IT & Security Manager / Administrator - Toronto On.
Toronto, ON, Canada
Full Time
Manager/Supervisor
About Dokainish & Company
Since 2011, Dokainish & Company has been delivering world-class project management and project controls consultancy services. We specialize in working diligently and collaboratively with our clients to achieve long-lasting, impactful results across numerous business functions.
Our areas of expertise include Project Controls, Project Management, Quantitative Risk Analysis, Organizational Change Management, Enterprise Reporting, Estimating, Asset Management, and System Implementation for Capital Projects. We draw upon decades of project experience to deliver customized solutions to our clients’ most complex challenges.
We are currently seeking an experienced IT & Security Manager / Administrator to join our growing team and lead the administration, security, and governance of our corporate and product technology environments.
The Opportunity
The IT & Security Manager / Administrator will be responsible for maintaining a secure, reliable, and professionally managed technology environment across Dokainish & Company.
This is a hands-on role spanning corporate IT administration, cybersecurity, cloud infrastructure, privacy, technology risk, and security compliance. The role will manage the company’s Microsoft and Azure environments, employee technology lifecycle, endpoint and identity security, and technology controls while supporting the secure development and operation of internal tools, client technology solutions, and software products.
The successful candidate will work closely with the Product & Technology team and company leadership to establish practical security standards, strengthen technology governance, support client security requirements, and advance the organization’s readiness for frameworks such as SOC 2.
Location & Travel
This is a full-time, non-remote, in-office position based in downtown Toronto, Ontario.
Key Responsibilities:
We take immense pride in our high-performing, collaborative team. We recognize and value the uniqueness of every individual, and you’ll be part of a growing consulting firm where your expertise will directly contribute to the security, reliability, and scalability of our technology environment.
If you believe your skillset, drive, qualifications, and experience are a match, we welcome your application and can’t wait to hear from you.
We thank all applicants for their interest in joining Dokainish & Company. Please note that only those candidates considered for an initial interview will be contacted.
Notes:
VACANCY STATUS: This job post is for a new position.
AI USAGE: Artificial intelligence may be used to support the initial screening and evaluation of applications for this position. Applications are also reviewed by members of our Talent Acquisition team, and all employment decisions are made by human decision-makers.
Dokainish & Company is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to age, gender, race, colour, religion, sexual orientation, gender identity, national origin, disability, age and veteran status, or any other protected status required by applicable law.
In accordance with the Ontario Human Rights Code, Accessibility for Ontarians with Disabilities Act, 2005, and Dokainish & Company AODA Policy, accommodation will be provided in all parts of the hiring process. Applicants need to make their needs known in advance.
Since 2011, Dokainish & Company has been delivering world-class project management and project controls consultancy services. We specialize in working diligently and collaboratively with our clients to achieve long-lasting, impactful results across numerous business functions.
Our areas of expertise include Project Controls, Project Management, Quantitative Risk Analysis, Organizational Change Management, Enterprise Reporting, Estimating, Asset Management, and System Implementation for Capital Projects. We draw upon decades of project experience to deliver customized solutions to our clients’ most complex challenges.
We are currently seeking an experienced IT & Security Manager / Administrator to join our growing team and lead the administration, security, and governance of our corporate and product technology environments.
The Opportunity
The IT & Security Manager / Administrator will be responsible for maintaining a secure, reliable, and professionally managed technology environment across Dokainish & Company.
This is a hands-on role spanning corporate IT administration, cybersecurity, cloud infrastructure, privacy, technology risk, and security compliance. The role will manage the company’s Microsoft and Azure environments, employee technology lifecycle, endpoint and identity security, and technology controls while supporting the secure development and operation of internal tools, client technology solutions, and software products.
The successful candidate will work closely with the Product & Technology team and company leadership to establish practical security standards, strengthen technology governance, support client security requirements, and advance the organization’s readiness for frameworks such as SOC 2.
Location & Travel
This is a full-time, non-remote, in-office position based in downtown Toronto, Ontario.
Key Responsibilities:
- Administer and maintain Microsoft 365, Microsoft Entra ID, Azure, user accounts, groups, permissions, licensing, and identity and access controls.
- Manage the employee technology lifecycle, including account provisioning, device setup, onboarding, role changes, and secure offboarding.
- Administer corporate laptops, endpoints, applications, software licenses, mobile devices, and other technology assets.
- Implement and maintain endpoint management, patching, antivirus/EDR, encryption, device compliance, MFA, conditional access, and related security controls.
- Manage corporate networking, Wi-Fi, VPN, backup, recovery, and other core IT infrastructure.
- Establish and maintain identity and access management standards based on least privilege, appropriate segregation of duties, and controlled privileged access.
- Maintain cybersecurity policies, standards, procedures, and technical controls appropriate to the company’s operations and client requirements.
