Director of Information Security
Offre en anglaisThe Director of Information Security will develop and execute the organization's cybersecurity strategy and roadmap. They will lead governance, risk management, compliance, and security operations to protect critical business assets.
- Sur place
- Toronto, ON
- Publié 27 août 2026
- Postuler avant le 26 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Government of Ontario
Chef des services de soins de santé
- Sur place
The Hilary and Galen Weston Foundation
Program Manager, Neuroscience
- Sur place
Segal Centre for Performing Arts
Gérance du bar
- Sur place
Résumé du poste
About the Opportunity Our client is seeking an accomplished cybersecurity leader to establish, mature, and continuously evolve their enterprise security program. This individual will be responsible for protecting critical business systems and information assets while ensuring security practices support broader business objectives. Reporting to executive leadership, the successful candidate will lead governance, risk management, security operations, compliance programs, incident response, and security architecture initiatives across a complex enterprise environment. This role requires a strategic mindset along with hands on technical experience in the cybersecurity space. What You'll Be Doing Develop and execute the organization's information security roadmap and long-term cybersecurity strategy. Lead enterprise-wide risk management and security governance programs. Partner with business and technology stakeholders to embed security requirements into projects and operational processes. Oversee compliance initiatives involving privacy, regulatory, and industry security standards. Direct vulnerability management, threat monitoring, security investigations, and incident response activities. Establish and maintain security policies, standards, and operational procedures. Drive identity and access management initiatives, including privileged access controls and modern authentication practices. Evaluate and manage third-party security risk across vendors and strategic partners. Lead employee security awareness programs and promote a security-first culture. Manage security budgets, resource planning, vendor relationships, and security investments. Build, mentor, and develop a high-performing information security team. What We're Looking For 15+ years of a combination of Technology and Cybersecurity experience. 5+ years of leadership experience managing security teams and enterprise initiatives. Strong background in cybersecurity governance, risk management, compliance, and security operations. Experience working with frameworks and regulatory requirements such as ISO 27001, NIST, PCI DSS, PIPEDA, GDPR, or similar standards. Must have experience implementing GRC policies and procedures. Solid understanding of enterprise infrastructure, cloud security, network architecture, and modern security controls. Proven ability to communicate security risks and recommendations to executive and board-level stakeholders. Strong relationship-building, leadership, and change-management skills. CISSP, CISM, CISA, or similar certifications are considered assets.
Ce que vous ferez
The Director of Information Security will develop and execute the organization's cybersecurity strategy and roadmap. They will lead governance, risk management, compliance, and security operations to protect critical business assets.
Exigences
Candidates need over 15 years of technology and cybersecurity experience, including at least 5 years in a leadership role. Proficiency in security frameworks like ISO 27001 and NIST, along with certifications like CISSP or CISM, is highly valued.
Compétences indiquées
- ComplianceSouhaitée
- Risk ManagementSouhaitée
- Team LeadershipSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity Strategy
- Risk Management
- Security Governance
- Compliance
- Incident Response
- Security Architecture
- Vulnerability Management
- Identity And Access Management
- Third-Party Risk Management
- Security Awareness
- Budget Management
- Team Leadership
- Cloud Security
- Network Architecture
- GRC Policies
- Stakeholder Communication
Domaines d’emploi
- Security & Safety
- Technology
- Management & Leadership
- Retail
Renseignements supplémentaires
- Formation minimale
- Diplôme professionnel
- Expérience minimale
- 10+ ans
- Postuler avant le
- 26 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Director
- Mode de candidature
- La candidature directe est offerte