Full-Time

IT and Security Manager / Administrator

Posted on 8/19/2026

Dokainish

Dokainish

No salary listed

Toronto, ON, Canada

In Person

Bachelor's

Category
IT & Security (1)
Required Skills
Microsoft Azure
Incident Response
CompTIA Security+
Microsoft Windows
Cybersecurity
Vulnerability Analysis
SOC 2
Cryptography
Penetration Testing
Requirements
  • A four-year university degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Computer Engineering, or a related technical field.
  • Five to eight years of relevant professional experience across IT administration, infrastructure, cybersecurity, cloud environments, or technology operations.
  • Hands-on experience administering Microsoft 365, Microsoft Entra ID, and Microsoft Azure environments.
  • Strong understanding of identity and access management, multifactor authentication, conditional access, privileged access, endpoint security, encryption, device management, and least-privilege principles.
  • Experience administering Windows endpoints and modern device-management and endpoint-security technologies.
  • Practical knowledge of cloud security, network security, vulnerability management, logging and monitoring, backup and recovery, and incident response.
  • Experience implementing or administering cybersecurity policies, standards, technical controls, and technology governance processes.
  • Experience supporting security audits, client security assessments, vendor risk assessments, security questionnaires, or compliance evidence collection.
  • Understanding of application security and secure software development practices, including authentication, authorization, secrets management, data protection, environment segregation, vulnerability management, and secure deployment.
  • Working knowledge of privacy and data-protection requirements applicable to corporate, employee, client, and application data.
  • Ability to independently troubleshoot technical issues, evaluate security risks, develop practical solutions, and execute required remediation.
  • Strong analytical, communication, documentation, and stakeholder-management skills.
  • Ability to communicate technical and cybersecurity risks clearly to technical and non-technical stakeholders.
  • Ability to operate in a growing organization where technology processes, infrastructure, governance, and controls are continuing to mature.
  • Must be legally eligible to work in Canada without sponsorship.
Responsibilities
  • Administer and maintain Microsoft 365, Microsoft Entra ID, Azure, user accounts, groups, permissions, licensing, and identity and access controls.
  • Manage the employee technology lifecycle, including account provisioning, device setup, onboarding, role changes, and secure offboarding.
  • Administer corporate laptops, endpoints, applications, software licenses, mobile devices, and other technology assets.
  • Implement and maintain endpoint management, patching, antivirus and endpoint detection and response, encryption, device compliance, multifactor authentication, conditional access, and related security controls.
  • Manage corporate networking, Wi-Fi, virtual private network, backup, recovery, and other core IT infrastructure.
  • Establish and maintain identity and access management standards based on least privilege, appropriate segregation of duties, and controlled privileged access.
  • Maintain cybersecurity policies, standards, procedures, and technical controls appropriate to company operations and client requirements.
  • Monitor vulnerabilities, security alerts, and technology risks, and coordinate remediation with internal teams and external providers.
  • Manage cybersecurity incidents, including investigation, containment, escalation, remediation, root-cause analysis, and documentation.
  • Coordinate penetration testing, vulnerability assessments, and security reviews for corporate infrastructure, internal applications, client technology solutions, and software products.
  • Support secure cloud and application architecture by reviewing authentication, authorization, data storage, integrations, secrets management, environment segregation, logging, and deployment controls.
  • Work with software development teams to embed appropriate security requirements throughout the software development lifecycle.
  • Establish minimum security requirements for internally developed applications, software-as-a-service products, client technology builds, and third-party integrations.
  • Support security and privacy requirements associated with client technology Statements of Work, proposals, and delivery engagements.
  • Lead the organization’s SOC 2 readiness activities, including control design, evidence collection, documentation, remediation tracking, and coordination with external auditors or advisors.
  • Support client security questionnaires, vendor assessments, cybersecurity due diligence, insurance requirements, and technology compliance reviews.
  • Maintain technology risk registers, access reviews, asset inventories, system documentation, incident records, and other security and governance documentation.
  • Assess third-party software and technology vendors for cybersecurity, privacy, operational, and data-handling risks.
  • Develop and maintain backup, disaster recovery, incident response, and business continuity procedures, and coordinate periodic testing where required.
  • Provide day-to-day IT support and troubleshoot employee technology, access, device, application, and infrastructure issues.
  • Act as a trusted advisor to leadership and the Product and Technology team on cybersecurity, privacy, infrastructure, technology risk, and required security investments.
Desired Qualifications
  • Experience supporting cybersecurity or compliance frameworks such as SOC 2, ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
  • Experience working with software development, product, or technical delivery teams.
  • Experience coordinating penetration testing, vulnerability assessments, remediation activities, or external security providers.
  • Relevant professional certifications such as Certified Information Systems Security Professional, Certified Information Security Manager, CompTIA Security+, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, or equivalent.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A