29 Aug
|
Dentons Canada
|
Winnipeg
29 Aug
Dentons Canada
Winnipeg
Information Security LeadLocation: Calgary, Toronto, Vancouver, Edmonton, Ottawa.ROLEDentons Canada LLP is recruiting an Information Security Lead who will ensure the security, integrity, and availability of Dentons Canada information assets. The candidate will manage and continuously improve multiple security programs, developing, implementing and maintaining security controls across people, processes and technology throughout the organization.KEY RESPONSIBILITIES & ACCOUNTABILITIESSecurity Architecture & Cloud SecurityProvide technical leadership and architectural oversight for the Firm’s security controls across on‑premises and cloud environments.Lead the design and implementation of secure architecture patterns for enterprise infrastructure, cloud platforms, identity services, and network security.Act as a key security advisor to Infrastructure, Cloud, and Application teams to ensure security is embedded into platform design, deployments, and operational processes.Support the secure adoption and governance of Microsoft Azure, including the design and implementation of security controls for identity, networking, workloads, and platform services.Lead the configuration and optimisation of Azure security capabilities including Microsoft Defender for Cloud, Conditional Access, Azure Policy, identity protection controls, and security monitoring integrations.Provide architectural guidance for secure network connectivity and access models, including integration with enterprise network security platforms such as Palo Alto and secure access platforms such as Netskope or Zscaler.Contribute to the development and automation of security guardrails for cloud environments, including policy enforcement, configuration standards and monitoring integrations.Monitor emerging threats, vulnerabilities, and technology trends and recommend improvements to strengthen the Firm’s security architecture and overall security posture.Mentor and provide technical guidance to Information Security team members across operational and engineering initiatives.Security Operations, Incident Response & Vulnerability ManagementLead the day‑to‑day security operations function, ensuring effective monitoring, detection and response across enterprise and cloud environments.Provide hands‑on technical leadership to team members responsible for security monitoring, threat detection, and vulnerability management activities.Serve as the primary escalation point for security incidents and high‑risk vulnerabilities, providing technical direction on investigation, containment, remediation and recovery.Oversee the development and continuous improvement of incident response playbooks, operational procedures, and response readiness activities, including incident simulations and tabletop exercises.Analyse vulnerability intelligence and security findings, guiding prioritisation and remediation efforts with infrastructure, cloud and application teams.Coordinate vulnerability scanning, penetration testing activities and remediation tracking to ensure security findings are appropriately assessed and addressed.Support the integration, tuning and optimisation of security technologies including SIEM, endpoint protection, network security and secure access platforms.Drive continuous improvement in detection, response,
and threat exposure management capabilities.Data Protection, Classification & DLPSupport the implementation and maturity of the Firm’s data protection program, including data classification, data loss prevention (DLP) and information protection controls.Provide guidance on protecting sensitive client and Firm data across collaboration platforms, cloud services and enterprise systems.Assist in designing and implementing data classification standards and enforcement mechanisms to ensure sensitive data is properly identified and protected.Support the configuration and management of DLP policies and controls across email, endpoints, cloud services and collaboration platforms.Work closely with legal, compliance and business stakeholders to ensure data protection controls align with regulatory requirements and client obligations.Assist with monitoring and responding to data protection incidents and DLP alerts, ensuring appropriate remediation and control improvements.Data Governance & ComplianceSupport the development and continuous improvement of the Firm’s security policies, standards and technical security guidelines.Assist with internal and external security audits, client security assessments and compliance activities related to industry frameworks.Contribute to the development of security metrics, reporting and dashboards that provide visibility into the Firm’s security posture and risk exposure.Prepare reporting on key security risks, operational metrics and program maturity for internal stakeholders.SKILLS & COMPETENCIESStrong understanding of enterprise security architecture and modern cloud security principles.Deep knowledge of Microsoft Azure security architecture and platform security capabilities.Strong understanding of identity‑centric security models and Zero Trust principles.Experience implementing and integrating enterprise security platforms including SIEM, network security controls, CASB/SSE platforms and endpoint security solutions.Strong knowledge of data protection practices including data classification, information protection and data loss prevention technologies.Excellent analytical and problem‑solving skills with the ability to evaluate risk and recommend practical technical solutions.Ability to lead technical discussions and mentor security team members while remaining hands‑on when required.Solid written and verbal communication skills with the ability to translate technical issues into business context.Strong stakeholder engagement skills with the ability to collaborate effectively across infrastructure, cloud, application and business teams.Ability to operate effectively in high‑pressure situations such as security incidents.Self‑motivated with the ability to anticipate risks and proactively improve security capabilities.Flexibility to collaborate across global teams and multiple time zones.EDUCATION,
EXPERIENCE & CERTIFICATIONSPost‑secondary education in Information Technology, Computer Science, Cybersecurity or a related discipline, or equivalent practical experience.Minimum 8+ years of experience in Information Technology with significant focus on cybersecurity architecture, engineering or operations.At least 6+ years of experience in an Information Security role with 3+ years in a lead or senior technical capacity.Deep experience securing Microsoft Azure environments, including identity security, network architecture, workload protection and cloud‑native security controls.Hands‑on experience implementing and managing Azure security capabilities such as Microsoft Defender for Cloud, Conditional Access, Azure Policy, identity protection controls and security monitoring integrations.Experience integrating enterprise security platforms with cloud environments, including SIEM solutions, network security platforms (e.G., Palo Alto) and CASB/SSE platforms (e.G., Netskope or Zscaler).Experience with Microsoft security technologies including Microsoft Sentinel, Defender for Endpoint, Defender for Identity, Defender for Cloud and related security services.Experience implementing or supporting data classification and data loss prevention (DLP) programmes across enterprise collaboration platforms and cloud services.Familiarity with threat frameworks such as MITRE ATT&CK and modern detection and response methodologies.Experience assessing security controls against industry frameworks such as ISO 27001/27002 and the NIST Cybersecurity Framework.One or more relevant certifications such as CISSP, CISM or certifications from GIAC, ISACA or Microsoft Security are preferred.This is a replacement role. The target salary range for this position is $130,000 – $135,000, commensurate with the successful candidate’s skills, experience and qualifications.Our comprehensive total rewards package includes inclusive and flexible benefits that support the wellbeing and development of our people, including extended health and mental health benefits, paid time off, retirement savings plans, a fitness subsidy, parental leave top‑up, and more.Note: Availability of benefits and programs may vary depending on your location and employment type and may be subject to eligibility criteria. Dentons reserves the right to modify or discontinue offerings, in whole or in part, at its discretion and without prior notice.Equal Opportunity StatementAt Dentons Canada, inclusion, diversity, equity and accessibility (IDEA) are not just ancillary values, they are foundational to our business. We believe that IDEA is essential to the shared success of our team and our clients. Our forward‑thinking and inclusive culture supports the professional development of all our people, enhances the leading services we offer to our clients and informs our commitment to make a positive impact in the communities where we live and work.Dentons Canada is an equal opportunity employer, and we welcome your application. All employment decisions, including hiring, will be made without regard to age, ancestry, citizenship, colour, creed, disability, ethnic origin, family status, gender identity, marital status, place of origin, race, sexual orientation or any other characteristic protected by applicable human rights legislation.#J-18808-Ljbffr
📌 Information Security Lead - C$130,000 - C$135,000 A Year (Winnipeg)
🏢 Dentons Canada
📍 Winnipeg