WHAT ON EARTH IS DECIEM?

Known as “The Abnormal Beauty Company”, DECIEM is the parent company of The Ordinary, NIOD, and other beauty brands & is an industry disruptor with a science first approach to innovation. DECIEM was Co-Founded in 2013 by the late Brandon Truaxe, a visionary who set out to change the beauty industry through authenticity and transparency. He developed DECIEM to be a happy family (of people and beauty brands), rooted in kindness, creativity, diversity, and respect, alongside Co-Founder and CEO, Nicola Kilner.

We are growing rapidly and we’re looking for someone who shares this vision and wants to grow with us!

WHAT WE’RE LOOKING FOR

We are looking for a Senior Manager, Cybersecurity, Compliance & Governance to work on a full-time permanent basis. This position is located out of our Toronto Head Office in Liberty Village, offering opportunity to work hybrid.

WHAT YOU’D BE DOING IN THIS ROLE

  • Lead a team across key regions, providing guidance, mentorship and support.
  • Supporting enterprise-wide regulatory compliance programs and building, operationalizing and supporting cybersecurity programs including developing and implementing strategies to identify, aggregate, and mitigate cybersecurity risks.
  • Communicating aggregated risk information and reports in a clear and understandable manner to key stakeholders (technical and non-technical)
  • Participating in Internal / External Audits, and Inspections, and driving noted audit findings to proper remediation
  • Directing the remediation and repair of non-compliant systems, software, and technologies across the Brand.
  • Managing communications with key partners and stakeholders, including messaging of SOX IT objectives and requirements, managing request lists, and facilitating discussions on risk & controls.
  • Facilitating the walkthrough process with Management and various audit teams. Collaborate with IT partners to review SOX documentation (risk control matrices, narratives, flowcharts) and identify areas where control enhancements and/or documentation improvements are needed. Ensure SOX documentation is accurate and reflects current process.
  • Completing and/or reviewing SOX assurance testing for key general IT controls (GITCs/ITGCs), IT application controls (ITACs), and key reports (IPE) identified in the walkthrough process. Coordinate testing approach and align expectations with internal & external auditors to ensure documentation and testing complies with industry standards (including PCAOB) and allows for reliance by the external auditors. Leverage knowledge of SOX methodology and industry requirements to ensure thorough workpapers are maintained.
  • Assessing and gathering details for in-scope SOX system and assist in performing an annual SOX IT Risk, Scoping and Controls Assessment
  • Providing advisory and when required, assess SOC 1 / SOC 2 reports to ensure appropriate controls are identified and operating effectively.

SKILLS AND QUALIFICATIONS NEEDED TO GET THE JOB DONE

  • 5+ years of experience in Cybersecurity, leading at least one team with strong record of successful delivery of the cybersecurity projects/programs and supporting day-to-day Cybersecurity Operations
  • 5+ years of experience in IT Risk Advisory or IT Controls & Compliance
  • 2+ years of project/program management experience
  • Strong knowledge and understanding of various areas of Cybersecurity and Compliance including Technology and Operations; Digital Identity & SAP Security; Data Classification, Protection, Third-Party Risk Management, Governance, Regulatory, & Compliance
  • Working knowledge of IT Audit, Risk Assessment, Cybersecurity, SOX compliance, GxP Compliance, SOC1, SOC2, ISO 27001.

WHAT YOU’LL BE GAINING BY JOINING OUR TEAM

There’s a lot of good stuff that comes along with being a DECIEM team member. Here’s a few of our favourite perks and benefits, in no particular order…

  • Generous Vacation & Personal Days, plus additional time off for volunteering in your community, voting, peaceful protesting, celebrating your birthday, and more.
  • 6 months of paid time off for new parents (inclusive of all genders).
  • Work from anywhere 4 weeks per year.
  • A hybrid work model (for applicable roles).
  • Summer Friday’s - get off at 1pm all summer long! (for applicable roles).
  • Unlimited access to an Employee Assistance Program that includes mental health care, mindfulness programs, and more.
  • Access to Development Grants & a LinkedIn Learning membership to help you keep growing and learning.
  • A generous discount on DECIEM products for you, your family, and your friends.

BUILDING GROWTH TO POWER GOOD

We are a People first company that lives by our core values to…

  • 😊 Do the right thing
  • 💡 Create impact
  • 🌱 Respect small things
  • ❤️ Care too much
  • 🚀 Be the future

These values continue to guide us in all that we do. Along the way, we’ve been honoured to win some pretty incredible awards, including a CEW Achiever Award, Best Skincare Brand at Sunday Times Style Beauty Awards, and Most Popular Sustainable Brand by The Cosmetify Index Global. We’re still blushing!

SUSTAINABILITY AND SOCIAL IMPACT

DECIEM’s objective is to build growth and do good things while prioritizing people, animals, and the Earth.

Our Sustainability strategy is focused on fighting climate change, improved waste management, responsible packaging, responsible sourcing and product lifecycle, and water conservation.

In 2020, DECIEM established the Good Fund to support both large and grassroots charities in response to global events.

CREATING A HUMAN WORLD OF BEAUTY

DECIEM is committed to diversity, equity, and inclusion (DEI) by creating meaningful, measurable change in the lives of our team members and in the communities where we operate. Achieving equality is critical to DECIEM and our future. You can learn more about our DEI commitment in our open letter, "Belonging is the Destination, Change is the Journey".

DECIEM is an equal opportunity employer. We prohibit discrimination based on age, colour, disability, national origin, race, religion, sex, gender, sexual orientation, and any other legally protected class in accordance with applicable federal, provincial and local laws. We are also committed to creating and maintaining an inclusive and accessible workplace. If you are contacted to be part of our recruitment process and require accommodation, please let us know.

WANT TO JOIN US?

Thank you for reading the whole thing! If you liked what you heard, kindly send us your resume. We really appreciate your effort in applying for this position. However, only those who have been shortlisted for interviews will be contacted. <3

#SP

#LI-MP1