Responsibilities
- Define and implement a scalable information security strategy and long-term security vision.
- Create, enforce, and maintain enterprise-wide security policies, standards, and governance models.
- Communicate cybersecurity risks, strategic recommendations, and performance metrics to senior executives.
- Collaborate with department heads to embed security practices into business processes and strategic decisions.
- Monitor emerging cybersecurity threats, AI-related risks, and evolving industry standards.
- Conduct regular risk assessments across IT infrastructure, endpoints, applications, and business workflows.
- Maintain a centralized risk register and drive the remediation roadmap based on business impact.
- Lead vulnerability identification, assessment, and prioritization aligned with organizational risk tolerance.
- Evaluate third-party vendors for security posture and manage ongoing vendor risk.
- Assess new technologies for security implications and recommend enhancements.
- Enforce data governance policies across distributed platforms to prevent data fragmentation.
- Implement and manage device security policies using mobile device management tools.
- Lead incident response planning, including playbook development, simulations, and post-event analysis.
- Oversee endpoint protection, identity management, privileged access, multi-factor authentication, and device controls.
- Work with IT leadership to deploy and monitor technical security controls.
- Coordinate with external security providers and managed services as needed.
- Develop and manage business continuity and disaster recovery strategies.
- Drive compliance with security frameworks such as SOC 2 Type II and future certifications.
- Manage customer security questionnaires and support sales by showcasing organizational security maturity.
- Collaborate with Legal, Insurance, and Finance on data privacy, governance, and regulatory requirements.
- Maintain comprehensive documentation for policies, controls, audits, and compliance evidence.
- Design and manage organization-wide security awareness and phishing simulation programs.
- Champion a security-conscious culture throughout the company.
- Educate staff on current threats, social engineering tactics, AI use, and data protection practices.
- Define and report on security metrics to track organizational maturity and improvement.
Benefits
- Annual base salary range for Canada-based roles is $150,000–$190,000 USD; actual offer may vary based on experience and company practices.
- Comprehensive medical, dental, vision, disability, and life insurance plans tailored to individual needs.
- Employer covers 100% of employee plan costs and 50% for dependent coverage.
- Mental health support through access to licensed therapists via Spring Health and Headspace membership.
- Physical wellness benefits including Omada physical therapy, Carrott fertility support, Aaptiv workouts, and One Medical membership.
- Generous time-off policy including unlimited PTO (minimum 2 weeks), paid holidays, birthday off, year-end recharge period, and parental leave.
- Retirement savings with Traditional and Roth 401(k) options and 3% company match.
- Annual tenure-based bonus that increases in value over time.
Compensation
Annual base salary range for Canada-based roles is $150,000–$190,000 USD; actual offer may vary based on experience and company practices.
Work Arrangement
Remote (Worldwide) — United States, Canada, Mexico, United Kingdom
Team
Remote-first organization with global operations and collaboration via digital tools.
Other
- Ability to remain stationary for long durations is required.
- Must be able to interpret written and verbal communication effectively.
- Reliable internet connection is mandatory.
- Professional home office environment is expected.
- Reasonable accommodations are available upon request.
- Applicants from Canada, UK, or Australia must have current and valid work authorization.
- Permanent residence in the country of application is required for global roles.
Not specified