Kraken Robotics is currently recruiting for a
Cybersecurity Specialist.
This position can be remote anywhere in Canada or US, with preference given to those candidates within the cities we have offices.ROLES AND RESPONSIBILITES - Operate and enforce Kraken's day-to-day information security controls across corporate, cloud, and SaaS environments.
- Support Kraken's ISO/IEC 27001 Information Security Management System (ISMS) by monitoring control operation, maintaining evidence, addressing control gaps, and updating risk register.
- Support SOC 2 Type II compliance by ensuring security and availability controls operate effectively and are supported by accurate, auditable evidence.
- Administer and maintain Kraken's GRC platform (Vanta) to support control tracking, evidence collection, remediation management, and audit activities.
- Enforce access control processes, including user onboarding and offboarding, privileged access reviews, and periodic access recertification.
- Monitor and respond to security alerts and incidents in coordination with managed detection and response (MDR) and SOC providers.
- Support incident response activities, including investigation, documentation, corrective actions, and post-incident review.
- Validate operational security controls such as logging, monitoring, vulnerability management, backup verification, and configuration compliance.
- Support cybersecurity infrastructure and policy projects, including the implementation and rollout of new security tools, platforms, and control capabilities.
- Enforce secure system usage and data handling requirements, escalating non-compliance and control failures as appropriate.
- Support third-party security and vendor risk management activities, including review of ISO 27001 certifications, SOC 2 reports, and related assurance artifacts.
- Identify gaps between documented controls and operational practice and work with internal teams to drive remediation and continuous improvement.
- Provide guidance to users on secure system usage and data handling requirements in line with company policy.
- Support the delivery of the organization's security awareness and phishing resistance program using KnowBe4, including administration of training campaigns, simulated phishing exercises, and post-email analysis workflows, and contributing to user remediation and reporting activities.
QUALIFICATIONS AND EXPERIENCE- Post-secondary education in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience.
- Experience supporting operational cybersecurity, information security programs, or compliance initiatives.
- Working knowledge of ISO/IEC 27001, SOC 2 Trust Services Criteria, and common operational security controls.
- Experience collecting, maintaining, and validating audit-ready security evidence.
- Experience working with GRC platforms (e.g., Vanta or similar) is strongly preferred.
- Technical security knowledge across areas such as identity and access management, endpoint security, logging and monitoring, vulnerability management, and secure system configuration.
- Experience operating in regulated, customer-assessed, or compliance-driven environments is an asset.
PREFERRED SKILLS- Strong written and verbal communication skills, with the ability to explain security requirements clearly to technical and non-technical audiences.
- High attention to detail and a disciplined, evidence-driven approach to security operations.
- Ability to translate security requirements into practical, enforceable operational controls.
- Strong organizational and time-management skills in a multi-priority environment.
- Self-motivated with a proactive mindset and a commitment to continuous improvement.
- Relevant certifications (e.g., Security+, SSCP, CISSP, ISO 27001 Lead Implementer/Auditor) are considered assets.