Security Compliance Lead

Dominion DynamicsOttawa, ON
Onsite

About The Position

In this role, you'll lead our CPCSC certification program from the ground up — owning the controls register, evidence collection, and assessor relationship to drive us through Level 1 and Level 2 audit readiness. Beyond certification, you'll build out third-party risk assessments, manage the Controlled Goods Program and export-control obligations, oversee security flow-downs on federal/defence contracts, and run the company's security awareness training and policy governance.

Requirements

  • Hands-on building or running a security compliance program — CPCSC, CMMC, ISO 27001, NIST SP 800-171, controlled goods, or a directly comparable regulatory/security regime.
  • Fluency in a controls framework (ITSP.10.171, NIST SP 800-171/CMMC, or ISO 27001) — you can read a control, design evidence for it, and defend it to an assessor.
  • Third-party / supply-chain risk experience.
  • Builder's temperament: you'd rather stand up the function than inherit a mature one, and you're fine with ambiguity.

Nice To Haves

  • No defence background required.

Responsibilities

  • Run the ITSP.10.171 controls program day to day: controls register, control owners, evidence collection, gap remediation, and audit readiness.
  • Partner with the Head of Security to drive certification — Level 1, then Level 2 — and keep us there once we land it.
  • Own the assessor relationship and the audit cycle end to end.
  • Stand up and run third-party risk assessments: vendor/supplier security due diligence, scoring, the risk register, and ongoing monitoring.
  • Push security requirement flow-downs to suppliers, subcontractors, and teaming partners, and verify they hold.
  • Own the Controlled Goods Program: registration, the security plan, Designated Official / Authorized Individual structure, visitor and access controls, and ongoing reporting.
  • Handle export-control obligations (EIPA, ITAR/EAR adjacency) as they come into scope.
  • Manage security flow-downs and contractual security obligations on federal and defence work.
  • Run personnel security and clearance administration, and own how controlled and classified information is handled across the company.
  • Build and run the security awareness program — role-based training, secure onboarding/offboarding — and track completion as control evidence.
  • Own the security policy suite (acceptable use, access/identity, logging, endpoint/workstation, and the rest), keep it mapped to controls, and turn tribal knowledge into a maintained, assessor-defensible body of work.

Benefits

  • Competitive base salary and company equity
  • Comprehensive health benefits
  • Additional equity granted based on impact
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service