UniUni

UniUni

Senior Security Compliance Engineer

Canada · Senior

Sponsorship not specified$53k-$800kDetected 17 days ago
PythonSQLAWSCybersecurityComplianceSupply ChainLogistics

About the role

  • We are hiring a Senior Security Compliance Engineer to be the operational backbone of UniUni's governance, risk, and compliance function.
  • You will run the day-to-day machinery that keeps our ISO 27001 certification and SOC 2 Type II attestation healthy, our policies current, our customers confident, and our regulatory obligations met.
  • We are looking for someone who automates what should be automated, writes clearly, and treats compliance as a real engineering problem.

Responsibilities

  • Maintain the risk register, drive risk treatment plans through to closure, and prepare risk reporting for the ISO and the executive team.
  • Build and maintain compliance automation, including evidence collection workflows, control testing, and dashboarding.
  • Support data residency and data minimization commitments, working with engineering and the data security team to verify they hold in practice.
  • Customer Reviews and Third-Party Risk Lead the response to customer security questionnaires, RFP security sections, and prospect security reviews, in partnership with sales, legal, and the ISO.

Nice to have

  • vendor inventory, tiering by risk, due diligence, security review of new vendors, periodic reassessment of existing vendors, and remediation tracking.
  • Operate the trust center and the security artifact library (SOC 2 reports, ISO certificates, pen test summaries, security overviews) and keep customer-facing materials current and accurate.
  • Write clearly and precisely.
  • 5 to 8 years in security GRC, audit, or a closely related discipline, with hands-on ownership of ISO 27001 and SOC 2 program operations in a cloud-native organization.
  • Direct experience driving SOC 2 Type II audit cycles end to end, including auditor coordination, evidence collection, and remediation.
  • Working knowledge of common control frameworks beyond ISO and SOC (NIST CSF, NIST 800-53, CIS) and the ability to map between them.
  • Familiarity with privacy regulation in North America, including PIPEDA and US state privacy laws, and a working understanding of cross-border data transfer requirements.
  • Experience operating a third-party risk management program at meaningful vendor volume.

Skills

  • Our technology is cloud-native on AWS.

Compensation

  • Core GRC Run the ISO 27001 program operations, including surveillance audit prep, internal audits, the annual risk assessment, management reviews, and corrective action tracking.
  • Operate the information security policy lifecycle: drafting, stakeholder review, approval workflows, annual reviews, version control, and employee attestations.

This listing is sourced directly from UniUni's careers page and normalized into a canonical job model.