Cybersecurity Specialist
- Canada, United States
- Remote
- Posted Sep 24, 2026
- 1 position
Opens an external site
- Employment type
- Full-time
- Experience level
- Mid-level · 2+ years
- Minimum education
- Bachelor’s degree
- Posting language
- English
- Working hours
- 40 hours per week
Job summary
The Cybersecurity Specialist will manage day-to-day information security controls, maintain compliance with ISO/IEC 27001 and SOC 2 standards, and administer the GRC platform. They will also monitor security alerts, support incident response activities, and facilitate security awareness training programs.
Job details
Kraken Robotics is currently recruiting for a Cybersecurity Specialist. This position can be remote anywhere in Canada or US, with preference given to those candidates within the cities we have offices. ROLES AND RESPONSIBILITES Operate and enforce Kraken’s day‑to‑day information security controls across corporate, cloud, and SaaS environments. Support Kraken’s ISO/IEC 27001 Information Security Management System (ISMS) by monitoring control operation, maintaining evidence, addressing control gaps, and updating risk register. Support SOC 2 Type II compliance by ensuring security and availability controls operate effectively and are supported by accurate, auditable evidence. Administer and maintain Kraken’s GRC platform (Vanta) to support control tracking, evidence collection, remediation management, and audit activities. Enforce access control processes, including user onboarding and offboarding, privileged access reviews, and periodic access recertification. Monitor and respond to security alerts and incidents in coordination with managed detection and response (MDR) and SOC providers. Support incident response activities, including investigation, documentation, corrective actions, and post‑incident review. Validate operational security controls such as logging, monitoring, vulnerability management, backup verification, and configuration compliance. Support cybersecurity infrastructure and policy projects, including the implementation and rollout of new security tools, platforms, and control capabilities. Enforce secure system usage and data handling requirements, escalating non‑compliance and control failures as appropriate. Support third‑party security and vendor risk management activities, including review of ISO 27001 certifications, SOC 2 reports, and related assurance artifacts. Identify gaps between documented controls and operational practice and work with internal teams to drive remediation and continuous improvement. Provide guidance to users on secure system usage and data handling requirements in line with company policy. Support the delivery of the organization’s security awareness and phishing resistance program using KnowBe4, including administration of training campaigns, simulated phishing exercises, and post‑email analysis workflows, and contributing to user remediation and reporting activities. QUALIFICATIONS AND EXPERIENCE Post‑secondary education in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience. Experience supporting operational cybersecurity, information security programs, or compliance initiatives. Working knowledge of ISO/IEC 27001, SOC 2 Trust Services Criteria, and common operational security controls. Experience collecting, maintaining, and validating audit‑ready security evidence. Experience working with GRC platforms (e.g., Vanta or similar) is strongly preferred. Technical security knowledge across areas such as identity and access management, endpoint security, logging and monitoring, vulnerability management, and secure system configuration. Experience operating in regulated, customer‑assessed, or compliance‑driven environments is an asset. PREFERRED SKILLS Strong written and verbal communication skills, with the ability to explain security requirements clearly to technical and non‑technical audiences. High attention to detail and a disciplined, evidence‑driven approach to security operations. Ability to translate security requirements into practical, enforceable operational controls. Strong organizational and time‑management skills in a multi‑priority environment. Self‑motivated with a proactive mindset and a commitment to continuous improvement. Relevant certifications (e.g., Security+, SSCP, CISSP, ISO 27001 Lead Implementer/Auditor) are considered assets.
What you’ll do
The Cybersecurity Specialist will manage day-to-day information security controls, maintain compliance with ISO/IEC 27001 and SOC 2 standards, and administer the GRC platform. They will also monitor security alerts, support incident response activities, and facilitate security awareness training programs.
Requirements
Candidates should have post-secondary education in Cybersecurity, Information Technology, or a related field, along with practical experience in operational security and compliance. Proficiency in ISO/IEC 27001, SOC 2 criteria, and GRC platform administration is strongly preferred.
Listed skills
- Compliance · Preferred
- Risk Management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity
- ISO/IEC 27001
- SOC 2
- GRC Platform
- Vanta
- Identity and Access Management
- Vulnerability Management
- Incident Response
- Security Awareness
- Phishing Resistance
- KnowBe4
- Compliance
- Risk Management
- Endpoint Security
- Logging and Monitoring
- Security Tools
- Workflow Management
- Evidence Collection
- Access Controls
- Auditing
- Management
- Certified Information Systems Security Professional
- Software As A Service (SaaS)
- Computer Science
- CompTIA Security+
- Information Technology
- System Configuration
- Continuous Improvement Process
- Control Operation
- Security Controls
- Cyber Security
- Governance Risk Management And Compliance
- Identity And Access Management
- Information Security Management Systems
- Operations Security
- Phishing
- Risk Register
- Robotics
- Security Requirements Analysis
- Systems Security Certified Practitioner
- Verbal Communication Skills
- Medical Device Reporting
- Coordinating
- Investigation
- Detail Oriented
Job areas
- Security & Safety
- Technology
- Software
- Cybersecurity Specialist
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Desjardins
Spécialiste en assurance qualité TI - R2611533
Direct employerEasy Apply- Hybrid
- montreal levis shawinigan, QC
- Posted Sep 23, 2026
Desjardins
Emplois en gestion de projets TI - R2611532
Direct employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 23, 2026
Desjardins
Analyste d'affaires système(BSA) Guidewire
Direct employerEasy Apply- Hybrid
- Lévis, QC
- Posted Sep 21, 2026
