Responsibilities
- Lead a team of information security analysts to drive innovation through AI and automation, strengthen information security operations, and streamline enterprise governance practices.
- Manage key stakeholders, collaborate closely with teams in Canada, and ensure that the organization’s information security program is optimized to deliver maximum protection with minimal disruption to business operations.
- Define, implement, and continuously enhance enterprise security policies, standards, and procedures.
- Align security initiatives with business objectives, regulatory requirements and cybersecurity threat intelligence insights.
- Serve as a trusted security advisor to leadership and technical teams on emerging threats, compliance, and risk mitigation.
- Lead risk assessments across infrastructure, applications, and cloud platforms (Azure, AWS, SaaS, hybrid).
- Ensure compliance with ISO 27001, NIST, GDPR, and other relevant standards.
- Support internal and external audits, including remediation planning and continuous improvement efforts.
- Oversee security event detection, monitoring, and analysis across hybrid environments.
- Partner with Center of Excellence (CoE) – Information Technology on Patch and vulnerability management governance.
- Lead root cause analysis for security incidents and embed lessons learned into operational practices.
- Coordinate with Incident Response partner firm for material security incidents.
- Act as a security subject matter expert, integrating security-by-design principles into enterprise projects.
- Guide technology selection and best-practice adoption for new tools and processes.
- Ensure consistent security integration into cloud-native deployments, SaaS adoption, and on-premises systems.
- Build a security-first culture by delivering awareness programs across the organization.
- Mentor staff, developers, and business stakeholders on secure practices.
- Lead and mentor a team of information security analysts.
- Partner with IT, compliance, and business stakeholders to ensure secure delivery of business services.
- Report on security posture, risks, and KPIs to senior management.
Requirements
- 10-15 years related work experience
- Degree or information security management experience is preferred
- Familiar with security standards and frameworks, such as ISO, NIST, SANS, and CIS
- Strong written and verbal communication skills; comfortable interacting with individuals at all levels of the organization
- Passion for technology and keep up with the latest information security trends
Nice to Have
- Experience with technologies such as Netskope Email Data Loss Prevention (DLP), Tenable Patch/Vulnerability Management, Cloud security, SIEM (Microsoft Sentinel), Email Security monitoring, Privileged Access Management (CyberArk) and XDR (Defender for Endpoints) are assets
- Comfortable working with and learning new technologies. Experience using Power Automate, AI tooling, PowerBI and Office 365 tooling (e.g. Excel) is a bonus
- Information security certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, etc. are a bonus but not mandatory