manage multiple tasks and projects simultaneously.
-
Excellent verbal and written communication skills, including comfort with delivering presentations and training.
-
Strong interpersonal and relationship-building skills; a strong team player able to engage with all levels of the organization.
-
Strong analytical skills with the ability to problem-solve with well-judged decisions.
-
Strategic mindset with a keen sense of priorities and the ability to pivot as the landscape changes.
-
Technical competence using software programs including Google Suite for Business (Sheets, Docs, Slides).
-
Entrepreneurial mindset; comfortable in a flat organization.
-
Willingness to adopt and learn AI tools to streamline security and compliance workflows; open to integrating AI-driven insights into risk analysis, audits and decision-making.
-
Post-Secondary Diploma/Degree specialization in Computer Science, Engineering, or a related field.
-
Equivalent combination of education and/or work experience in related field may be substituted.
-
Professional certification in Information Security from a reputable institution highly valued (e.g., CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor, ISO 42001, certifications).
-
5-8 years of required previous experience in security evaluation/analysis, risk assessments, and/or compliance within a technology-focused industry.
Why job seekers choose Geotab:
Flex working arrangements
Home office reimbursement program
Baby bonus & parental leave top up program
Online learning and networking opportunities
Electric vehicle purchase incentive program
Competitive medical and dental benefits
Retirement savings program
*The above are offered to full-time permanent employees only
How we work:
The annual base salary for this position is the expected annual salary for this role, and may be subject to change. Geotab offers various perks and benefits and other compensation components that an individual may be eligible for. The actual base salary for this position depends on a variety of factors such as but not limited to skills, qualifications, education and overall experience, including the location the applicant lives while performing the job. This also includes equity with other team members and alignment with local market data. All offers of employment are contingent upon proof of eligibility to work and the individual's ability to pass a background check.
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
- Current company
- LinkedIn Profile optional
- Github URL optional
- Portfolio URL optional
- Other Website optional
- How did you hear about Geotab? choose one
- How did you hear about this job opportunity? choose one
- City & Country in which you are currently located
- Are you legally authorized to work in the region in which the position you are applying for is located? choose one
- Will you now or in the future require sponsorship to be able to work in the Country in which the position you are applying for is located? choose one
- Do you currently work for a partner or reseller of Geotab? choose one
- Are there any post-employment restrictions from your current or most recent employer (such as hiring restrictions or confidentiality obligations)? choose one
- What are your compensation expectations for the role you are applying for?
- Will you consent to a background check? (All offers of employment are contingent on passing a background check) choose one
- What date would you be available to onboard with Geotab?
- Were you previously employed with Geotab? choose one
- If you are a veteran of the armed forces in your country and would like to identify this fact to our recruiting team, please write "YES" in the text box below. choose one · optional