Indigobooksmusic

Indigobooksmusic

Team Lead, Information Security & Risk Management

Toronto, Ontario, Canada

Sponsorship not specifiedDetected 23 days ago
AzureCloud PlatformsCybersecuritySOC OperationsIncident ResponseComplianceSupply ChainHRPerformance ManagementLeadershipProblem SolvingAdaptability

About the role

  • We believe in real books, living life fully and generously, being kind to each other and to the environment, and that stories - big and little - connect us.
  • Indigo is our customer's happy place - for joyful moments of discovery and to connect with people who share their passion for reading, their belief in ideas, and their commitment to making the world a better and more beautiful place.
  • Monitor training completion and phishing metrics.

Responsibilities

  • Maintain an accurate and up-to-date inventory of critical information systems and data assets to support risk assessments, compliance audits, and continuous security monitoring.
  • Manage the enterprise security awareness and phishing simulation program.
  • Develop and deliver security awareness campaigns and communications.
  • Support security culture initiatives across the organization.
  • Support the design and implementation of Identity and Access Management controls.
  • Manage and improve processes related to user access, privileged access, and multi-factor authentication.
  • Lead IAM initiatives, including Azure PIM and Privileged Access Management (PAM) projects.
  • Collaborate with IT teams to strengthen identity governance and access controls.
  • Support investigation and remediation of security incidents.
  • Support continuous improvement of security monitoring and response processes.

Nice to have

  • Approved Vendors
  • External auditors
  • Regulatory bodies
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of progressive experience in Information Security, preferably in a
  • A professional certification in the security field (CISSP, CISM, or relevant cloud security certifications like AZ-500) is considered an asset.
  • Strong experience supporting frameworks and regulations (specifically PCI DSS).
  • Proven experience working with cloud environments (Azure preferred) and IAM/PAM solutions.

Skills

  • High completion rates for enterprise security awareness training and positive phishing simulation metrics.
  • Timely completion of security risk assessments for new technologies, applications, and vendors.
  • Strong cloud security posture maintained across Azure and SaaS environments.
  • Review cloud solutions and provide security recommendations.
  • Participate in cloud security assessments and remediation activities.
  • Work with internal teams and service providers to improve cloud security posture.
  • Conduct security assessments for new technologies, applications, vendors, and business initiatives.
  • Identify security risks and recommend appropriate mitigating controls.

Benefits

  • Collaborate with others to drive flexible and iterative solutions, quickly and easily
  • Understands/demonstrates in a manner that promotes, and is aligned with, Indigo's Mission, Vision, Beliefs
  • Take an active role in fostering a culture of continual learning, taking risks without the fear of making mistakes

This listing is sourced directly from Indigobooksmusic's careers page and normalized into a canonical job model.