About this role
Main Responsibilities
- Conduct cybersecurity compliance reviews throughout the Lightspeed system lifecycle, including TRR, PDR, CDR, and other program milestones
- Gather, analyze, and maintain compliance evidence through interviews, documentation reviews, walkthroughs, and control validation activities
- Interpret cybersecurity and regulatory requirements and assist in translating them into actionable compliance activities
- Collaborate with Engineering, Product Security, IT, and testing teams to verify cybersecurity controls are implemented and effective
- Track compliance activities, findings, remediation efforts, and action items
- Support implementation and maintenance of cybersecurity controls required to meet applicable obligations
- Monitor changes to cybersecurity standards and regulations and support compliance updates
- Prepare and maintain compliance documentation, assessment records, evidence repositories, and reports
- Work collaboratively with cross-functional teams to address compliance concerns and promote awareness
Education and Experience
- Diploma or Bachelor's Degree in Computer Science, Engineering, IT, Cybersecurity, or related field, or equivalent experience
- 3+ years supporting cybersecurity, compliance, governance, risk management, audit, assurance, or information security programs
- Experience assessing cybersecurity controls and compliance requirements
- Experience with NIST 800-53, NIST 800-171, ISO 27001, CMMC, or similar frameworks
- Experience coordinating with technical and business stakeholders
- Strong analytical, organizational, and communication skills
- Experience supporting audits, assessments, certifications, or compliance reviews is an asset
- Certifications such as CISA, CRISC, Security+, CGRC, or ISO 27001 Lead Auditor are assets
Specialized Knowledge, Skills and Abilities
- Knowledge of cybersecurity governance, risk management, compliance, and control assurance principles
- Experience assessing cybersecurity controls, identifying compliance gaps, and supporting remediation activities
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Strong interpersonal, organizational, and stakeholder management skills
- Experience supporting audits, compliance assessments, certification activities, or control validation efforts is an asset
- Knowledge of NIST, CMMC, ISO 27001, or similar frameworks
- Experience reviewing technical documentation, system designs, security controls, and implementation evidence
- Knowledge of CNSSP-12 or CAIQ is an asset
- Experience with GRC, audit management, evidence management, or compliance tracking tools is an asset
Decision Making and Supervision
- Provide guidance and support to cross-functional teams on cybersecurity compliance requirements, control implementation, and evidence collection activities
- Collaborate with stakeholders across Engineering, Product Security, IT, and Operations to identify compliance gaps and track remediation efforts
- Exercise independent judgment in conducting compliance assessments and evaluating control implementation
- Monitor and report on compliance activities, findings, and action items, escalating significant risks as appropriate
- Work autonomously while managing multiple priorities and coordinating with stakeholders