> Markdown version of [/jobs/ext/145897-enterprise-security-specialist](https://www.wearedevelopers.com/jobs/ext/145897-enterprise-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Security Specialist - **Company:** Nitor Infotech - **Location:** Canada, KY, United States - **Experience:** Expert - **Salary:** $124,800.0 - $166,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Continuous Integration, Information Security Management, PCI Data Security Standards, Systems Development Life Cycle, Software Vulnerability Management, Cloud Platform System, Software Security, Devsecops - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cf2307186dbbcce4 ## About the Role * 5 -7+ years of experience in information security, cybersecurity, or technology risk. * Experience leading security programs or initiatives in fintech, financial services, SaaS, or other regulated environments. * Hands-on experience supporting SOC 2, PCI DSS, ISO 27001, or similar audits and certifications. * Strong understanding of enterprise security controls, risk management, and governance. * Familiarity with cloud environments (AWS, Azure, or GCP). * Ability to communicate security concepts clearly to technical and non-technical audiences. * Knowledge of Canadian regulatory and privacy requirements. * Clearly convey complex security topics to executives, clients, and technical teams. * Analyze security and compliance issues and design effective solutions. * Build strong partnerships internally and externally. * Deep understanding of SDLC, DevSecOps, CI/CD pipelines, cloud technologies, and regulatory frameworks. Bonus Points if you have the following: * Exposure to DevSecOps or secure SDLC practices. * Experience with vulnerability management or application security tooling. * Experience supporting client security assessments or enterprise customer due diligence. * Security certifications such as CISSP, CISM, or ISO 27001 Lead Implementer/Auditor. ## Description The Enterprise Security Specialist is a senior individual contributor responsible for leading the organization's enterprise security program in a regulated fintech environment. Reporting to the CTO, this role focuses on security governance, risk management, audits, certifications, and enterprise security practices, with exposure to DevSecOps considered an asset. This role serves as a primary security lead and advisor, working cross-functionally to ensure security practices support business growth, regulatory requirements, and customer trust, without formal people management responsibilities. What you'll do: Enterprise Security Program Leadership * Lead the development, implementation, and continuous improvement of the enterprise information security program. * Develop and maintain security policies, standards, procedures, and controls aligned with business objectives. * Establish security metrics and reporting to support executive visibility and informed decision-making. * Act as a trusted security advisor to the CTO and senior leadership. Governance, Risk & Compliance * Lead enterprise risk assessments, security reviews, and control evaluations. * Align security practices with recognized frameworks such as ISO 27001, NIST etc. * Support compliance with Canadian regulatory and privacy requirements, including PIPEDA, OSFI guidance, and applicable provincial legislation. Audits, Certifications & Regulatory Engagement * Lead and support security audits and certifications, including SOC 2, PCI DSS, ISO 27001, and customer security reviews. * Serve as a primary point of contact for auditors, regulators, and enterprise clients. * Coordinate audit readiness activities, including evidence collection, policy updates, control testing, and remediation tracking. * Translate audit findings into practical, risk-based improvements. Third-Party & Vendor Security * Lead third-party security risk assessments and vendor security reviews. * Support security questionnaires, contract reviews, and customer due diligence requests. Security Awareness & Collaboration * Promote a security-conscious culture through collaboration, education, and practical guidance. * Support security awareness initiatives and training across the organization. * Work closely with Product, Professional Services, Risk, and Legal teams to support internal and external security needs. Reporting & Leadership Support * Provide regular reporting on security posture, risks, audit readiness, and remediation progress. * Escalate significant security risks and incidents appropriately and support incident response activities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)