Information Security Strategy and Risk Lead (Winnipeg)

Information Security Strategy and Risk Lead (Winnipeg)

13 Sep
|
FISPAN
|
Winnipeg

13 Sep

FISPAN

Winnipeg

FISPAN is hiring a Lead, Information Security Strategy and Risk to help ensure security decisions, control designs, and technical changes are reviewed early and implemented with the right level of rigor

This role focuses on practical security architecture, design assurance, and risk reduction across product, engineering, infrastructure, and operational change

You will partner closely with Engineering, Infrastructure, Product, GRC & Legal to review material technical decisions, assess security controls, and help teams move quickly without introducing avoidable risk

You will also lead key parts of FISPAN’s vulnerability management and penetration testing program, translating technical findings into clear remediation priorities and durable security improvements

Security Design & Risk Review

Lead security and risk reviews for material technology, infrastructure, integration, product, and operational changes

Define security principles, control expectations, and risk guardrails across cloud, SaaS, data flows, identity, privileged access, and production environments

Provide security-by-design guidance for new systems, internet-facing services, AI capabilities, shared platforms, and sensitive data integrations

Support risk assessments, threat modeling, control reviews, and documented security decisions for significant initiatives

Vulnerability Management & Security Testing

Own the vulnerability management strategy and governance process across applications, infrastructure, cloud services, and shared platforms

Define risk-based severity, prioritization, remediation expectations, escalation, and exception handling

Identify recurring vulnerability patterns and drive lasting control improvements and measurable risk reduction

Provide oversight of high-severity vulnerabilities, external exposure, and emerging threats

Security Strategy, Risk & Oversight

Develop and maintain security strategy and priorities aligned with business objectives, regulatory obligations,



and bank partner expectations

Identify material and emerging risks, recurring control weaknesses, and areas requiring broader security investment

Translate technical risks into transparent business impact, priorities, and recommendations for leadership

Contribute to security governance, risk reporting, roadmap planning, and oversight of material exceptions and risk acceptances

Partner with Product, Engineering, Compliance, Legal, and Operations to embed security and risk considerations into key decisions

Benefits

4-Week Vacation

Health & Wellness Coverage

100% Parental Leave Top-Up

Downtown Vancouver Offices & Amenities including fitness centre

Daily Coffee Runs & Weekly Team Lunches

MacBook / Apple equipment

Experience leading or materially contributing to vulnerability management and penetration testing programs7+ years in security architecture, cloud security, application security, security assurance, or technical risk roles with strong technical collaborationDemonstrated experience reviewing architecture and implementation decisions in SaaS or cloud-native environmentsAbility to assess material risk, identify control gaps, and drive practical remediationStrong written communication skills, including the ability to produce clear security recommendations, design feedback, and executive-facing summariesStrong understanding of security controls across IAM, cloud infrastructure, network security, logging/monitoring, vulnerability management, and production accessStrong collaboration and teamwork skills with the ability to work effectively across Engineering, Infrastructure, Product, Legal/GRC, and SecurityExperience in FinTech, banking, embedded finance, or regulated SaaS environmentsExperience reviewing shared infrastructure patterns, workflow automation platforms, and operational toolingFamiliarity with AWS, Kubernetes/EKS, cloud networking, and production change patternsFamiliarity with privacy and regulatory expectations relevant to SaaS platforms serving financial institutions

📌 Information Security Strategy and Risk Lead (Winnipeg)
🏢 FISPAN
📍 Winnipeg

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security strategy and risk lead (winnipeg) / winnipeg

Subscribe to this job alert:

Get the latest job offers by email for: information security strategy and risk lead (winnipeg) / winnipeg