Cybersecurity Administrator
Location
Canada
Posted
12 days ago
Salary
$55K - $65K / year
Seniority
Mid Level
Job Description
Cybersecurity Administrator
JDPA LIMITED
• Manage inbound security questionnaires/RFIs and coordinate inputs across IT, Legal, Engineering, and other stakeholders • Maintain and continuously improve a centralized library of standardized, policy-aligned security responses • Track questionnaire/RFI status, deadlines, and follow-ups to ensure accurate, on-time delivery • Support the end-to-end third-party vendor risk lifecycle, including onboarding, periodic reviews, and offboarding • Conduct vendor security risk assessments using established frameworks and questionnaires (e.g., SIG, CAIQ, custom templates) • Maintain the vendor risk register, including risk ratings, evidence requests, remediation actions, and review schedules; escalate high-risk findings • Coordinate audit readiness activities (e.g., SOC 2 Type II, TISAX, internal audits), including continuous evidence collection and audit calendars • Serve as a point of contact during audit fieldwork by scheduling walkthroughs, gathering artifacts, and tracking auditor requests • Track audit findings and management responses and follow remediation commitments through closure; help update control narratives, policies, and procedures • Monitor and track vulnerabilities (scans, penetration tests, threat intel), maintain the vulnerability register, drive follow-ups, and produce status reporting.
Job Requirements
- Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field — or equivalent practical experience
- 1–2 years of experience in information security, IT compliance, risk management, or a related discipline
- Familiarity with common compliance frameworks and standards such as SOC 2, ISO 27001, TISAX, NIST, or similar
- Strong organizational skills with the ability to manage multiple workstreams, deadlines, and stakeholders simultaneously
- Excellent written and verbal communication skills — able to translate technical concepts for non-technical audiences
- Detail-oriented with a structured, process-driven approach to work
- Proficiency in standard productivity tools (Microsoft 365, Google Workspace) and experience with spreadsheets and tracking tools
- Entry-level security certification or active pursuit thereof: CompTIA Security+, CC (ISC²), or equivalent
- Understanding of cloud security concepts (AWS, Azure, or GCP environments)
- Understanding / Experience supporting external audits or regulatory examinations.
Benefits
- Health insurance
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Engineer
SAICSAIC is a premier Fortune 500® mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives. We are approximately 24,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.5 billion. For more information, visit saic.com . For ongoing news, please visit our newsroom .
Role Description Provide enterprise cybersecurity systems engineering, integration, and modernization support for HHS cybersecurity initiatives related to Post-Quantum Cryptography (PQC), Zero Trust (ZT), and enterprise security interoperability. - Support analysis, coordination, and integration of cybersecurity technologies, systems, and enterprise security architectures across HHS environments. - Assess interoperability, dependencies, and integration considerations between cybersecurity tools, cryptographic technologies, governance processes, and enterprise systems. - Support implementation planning and coordination for cybersecurity modernization initiatives involving PQC readiness, cryptographic agility, and Zero Trust alignment. - Assist in evaluating system configurations, security architecture alignment, and technical dependencies across enterprise environments. - Collaborate with technical and program stakeholders to support secure, scalable, and interoperable cybersecurity modernization efforts. - Support enterprise cybersecurity engineering activities across cloud, hybrid, and on-premises environments, as applicable. Qualifications - Support enterprise cryptographic discovery, dependency analysis, and interoperability assessment activities associated with cybersecurity modernization and PQC readiness initiatives. - Support discovery and inventory activities related to cryptographic assets across enterprise environments. - Assess and review data related to cryptographic dependencies across enterprise systems, applications, and network environments to identify vulnerable cryptographic implementations and technologies impacted by PQC migration requirements. - Assist in identifying legacy systems, applications, and technologies that may not support PQC algorithms or cryptographic agility principles. - Support interoperability assessments and dependency analysis related to enterprise cryptographic modernization initiatives. - Assist with the evaluation of operational impacts, integration dependencies, and transition considerations associated with PQC modernization efforts. Requirements - Support planning, coordination, and technical integration activities associated with Post-Quantum Cryptography modernization initiatives. - Support the development of migration strategies and implementation roadmaps for transitioning enterprise cybersecurity environments toward PQC-capable solutions. - Assist with implementation planning for TLS 1.3 adoption and other modern cryptographic protocols. - Support evaluation of vendor documentation, product roadmaps, and PQC readiness statements for enterprise technologies and security platforms. - Assist with architecture reviews to support future-state cybersecurity environments, incorporating cryptographic agility principles. - Assist with the development of technical standards, implementation guidance, and engineering baselines supporting PQC migration and modernization activities. - Support evaluation of emerging cybersecurity technologies, standards, and modernization approaches related to PQC implementation considerations. Benefits - Support testing, validation, and technical assessment activities associated with cybersecurity modernization and PQC readiness initiatives. - Assist with the development of testing procedures, interoperability assessments, and validation criteria for PQC-capable technologies and modernization initiatives. - Support review of test results, operational impacts, compatibility considerations, technical risks, and recommended remediation approaches. - Support pilot implementations, proof-of-concept activities, and technical coordination efforts related to PQC migration and cybersecurity modernization planning. - Support risk identification, impact assessments, and technical analysis associated with enterprise cybersecurity modernization efforts. Documentation, Reporting & Stakeholder Coordination - Support operational visibility, technical documentation, reporting, and stakeholder coordination activities across cybersecurity modernization initiatives. - Assist with the development and maintenance of technical documentation, implementation procedures, engineering diagrams, architecture artifacts, and operational guidance. - Support preparation of reports, technical summaries, status updates, technical briefings, leadership presentations, and decision support materials. - Document identified risks, issues, dependencies, implementation considerations, and recommendations associated with PQC migration and cybersecurity modernization activities. - Support the development of inventory reports, migration-related documentation, dashboards, trackers, and reporting artifacts required for federal reporting and compliance activities. - Communicate technical concepts, modernization impacts, and interoperability considerations clearly to both technical and non-technical stakeholders. - Contribute to continuous improvement efforts supporting enterprise cybersecurity modernization, systems integration, and governance alignment.
Title: Project Coordinator II, Security Location: California, United States Job Description: Location: This is a 100% remote position. The position may be hybrid if the employee is local, in the San Diego, California region. Hybrid work model: 60% remote, 40% on-site as needed. General Summary The Project Coordinator will be part of an established team providing comprehensive project coordination of security projects. The role requires experience with supporting small through large-scale projects from inception through completion. Supervision Level: Reports to Director, Network Communications. Responsibilities: - Provides project support, including meeting coordination and project progress tracking. - Maintains documentation, meeting minutes, action items, deliverables, purchase orders, material shipments, return authorizations, and change orders. - Collaborates with internal and external stakeholders to understand project needs and meet requirements. - Assists project managers with preparing work orders documents, budgets, schedules, statement of work, and project plans. - Prepares summaries and detailed project reports for management and project team members. - Communicates project milestones, progress, and deliverables. - Conducts audits to ensure accuracy, quality, and completeness of project scopes. - Monitors budgets, forecasts, and develops monthly variance reports. - Provides Request for Information and Request for Proposal support as needed. - Identifies and raises issues and risks; recommends actions to resolve. - Performs other duties as assigned.
• Own and maintain cloud infrastructure across AWS and container-based environments • Design, build, and maintain infrastructure using Infrastructure as Code tools such as Terraform • Support with future replatforming and infrastructure modernisation initiatives, including migration from Heroku to AWS container platforms • Manage vulnerability remediation processes including CVE tracking, security patching, and maintaining regular patching cadences • Support operational resilience (OR), disaster recovery (DR), backup strategies, and business continuity planning • Help maintain and improve security and compliance processes aligned with ISO27001 framework • Improve system reliability, scalability, resilience, and performance across the Mast platform • Troubleshoot infrastructure, platform, networking, and security related issues across environments • Contribute to incident response processes and ongoing operational improvements • Build systems and tooling that automate infrastructure management and operational workflows wherever possible • Implement and maintain observability tooling including monitoring, logging, alerting, and tracing • Building tools and platforms that enable product teams to provision resources autonomously (self-service) • Building and maintaining CI/CD pipelines and deployment workflows to improve developer experience and delivery velocity • Introducing guardrails for self-service cloud engineering by development teams
• Design vulnerable multi-component applications and security challenge environments across languages such as Go, Python, Node.js, or Rust • Develop realistic exploit chains combining multiple vulnerability categories and attack vectors • Build deterministic evaluation environments using Docker and automated validation tooling • Create security-focused test cases and verification logic for vulnerability detection and remediation workflows • Review and analyze AI-generated outputs to identify gaps in reasoning, security understanding, or exploit detection • Develop adversarial scenarios involving misleading documentation, obfuscated code, edge cases, and hidden attack paths • Model real-world vulnerability classes inspired by CVEs, bug bounty findings, and production security incidents • Ensure evaluation tasks remain scalable, reproducible, and resistant to contamination from public datasets • Collaborate with cross-functional teams working on AI evaluation, benchmarking, and automated testing systems

