Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score
Job Description
We’re Hiring!
Senior Information Security Officer
Toronto, ONPOSITION TYPE: Permanent Full-Time
HIRING RANGE: $101,360 to $121,360
REASON FOR HIRING: New Role
WORK MODEL: Remote
LANGUAGE: English, French is an assetWHO WE ARE
SOCAN is a not-for-profit copyright collective dedicated to ensuring music creators and publishers receive what they have rightfully earned for the use of their work. SOCAN supports and represents nearly 200,000 songwriters, composers, and music publishers. Through licensing, global royalty collection and advocacy, we help creators to keep making the music that entertains, moves, and inspires us.OUR COMMITMENT TO DIVERSITY, EQUITY, INCLUSION, AND ANTI-RACISM
SOCAN thrives with a variety of viewpoints, identities, and backgrounds, and we are committed to anti-racism. Everyone is welcome to apply for our wide range of roles, regardless of gender identity, gender expression, ethnicity, race, age, culture, sexual orientation, religious belief, or physical ability. Learn more about SOCAN’s commitment to .WHY WORK WITH US?
- Make a difference by supporting and collaborating with a vibrant and creative community
- Enjoy many options for workplace flexibility and work-life balance
- Get involved in the rapidly changing creative space
- Advocate for and empower the creative community
- Together, we’ll help music creators earn more income and make a living
WHAT WE OFFER
- 35-hour workweek schedule (possible flexible work options i.e., 4-day work week (position based)
- Twelve paid sick days annually (including five personal days)
- Access to SOCAN fitness facility
- Annual Performance Incentive bonus (dependent on a personal and company performance)
- Defined contribution Pension Plan
- Comprehensive, health and dental benefits program
- Inclusive and collaborative working environment
ABOUT THE ROLE The Senior Information Security Officer (SISO) helps protect the organization’s people, data, and technology by building and operating a pragmatic security program across governance, risk management, and security operations. Working on a small team with wide-ranging responsibilities, the ISO partners closely with IT and business stakeholders to reduce risk through policy and standards, security monitoring and detection engineering, threat hunting, incident handling, and continuous improvement of security controls, automation, and resilience across a hybrid environment consisting of Microsoft Azure and on-prem infrastructure hosted on VMware ESX/NSX.WHAT YOU’LL DO / KEY RESPONSIBILITIES
- Security Governance: develop, maintain, and socialize security policies, standards, procedures, and security architecture guardrails aligned to business objectives
- Risk Management: lead and/or support security risk assessments, control reviews, threat modeling, risk treatment plans, and executive-ready reporting
- Security Operations: design and continuously improve security monitoring, alerting, and response processes across Microsoft Azure cloud and on-prem infrastructure (VMware ESX/NSX), as well as endpoint, identity, network, and SaaS environments
- Detection Engineering: build and tune SIEM detections and analytics (queries, correlation rules, use cases), reduce false positives, and measure detection coverage (e.g., mapped to MITRE ATT&CK)
- Threat Hunting: conduct proactive hunts using logs/telemetry, develop hypotheses, document findings, and translate learnings into new detections and control improvements
- Incident Handling: triage and investigate security alerts; lead incident response from containment through eradication and recovery; run post-incident reviews and drive corrective actions
- SIEM & Automation: operate and optimize SIEM/SOAR integrations, log onboarding, parsing/normalization, playbooks, and automations to improve MTTR and analyst efficiency
- Vulnerability Management: manage scanning and remediation workflows, prioritize findings based on risk, track SLAs, and validate fixes
- Security Assessments & Testing: perform technical security assessments, configuration reviews, and support or execute penetration testing; coordinate remediation with owners
- Application Security: partner with developers or vendors on secure SDLC practices and standards (OWASP ASVS and OWASP Top 10), including code review support, dependency scanning, secrets management, CI/CD security, and developer enablement
- Third-Party & SaaS Security: assess vendors and integrations, review security controls, and monitor ongoing risk
- Security Awareness: contribute to security training, guidance, and internal communications to strengthen the security culture
- Documentation & Metrics: maintain runbooks and playbooks; defin
Want AI-powered job matching?
Upload your resume and get every job scored, your resume tailored, and hiring manager emails found - automatically.
Get Started Free