Logo for More Than a Workplace.

Program Manager-Security Operations & Compliance

Role overview

Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework
  • Experience with GRC processes and tools, including risk and control management, compliance tracking, audit preparation
  • Working knowledge of information security principles, risk management, access control, vulnerability management

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS)
  • Coordinate internal and external audit activities, including preparing evidence and maintaining action items
  • Support identity and access management activities, including provisioning and de-provisioning
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures

Key facts

Hard skills

Other skills

  • Organizational Skills
  • Communication
  • Time Management

About the company

More Than a Workplace. logo

More Than a Workplace.

IT Services & IT Consulting

Anovia - Your trusted partner for outsourced IT, Cloud, NOC, SOC, Managed IT, BPO, and Infrastructure Services. With more than two decades of global experience, Anovia empowers enterprise organizations with scalable, future-ready IT services and operational support. From Managed IT and Help Desk support to NOC, SOC, Cloud, VoIP, and BPO services, Anovia helps organizations simplify operations, improve service reliability, and reduce technology management costs. Every service is designed to help organizations strengthen operational resilience, optimize technology environments, and reduce operational costs. 🌍 𝐆𝐥𝐨𝐛𝐚𝐥 𝐃𝐞𝐥𝐢𝐯𝐞𝐫𝐲, 𝟐𝟒/𝟕 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 Our global team of 300+ certified professionals delivers multilingual Tier 1–3 support across multiple time zones, ensuring seamless service delivery and reliable enterprise support. 📊 𝐃𝐚𝐭𝐚-𝐃𝐫𝐢𝐯𝐞𝐧 𝐑𝐞𝐬𝐮𝐥𝐭𝐬 𝐓𝐡𝐚𝐭 𝐃𝐞𝐟𝐢𝐧𝐞 𝐎𝐮𝐫 𝐒𝐮𝐜𝐜𝐞𝐬𝐬 • 725,000+ Tickets Resolved • 300+ Certified support specialists • 99.7% SLA Achievement Rate • 98% Customer Satisfaction • 99.9% Uptime for managed systems • 80% First Contact Resolution 💡 𝐓𝐞𝐜𝐡𝐧𝐨𝐥𝐨𝐠𝐲 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦𝐬 𝐖𝐞 𝐒𝐮𝐩𝐩𝐨𝐫𝐭 From deployment and migration to daily operational support, our engineers support enterprise environments built on leading communication and collaboration platforms: Avaya | Cisco | Microsoft Teams | Microsoft 365 | Mitel | Genesys | OpenScape | Five9 | Dialpad | Unify | Motorola | Public Safety 🔧 𝐎𝐮𝐫 𝐂𝐨𝐫𝐞 𝐒𝐞𝐫𝐯𝐢𝐜𝐞𝐬 • Managed IT Services • IT Help Desk & Technical Support • VoIP & Unified Communications Support • Cloud Managed & Migration • Network Operations Center (NOC) • Security Operations Center (SOC) Services • Professional IT Services • Business Process Outsourcing (BPO) • Multilingual Customer & Technical Support • IT Staffing • Unified Communications • AI Services ⚡ Let’s connect

Company details

IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Anovia (formerly Innovatia Technical Services) is an industry-leading technology outsourcing support provider with expertise in the telecommunications industry. Operating for over 20 years, we specialize in workflow and knowledge processes, as well as technical support, helpdesk and multilingual support services. With over 200 professional experts across the globe, we service some of the worlds’ most successful Fortune 500 and Fortune 1000 companies.

About the Role

Anovia is looking for a hands-on information security and compliance professional with practical experience working with ISO/IEC 27001, SOC 2, HIPAA, or similar security and compliance programs.

The successful candidate will have experience helping an organization prepare for and work through an audit or certification process, including developing and maintaining policies and controls, supporting evidence collection, coordinating activities and meetings, tracking actions, and working with internal and external auditors.

This is also a build and delivery role. Anovia has a number of technical and operational initiatives that require more structure, planning, coordination, and follow-through. The successful candidate will be comfortable taking an initiative that is not yet well defined, establishing a practical plan, coordinating the people involved, and driving the work through to completion. Examples could include implementing a new security tool, improving security monitoring or vulnerability management, or helping establish a NOC/SOC capability.

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS), including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities.
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives as they are introduced and developed.
  • Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring audit findings and resulting actions are addressed.
  • Maintain the information asset inventory and data classification program, including assigning and tracking ownership.
  • Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
  • Coordinate vulnerability identification, remediation tracking, and escalation of significant findings.
  • Coordinate third-party and vendor security assessments, including security questionnaires and contract review support.
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures.
  • Coordinate security awareness training and phishing simulation programs.
  • Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting.
  • Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence.
  • Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion.
  • Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders.

Required Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework. Experience should include meaningful participation in an audit or certification process and familiarity with activities such as policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Demonstrated ability to take an ambiguous technical or operational initiative and bring structure to it, including defining scope, developing a practical plan, coordinating stakeholders, managing dependencies and issues, and driving the work through to completion.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.

Nice to Have

  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.
  • Experience with NIST CSF or other complementary security frameworks.
  • Experience managing contractors or vendors during technical or security initiatives.
  • Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities.
  • Experience with business continuity and disaster recovery planning.

Certifications

Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience. Relevant certifications include:

  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Relevant certifications are preferred but not require

Benefits at Anovia

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
  • Remote work opportunities
  • Focus on work/life balance
  • Immigration Program supporting immigration to Canada for eligible employees

We thank all candidates for their interest, however, only those selected for an interview will be contacted.
Anovia is an equal opportunity employer.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Program Manager Related jobs

Other jobs at More Than a Workplace.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.