Senior Manager, Information Security (Toronto)

Senior Manager, Information Security (Toronto)

31 Jul
|
Hays
|
Toronto

31 Jul

Hays

Toronto

We are hiring a Senior Manager, Information Security, Risk andpliance on behalf of a well-established organization in Toronto.

As the Senior Manager, Information Security, you aren''t just checkingpliance boxes, you are an architect and the owner of securitypliance program, risk register, andernance processes.

This is a planner-and-operator leadership role keeping the security strategy and roadmap current, decide what the security function works on next, and drive Engineering, IT, Product, and Legal to deliver against those priorities.

In addition to doing hands-on work when needed, you set priorities, hold teams accountable, and report on whether the program is working. A core part of the role is making sure the function is staffed and resourced to deliver its mission, including knowing when to bring in external experts to supplement the team.

You are a trusted and analytical rmender on which risks the organization accepts vs. remediates, how work is sequenced against business priorities, and how to spend resources and time against the highest impact risks in the most effective way.

Impact & Decision authority: This role owns the organizations PCI DSS and SOC 2pliance programs, ensuring attestations are maintained cleanly and without lapse.

You ensure the organization operates within the bounds of all relevant regulatory requirements.

Beyondpliance, this role directs risk management, including deciding which risks to accept versus remediate.

You provide accountability for oues, such as defensible customer data and efficient audit processes, rather than just tracking activity.

Responsibilities: Security Strategy and Program Management Own security strategy and multi-year roadmap as aerned program: initiatives tied to business objectives, with success criteria and key risks/dependencies.

Run the roadmap with program discipline (milestones, status reporting, dependency tracking) so work is prioritized by business impact, not handled reactively.

Staff and drive the Security Steeringmittee: agenda, metrics, and decisions on prioritization, resourcing, and policy approval.

Service Queue, Prioritization and Trend Analysis Own the operating model for the security service queue.

Every ticket has an owner, due date, and status,



with enforced SLAs.

Set the criteria for prioritizing requests (business impact, risk, deadlines, effort) and make the call on ambiguous requests that don''t fit a playbook.

Read the queue as a signal: spot recurring themes and emerging risks, and feed them into the strategy, roadmap, and Steeringmittee.

Report queue health and SLA performance to leadership in that context; escalate proactively. AIernance Lead and formalize AIernance Council as a cross-functional body (Legal, Privacy, Engineering, Information Security).

Own the framework for reviewing AI use cases (acceptable use, data privacy, auth, logging, DLP) and the decision on what''s approved.

Define and report AIpliance KPIs so the org can see and enforce adherence to the AI and Acceptable Use policies.

Partner with IT/Engineering on monitoring and data-filtering controls, and on steering employees to approved enterprise models.

Security Metrics and Executive Reporting Own a security metrics program that turns raw data into business-framed reporting for the Senior Leadership Team and Board.

Define the KPIs and KRIs the program is measured on (e.g. vulnerability remediation vs SLA, EDR coverage, phishing rates, audit findings) with multi-year maturity targets.

Stand up a security metrics dashboard that shows real-time metrics from our security and operational tooling.

People Leadership Manage and develop team members in the Information Security team.

Own a skills matrix and staffing plan for the function: identify gaps and decide what''s staffed internally vs. supplemented by external experts.

Bring in external specialists for audit peaks, point-in-time assessments, or capabilities not worth holding in-house, and manage those engagements.

Own people and technology resourcing, including budget implications.

Qualifications: Craft experience:



8+ years of experience in information security, with a strong focus onpliance, GRC, or security program management.

People leadership experience: 3+ years of direct people management experience, with a proven ability to develop talent and build cohesive teams.

Deeppliance expertise: Hands-on experience owning and successfully navigating PCI DSS and SOC 2 Type II audit cycles.

Risk management: Proven track record of operating an enterprise risk register and translating risk into a prioritized engineering/IT roadmap.

Program management: Strong project and program management skills with meticulous organization, attention to detail, and a focus on driving accountability across Engineering, IT, Product, and Legal.

Vendor and resource management: Experience managing external specialists/consultants for point-in-time assessments or audit peaks.

Education and certifications: Active security certification (e.g., CISSP, CISM, CRISC, or equivalent) is highly preferred.

Additional Valuable Skills, Experience, or Credentials Undergraduate Degree inputer Science, Cybersecurity, Business, or a related field, or equivalent practical experience.

Experience managing AIernance or emerging technology risk is a strong asset.

Experience designing and executing incident response tabletop exercises and security awareness programs.

What Success Looks Like in Year 1 PCI DSS and SOC 2 Type II audits werepleted cleanly: no material findings, attestations maintained without lapse.

Risk register live and current: open risks owned, dated, tied to business impact, and driving roadmap decisions.

Service-queue SLAs defined and met, with a documented prioritization model and a quarterly trend read feeding the roadmap.

Security metrics program live: KPI/KRI set reported monthly to leadership and quarterly to the riskmittee/Board. AIernance Council runs on a consistent cadence with a documented review framework and firstpliance KPIs reported.

First annualpany-wide tabletoppleted; security awareness program delivered with results tracked against benchmarks.

The Information Security department is appropriately staffed and resourced to deliver the mission.

📌 Senior Manager, Information Security (Toronto)
🏢 Hays
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, information security (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, information security (toronto) / toronto