Talent.com
Indigo
Director, Information SecurityIndigo • Toronto, ON, CA
Les candidatures ne sont plus acceptées
Director, Information Security

Director, Information Security

Indigo • Toronto, ON, CA
Il y a plus de 30 jours
Type de contrat
  • Temps plein
Description de poste

Company Description

Indigo is a physical and digital place inspired by and filled with books, ideas, beautifully designed lifestyle products, and the creative people who help make it all happen. We believe in real books, living life fully and generously, being kind to each other and to the environment, and that stories — big and little — connect us. Indigo is our customer's happy place — for joyful moments of discovery and to connect with people who share their passion for reading, their belief in ideas, and their commitment to making the world a better and more beautiful place.

OUR GUIDING PRINCIPLES

Our Mission is to inspire reading and enrich the lives of booklovers. As such, we believe in the power of people and their stories. We aim to attract top talent, nurture the potential of our employees, and create space for everyone to thrive. Our Guiding Principles are the few key ideas that are meant to influence everything we do, every day.

  • We Will Hire, Inspire, Promote and Retain the Best
  • We Will Be Customer Centric
  • We Will Be Entrepreneurial
  • We Will Be Committed to Caring About Each Other, Our Communities, and Our Environment
  • We Will Be Committed to True and Shared Value Creation
  • We Will Be Systems Thinking, Data Driven and AI enabled

Job Description

MISSION

Accountable for establishing and executing the enterprise information security strategy to guarantee the confidentiality, integrity, and availability of Indigo’s information assets. This role proactively manages enterprise technology risk, ensures strict compliance with regulatory and industry frameworks, and safeguards data through the leadership of Governance, Risk & Compliance (GRC), Security Architecture, and Security Operations.

KEY PERFORMANCE METRICS

  • Zero critical preventable security breaches.
  • Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) within established operational SLAs.
  • 100% compliance with critical regulatory and industry frameworks (, PCI-DSS, PIPEDA).
  • High completion rates for enterprise-wide security awareness training.

KEY ACCOUNTABILITIES

Strategic

  • Develop and implement a comprehensive enterprise information security strategy that aligns with Indigo's business objectives and risk tolerance.
  • Partner cross-functionally at the senior level to embed security-by-design principles into all foundational technology and retail store operations.
  • Set and manage operational and capital budgets to ensure the cost-effective execution of security infrastructure and compliance initiatives.

Functional

  • Enterprise Risk Management: Establish and maintain a continuous IT risk assessment framework to identify, quantify, and mitigate cybersecurity risks across retail, e-commerce, and corporate environments.
  • Regulatory Compliance: Guarantee strict adherence to critical data protection regulations and industry frameworks (, PCI-DSS, PIPEDA) through systematic control validations and comprehensive security audits.
  • Policy Governance: Formulate, publish, and enforce data-driven information security policies, standards, and operational guidelines across the organization.
  • Security Architecture Integration: Embed secure-by-design principles, NIST framework methodologies, and threat modeling into the lifecycle of all cloud, network, and retail store systems.
  • Identity & Access Management (IAM): Oversee the enforcement of Zero Trust architectures, privileged access management, and robust authentication mechanisms to protect all enterprise assets.
  • Threat Monitoring: Direct 24/7 Security Operations Center (SOC) activities, utilizing threat intelligence and data analytics to proactively detect and analyze anomalous network behavior.
  • Vulnerability Management: Execute systematic vulnerability scanning, penetration testing, and data-backed remediation prioritization to continuously reduce the organizational attack surface.
  • Incident Response: Lead the enterprise security incident response process, directing rapid containment strategies and conducting empirical root-cause analysis to prevent recurrence.
  • Security Awareness: Implement measurable, enterprise-wide security awareness training and phishing simulations to cultivate a resilient, security-first workforce.
  • Third-Party Risk Management: Assess and continuously monitor the cybersecurity posture of IT vendors, supply chain partners, and integrated platforms to ensure strict alignment with Indigo's risk tolerance.

People

  • Accountable for the overall engagement, productivity, turnover and bench strength of the team
  • Supports the creation and maintenance of a talent succession plan
  • Collaborate with others to drive flexible and iterative solutions, quickly and easily
  • Share technical knowledge with others and actively seek to learn from those more knowledgeable than yourself
  • Help others see the impacts of their efforts and proactively engage other functions to get input
  • Encourage others to freely share their point of view and be open to feedback
  • Understand and follow Indigo's core HR process - staffing, performance management, rewards, and development
  • Ensures all team members are provided with clear performance objectives that are aligned with Indigo Functional and Departmental goals
  • Has the ability to see the total organization with an integrated perspective
  • Develops positive and productive peer relationships

Cultural

  • Model Indigo’s beliefs and convey a positive image in everything you do
  • Understands/demonstrates in a manner that promotes, and is aligned with, Indigo's Mission, Vision, Beliefs
  • As a leader, hold others accountable in maintaining the integrity of Indigo's culture
  • Celebrate diversity of thought and have an open mindset
  • Take an active role in fostering a culture of continual learning, taking risks without the fear of making mistakes
  • Embrace, champion, and influence change through your team and/or the organization

SCOPE

Reports to: VP, Enterprise IT

Manager once Removed (MOR): Chief Technology & AI Officer

KEY RELATIONSHIPS

Internal:

  • IT
  • Digital
  • Finance
  • Supply Chain
  • