IT & Security Manager / Administrator - Toronto On.

Dokainish & CompanyToronto, ON
Onsite

About The Position

Dokainish & Company is seeking an experienced IT & Security Manager / Administrator to join their growing team. This role is responsible for leading the administration, security, and governance of the company's corporate and product technology environments. It's a hands-on position covering IT administration, cybersecurity, cloud infrastructure, privacy, technology risk, and security compliance. The manager will oversee Microsoft and Azure environments, employee technology lifecycle, endpoint and identity security, and technology controls. They will also support the secure development and operation of internal tools, client technology solutions, and software products. The successful candidate will collaborate with the Product & Technology team and company leadership to establish security standards, strengthen technology governance, support client security requirements, and prepare the organization for frameworks like SOC 2.

Requirements

  • 4-year university degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Computer Engineering, or a related technical field.
  • 5–8 years of relevant professional experience across IT administration, infrastructure, cybersecurity, cloud environments, or technology operations.
  • Demonstrated hands-on experience administering Microsoft 365, Microsoft Entra ID, and Microsoft Azure environments.
  • Strong understanding of identity and access management, MFA, conditional access, privileged access, endpoint security, encryption, device management, and least-privilege principles.
  • Experience administering Windows endpoints and modern device-management and endpoint-security technologies.
  • Practical knowledge of cloud security, network security, vulnerability management, logging and monitoring, backup and recovery, and incident response.
  • Experience implementing or administering cybersecurity policies, standards, technical controls, and technology governance processes.
  • Understanding of application security and secure software development practices, including authentication, authorization, secrets management, data protection, environment segregation, vulnerability management, and secure deployment.
  • Working knowledge of privacy and data-protection requirements applicable to corporate, employee, client, and application data.
  • Ability to independently troubleshoot technical issues, evaluate security risks, develop practical solutions, and execute required remediation.
  • Strong analytical, communication, documentation, and stakeholder-management skills.
  • Ability to communicate technical and cybersecurity risks clearly to both technical and non-technical stakeholders.
  • Comfortable operating in a growing organization where technology processes, infrastructure, governance, and controls are continuing to mature.
  • Must be legally eligible to work in Canada without sponsorship.

Nice To Haves

  • Experience supporting cybersecurity or compliance frameworks such as SOC 2, ISO 27001, NIST Cybersecurity Framework, or CIS Controls is strongly preferred.
  • Experience supporting security audits, client security assessments, vendor risk assessments, security questionnaires, or compliance evidence collection.
  • Experience working with software development, product, or technical delivery teams is strongly preferred.
  • Experience coordinating penetration testing, vulnerability assessments, remediation activities, or external security providers is an asset.
  • Relevant professional certifications such as CISSP, CISM, CompTIA Security+, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, or equivalent are considered an asset.

Responsibilities

  • Administer and maintain Microsoft 365, Microsoft Entra ID, Azure, user accounts, groups, permissions, licensing, and identity and access controls.
  • Manage the employee technology lifecycle, including account provisioning, device setup, onboarding, role changes, and secure offboarding.
  • Administer corporate laptops, endpoints, applications, software licenses, mobile devices, and other technology assets.
  • Implement and maintain endpoint management, patching, antivirus/EDR, encryption, device compliance, MFA, conditional access, and related security controls.
  • Manage corporate networking, Wi-Fi, VPN, backup, recovery, and other core IT infrastructure.
  • Establish and maintain identity and access management standards based on least privilege, appropriate segregation of duties, and controlled privileged access.
  • Maintain cybersecurity policies, standards, procedures, and technical controls appropriate to the company’s operations and client requirements.
  • Monitor vulnerabilities, security alerts, and technology risks, and coordinate remediation with internal teams and external providers.
  • Manage cybersecurity incidents, including investigation, containment, escalation, remediation, root-cause analysis, and documentation.
  • Coordinate penetration testing, vulnerability assessments, and security reviews for corporate infrastructure, internal applications, client technology solutions, and software products.
  • Support secure cloud and application architecture by reviewing authentication, authorization, data storage, integrations, secrets management, environment segregation, logging, and deployment controls.
  • Work with software development teams to embed appropriate security requirements throughout the software development lifecycle.
  • Establish minimum security requirements for internally developed applications, SaaS products, client technology builds, and third-party integrations.
  • Support security and privacy requirements associated with client technology Statements of Work, proposals, and delivery engagements.
  • Lead the organization’s SOC 2 readiness activities, including control design, evidence collection, documentation, remediation tracking, and coordination with external auditors or advisors.
  • Support client security questionnaires, vendor assessments, cybersecurity due diligence, insurance requirements, and technology compliance reviews.
  • Maintain technology risk registers, access reviews, asset inventories, system documentation, incident records, and other security and governance documentation.
  • Assess third-party software and technology vendors for cybersecurity, privacy, operational, and data-handling risks.
  • Develop and maintain backup, disaster recovery, incident response, and business continuity procedures, and coordinate periodic testing where required.
  • Provide day-to-day IT support and troubleshoot employee technology, access, device, application, and infrastructure issues.
  • Act as a trusted advisor to leadership and the Product & Technology team on cybersecurity, privacy, infrastructure, technology risk, and required security investments.

Benefits

  • We take immense pride in our high-performing, collaborative team. We recognize and value the uniqueness of every individual, and you’ll be part of a growing consulting firm where your expertise will directly contribute to the security, reliability, and scalability of our technology environment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service