- Monitor vulnerabilities, security alerts, and technology risks, and coordinate remediation with internal teams and external providers.
- Manage cybersecurity incidents, including investigation, containment, escalation, remediation, root-cause analysis, and documentation.
- Coordinate penetration testing, vulnerability assessments, and security reviews for corporate infrastructure, internal applications, client technology solutions, and software products.
- Support secure cloud and application architecture by reviewing authentication, authorization, data storage, integrations, secrets management, environment segregation, logging, and deployment controls.
- Work with software development teams to embed appropriate security requirements throughout the software development lifecycle.
- Establish minimum security requirements for internally developed applications, SaaS products, client technology builds, and third-party integrations.
- Support security and privacy requirements associated with client technology Statements of Work, proposals, and delivery engagements.
- Lead the organization’s SOC 2 readiness activities, including control design, evidence collection, documentation, remediation tracking, and coordination with external auditors or advisors.
- Support client security questionnaires, vendor assessments, cybersecurity due diligence, insurance requirements, and technology compliance reviews.
- Maintain technology risk registers, access reviews, asset inventories, system documentation, incident records, and other security and governance documentation.
- Assess third-party software and technology vendors for cybersecurity, privacy, operational, and data-handling risks.
- Develop and maintain backup, disaster recovery, incident response, and business continuity procedures, and coordinate periodic testing where required.
- Provide day-to-day IT support and troubleshoot employee technology, access, device, application, and infrastructure issues.
- Act as a trusted advisor to leadership and the Product & Technology team on cybersecurity, privacy, infrastructure, technology risk, and required security investments.
- 4-year university degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Computer Engineering, or a related technical field.
- 5–8 years of relevant professional experience across IT administration, infrastructure, cybersecurity, cloud environments, or technology operations.
- Demonstrated hands-on experience administering Microsoft 365, Microsoft Entra ID, and Microsoft Azure environments.
- Strong understanding of identity and access management, MFA, conditional access, privileged access, endpoint security, encryption, device management, and least-privilege principles.
- Experience administering Windows endpoints and modern device-management and endpoint-security technologies.
- Practical knowledge of cloud security, network security, vulnerability management, logging and monitoring, backup and recovery, and incident response.
- Experience implementing or administering cybersecurity policies, standards, technical controls, and technology governance processes.
- Experience supporting cybersecurity or compliance frameworks such as SOC 2, ISO 27001, NIST Cybersecurity Framework, or CIS Controls is strongly preferred.
- Experience supporting security audits, client security assessments, vendor risk assessments, security questionnaires, or compliance evidence collection.
- Understanding of application security and secure software development practices, including authentication, authorization, secrets management, data protection, environment segregation, vulnerability management, and secure deployment.
- Experience working with software development, product, or technical delivery teams is strongly preferred.
- Working knowledge of privacy and data-protection requirements applicable to corporate, employee, client, and application data.
- Experience coordinating penetration testing, vulnerability assessments, remediation activities, or external security providers is an asset.
- Relevant professional certifications such as CISSP, CISM, CompTIA Security+, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, or equivalent are considered an asset.
- Ability to independently troubleshoot technical issues, evaluate security risks, develop practical solutions, and execute required remediation.
- Strong analytical, communication, documentation, and stakeholder-management skills.
- Ability to communicate technical and cybersecurity risks clearly to both technical and non-technical stakeholders.
- Comfortable operating in a growing organization where technology processes, infrastructure, governance, and controls are continuing to mature.
- Must be legally eligible to work in Canada without sponsorship.
- This is a full-time, non-remote, in-office position based in downtown Toronto, Ontario.
We take immense pride in our high-performing, collaborative team. We recognize and value the uniqueness of every individual, and you’ll be part of a growing consulting firm where your expertise will directly contribute to the security, reliability, and scalability of our technology environment.
If you believe your skillset, drive, qualifications, and experience are a match, we welcome your application and can’t wait to hear from you.
We thank all applicants for their interest in joining Dokainish & Company. Please note that only those candidates considered for an initial interview will be contacted.
Notes:
VACANCY STATUS: This job post is for a new position.
AI USAGE: Artificial intelligence may be used to support the initial screening and evaluation of applications for this position. Applications are also reviewed by members of our Talent Acquisition team, and all employment decisions are made by human decision-makers.
Dokainish & Company is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to age, gender, race, colour, religion, sexual orientation, gender identity, national origin, disability, age and veteran status, or any other protected status required by applicable law.
In accordance with the Ontario Human Rights Code, Accessibility for Ontarians with Disabilities Act, 2005, and Dokainish & Company AODA Policy, accommodation will be provided in all parts of the hiring process. Applicants need to make their needs known in advance.
Apply for this position
Required*