Full Job Description
In this role, you won't just manage a project—you'll lead a transformational compliance program that opens doors. You'll guide a large-scale pension and benefits administration platform through NIST 800-53 Moderate compliance, positioning TELUS Health to serve federal agencies and secure government contracts. This is strategic work that directly impacts the organization's growth trajectory and our ability to serve new markets.
You'll work at the intersection of security, technology, and compliance—translating complex regulatory frameworks (NIST 800-53, FedRAMP, ISO 27001, CSA STAR) into clear, actionable implementation plans. You'll partner with Engineering, Security, DevSecOps, and Compliance teams to build a compliant cloud environment from the ground up. Your leadership will ensure that security controls aren't just checked boxes—they're embedded into our architecture, our processes, and our culture.
This is hands-on strategic leadership where your expertise shapes both the technical direction and the organizational capability we build to compete in regulated markets.
What You'll Do
Your week will move between big-picture strategy and hands-on execution. Here's what a typical engagement looks like:
NIST 800-53 Compliance Leadership
You'll own the NIST 800-53 Moderate program from initial gap assessment through remediation and into continuous monitoring. You'll coordinate cross-functional teams12Engineering, DevSecOps, Security, and Compliance12to implement NIST 800-53 controls. You'll oversee the creation and maintenance of System Security Plans (SSPs), Plans of Actions & Milestones (POA&Ms), and supporting documentation. As the primary liaison with Third Party Assessment Organizations (3PAOs) and federal sponsor agencies, you'll manage remediation efforts based on audit findings and establish continuous monitoring (ConMon) practices that stick.
Multi-Framework Certification Management
You'll lead project planning, execution, and reporting across multiple cybersecurity frameworkswith NIST 800-53 Moderate as the primary focus. You'll develop and maintain schedules, milestones, deliverables, and dependencies that keep the team aligned. You'll coordinate with internal teams to ensure controls are documented, tested, and evidenced per relevant frameworks. You'll manage documentation creation (Security Assessment Reports, incident response plans, vulnerability management records) and oversee continuous monitoring programs and periodic compliance reviews.
Technical Architecture & Implementation
You'll partner closely with Engineering to ensure technical architecture and security control implementations are aligned with NIST 800-53 baselines. You'll lead the design and validation of identity management, data flows, and API integrations. You'll champion vulnerability management and incident response frameworks, ensuring alignment of data protection mechanisms across the technology stack.
Stakeholder Management & Communication
You'll communicate progress, risks, and dependencies to executive leadership and client stakeholders regularly. You'll prepare status reports, dashboards, and presentations for senior leadership. You'll facilitate executive steering committees and governance forums. You'll liaise with external auditors, cloud service providers, and regulatory bodies. And you'll provide technical mentorship and leadership for compliance best practices across the organization.
What You Bring
Must-Haves
310+ years in IT project management or solution architecture for enterprise or government platforms
3Direct hands-on experience managing cybersecurity compliance OR equivalent regulatory/assurance programs (DoD SRG, ISO 27001, SOC 2, GxP). You know NIST 800-53 documentation, continuous monitoring, 3PAO engagement, SSP and POA&M development inside and out.
3PMP or equivalent project management certification
3Deep working knowledge of cloud environments (AWS, Azure, GCP) including security control implementation, cloud network/security architecture, identity & access management, encryption, and logging
3Strong knowledge of NIST 800-53 controls and continuous monitoring operations
3Experience working with Third Party Assessment Organizations, federal compliance bodies, and cloud providers
3Excellent communication skills ability to simplify complex technical and compliance concepts for both technical teams and executive stakeholders
3Strategic and hands-on leadership you're comfortable both setting direction and rolling up your sleeves
3Collaborative and adaptable you thrive in cross-functional environments and can navigate competing priorities
Nice-to-Haves
3Master's degree in Computer Science, Information Systems, or Engineering
3Cloud certification such as Azure Solutions Architect Expert
3CISSP, CISM, CISA, or NIST CSF certification
3Experience with CSA STAR, the Cloud Security Alliance's CCM, or other related trust & assurance cloud frameworks
3Familiarity with security/privacy/regulatory requirements in pensions, benefits administration, or financial services (PIPEDA, HIPAA, GLBA, state data breach laws, US federal or state agency standards)
3Background in pension administration, benefits management, or financial services technology
3Experience with GRC tools and conformity reporting
Salary Range: $120,000 - $160,000
Actual total compensation will be determined based on factors such as knowledge, skills, performance and experience. We encourage all qualified candidates to apply, even if the posted salary range doesn't match your expectations. We're open to discussing competitive compensation packages tailored to your experience level and expertise.
TELUS Health offers rewarding benefits, which may vary per job function, such as:
3Comprehensive total rewards package highlighting competitive salary and bonus structures, minimum 3 weeks of vacation, and flexible benefits plan to meet the needs of you and your family
3Flexibility to work in-office, virtually or a combination of both
3Generous company matched pension
3Opportunity to give back to communities in which we work, live and serve
3Career growth and learning & development opportunities to develop your skills
3And much more5
Job Type: This is for a current vacancy.