Ture handles sensitive career, employment, organizational, and program data. Trust, privacy, and security are foundational product requirements—not secondary administrative concerns.
We are building a platform for enterprise and public-sector customers that need strong controls, clear evidence, responsible data practices, and confidence in how their information is managed.
The roleWe are looking for a Security & Compliance Operations Manager to build and operate Ture’s security and compliance program.
You will translate frameworks, customer commitments, and company policies into practical operating controls. You will coordinate evidence collection, risk assessments, vendor reviews, customer questionnaires, incident readiness, employee training, and audit activities.
This is an operational role for someone who understands that a control is only useful when it is clearly owned, consistently performed, and supported by evidence.
What you’ll doOperate and mature Ture’s information-security and compliance program.
Maintain policies, control descriptions, evidence requirements, and ownership records.
Coordinate SOC 2 and other applicable assurance or certification activities.
Manage recurring control testing and evidence collection.
Maintain company risk, issue, exception, and remediation registers.
Lead vendor-security and third-party-risk reviews.
Coordinate customer security questionnaires, due-diligence requests, and evidence packages.
Partner with engineering on access controls, logging, vulnerability management, secure development, and incident readiness.
Support privacy operations, data inventories, retention practices, and data-processing documentation.
Coordinate security-awareness training and workforce attestations.
Maintain incident-response plans and support tabletop exercises.
Track remediation commitments through completion.
Help assess new products, vendors, and integrations for security and compliance risk.
Make compliance processes efficient enough to support rather than obstruct the company.
5+ years of experience in security compliance, governance, risk, privacy operations, audit, or related work.
Hands-on experience with SOC 2 or comparable security frameworks.
Strong understanding of control design, evidence, risk assessment, and remediation.
Experience managing security questionnaires and customer due diligence.
Familiarity with cloud and SaaS security concepts.
Strong documentation and project-management skills.
Ability to work effectively with engineering, legal, operations, sales, and customer teams.
Sound judgment when handling confidential and sensitive information.
Experience at an early-stage B2B SaaS company.
Familiarity with ISO 27001, NIST, CIS Controls, PIPEDA, GDPR, or public-sector requirements.
Experience with GRC and trust-centre platforms.
Security or privacy certifications such as CISA, CISM, CISSP, CRISC, or CIPP.
Experience supporting Canadian data-residency or multi-jurisdiction requirements.
Within your first six months, you will have:
Established clear ownership and operating rhythms for core controls.
Improved audit and customer-evidence readiness.
Created stronger visibility into security risks and remediation work.
Reduced friction in customer security reviews.
Strengthened Ture’s security culture without creating unnecessary bureaucracy.


