Security Compliance Lead in Montreal, Quebec at Axya Inc.
Explore Related Opportunities
Job Description
About Axya
Axya is building AI-powered technology that's transforming how the manufacturing industry sources and procures parts. Our platform connects manufacturers with suppliers and automates the entire source-to-pay process — from sourcing and quoting to procurement — making it faster, simpler, and more cost-effective for companies sourcing custom parts. By digitizing traditionally manual workflows, Axya enables manufacturers to operate with greater efficiency and competitiveness.
We are proud to cultivate an inclusive and collaborative work environment that fosters innovation, growth, and professional development. As a member of our team, you'll collaborate with passionate, forward-thinking professionals and contribute directly to transforming procurement in the manufacturing sector.
Role Overview
Axya's customers audit us. Aerospace, defence and industrial buyers don't sign until their vendor risk teams are satisfied — security questionnaires, control evidence, live reviews, often several at once and always on a deal timeline.
Right now that work lands on our engineering team, alongside SOC 2 renewal, vendor reviews and privacy obligations. It gets done, but by people whose day job is building the platform, and it slows down both the deals and the roadmap.
At the same time, our product is changing faster than our compliance posture is. We're shipping AI capabilities that process supplier-authored content and take actions inside our customers' systems. Our SOC 2 report says nothing about any of that, and the AI sections now appearing in enterprise questionnaires are the ones we're least prepared for.
This role takes all of it. You'll own compliance, privacy and trust at Axya end to end.
This is a first-of-its-kind hire here. You won't inherit a team or a playbook — you'll build the function and set its priorities.
Key Responsibilities
- SOC 2 Type 2, end to end. Scope, control monitoring, evidence collection, auditor coordination, remediation and the renewal cycle on schedule. That includes keeping the system description current as the platform changes — new data flows, new subprocessors and new automated processing need to be in scope before fieldwork, not discovered during it.
- AI governance. Our AI features are the part of the product our customers scrutinize hardest and our compliance program covers least. You'll build the governance layer: acceptable use, model and vendor risk, data handling for content that flows through AI systems, human oversight and audit trails for automated actions, and the controls that go with agents holding real permissions. ISO 42001 is our likely target framework, and you'll own the call on when and whether to certify.
- Customer security reviews. Questionnaires, vendor assessments, RFP security sections and live calls with enterprise security teams — including the AI questions we currently answer ad hoc. You'll build the reusable answer library and Trust Center content that turns a two-week exchange into a same-day response.
- Privacy and regulatory obligations. Quebec's Law 25 and PIPEDA, plus GDPR where our customers' data reaches Europe. Working with outside counsel, you'll translate obligations into controls engineers can implement, and own records of processing, retention schedules, privacy impact assessments and breach notification procedures.
- Third-party and vendor risk. A real assessment process for the tools, subprocessors and model providers we bring in, sized to our risk rather than to a checklist.
- The certification roadmap. ISO 27001 and, potentially, FedRAMP are on the horizon as our customer base moves further into aerospace and defence. Both are significant commitments. You'll run the gap assessments, build the honest cost and timeline case for each — including where they conflict with how we operate today — and tell us when the answer is "not yet." We'd rather hear that from you than discover it eighteen months in.
- Policies, standards and awareness. Security policies people can follow, an access review cadence that runs on time, joiner-mover-leaver controls, and training that isn't just an annual video.
- Risk register and reporting. Tracked risks with named owners, and honest reporting to the leadership team and the board.
What We’re Looking For
- Six or more years in security compliance, GRC, IT audit or risk, including at least one full SOC 2 Type 2 cycle where you were the primary owner rather than a contributor
- A second framework delivered end to end — ISO 27001, NIST 800-53, PCI DSS, HITRUST or similar. We need someone who has seen more than one control model and knows how they map onto each other.
- Hands-on experience with a compliance automation platform (Drata, Vanta, Secureframe or similar)
- Enough technical fluency to hold a credible conversation with engineers about AWS, access control and SDLC practices, and to push back on an answer that doesn't sound right
- A working point of view on AI governance — not necessarily a certification, but a real understanding of where the risk sits in AI-enabled products and how to write controls for it
- Comfort being the only person in your function
- Experience writing questionnaire and audit responses that survive enterprise scrutiny
- Clear writing. Most of this job is producing documents other people have to trust.Hands-on experience with a compliance automation platform (Drata, Vanta, Secureframe or similar)
What This Role is Not
We want to be straight with you, because the wrong fit wastes everyone's time.
This is not a SOC or monitoring role. Security operations — alerting, detection and incident response — is handled separately.
This is not an application or cloud security engineering role. You won't be writing code, running pentests or architecting the platform. You'll partner with the engineers who do, and you'll need to earn their respect to be effective.
If what you want is to be hands-on in the product, this isn't the job, and we'd rather say so now.
Preferred (Axya-Specific)
- Quebec Law 25 experience
- ISO 42001, or governance work against the NIST AI Risk Management Framework
- Exposure to FedRAMP, NIST 800-53 or Canadian Controlled Goods Program requirements
- Experience serving aerospace, defence or other customers where vendor assessment is a hard sales gate
- CISA, CISSP, CIPP/C, ISO 27001 Lead Implementer or equivalent
- Functional French
Why Join Axya
- 🏖 Unlimited Vacation Policy: because we believe in balance
- 🏥 Comprehensive Health Insurance: your well-being matters
- 🕒 Flexible work schedule: results matter more than hours
- 🏡 100% remote: get the job done wherever you prefer
- 🚀 Be part of a high-impact, collaborative team making real change in a traditional industry