19 Aug
|
Hire DigITalent
|
Toronto
19 Aug
Hire DigITalent
Toronto
Job Title: Director, Information Security
Location: Toronto, ON (On-site required)
Position Overview The Director, Information Security is responsible for establishing, leading, and executing the enterprise-wide cybersecurity strategy. This role ensures the protection of corporate, e-commerce, and various technology environments while aligning security practices with overall business growth, operational resilience, and regulatory compliance.
Key Accountabilities
Strategic Leadership
- Develop and execute an enterprise information security roadmap that supports business goals and risk tolerance.
- Partner with senior cross-functional leaders to embed security-by-design principles across IT operations and foundational technology platforms.
- Manage operational and capital security budgets to ensure cost-effective protection and compliance.
Functional & Operational Security
- Enterprise Risk Management: Maintain a continuous IT risk assessment framework to identify, quantify, and mitigate cybersecurity threats across retail, e-commerce, and corporate infrastructure.
- Regulatory Compliance: Ensure adherence to industry regulations and compliance frameworks (e.g., PCI-DSS, PIPEDA, GDPR, ISO) through ongoing audits and control validations.
- Policy & Governance: Formulate, publish, and enforce data-driven security standards and policies across the organization.
- Security Architecture: Integrate secure-by-design principles, threat modeling, and NIST framework methodologies into cloud, network, and store systems.
- Identity & Access Management (IAM): Oversee Zero Trust architecture, privileged access management (PAM),
and multi-factor authentication systems.
- Threat Monitoring & SOC: Direct 24/7 Security Operations Center (SOC) activities using threat intelligence and data analytics to detect and analyze anomalous behavior.
- Vulnerability Management: Drive systematic vulnerability scanning, penetration testing, and risk-prioritized remediation.
- Incident Response: Lead response strategies for security incidents, directing rapid containment and performing empirical root-cause analysis to prevent recurrence.
- Security Awareness: Deliver enterprise-wide security training and phishing simulations to build a security-first organizational culture.
- Third-Party Risk Management: Continuously assess and monitor third-party vendors and supply chain partners to uphold enterprise security standards.
People & Team Leadership
- Accountable for team productivity, engagement, talent succession, and bench strength.
- Establish clear, measurable performance objectives aligned with departmental objectives.
- Foster a collaborative environment that encourages technical growth, knowledge sharing, and constructive feedback.
- Guide team members in understanding the broader organizational impact of their initiatives.
Qualifications
- 10+ years of progressive experience in Information Technology.
- 10+ years of leadership experience in cybersecurity or IT risk roles.
- Solid expertise in security frameworks and regulatory compliance
- Deep technical understanding of network design, tiered systems, and secure cloud architectures.
- Professional certifications such as CISSP, CISM, or CISA (or equivalent demonstrated experience) are strongly preferred.
📌 Director Information Security (Toronto)
🏢 Hire DigITalent
📍 Toronto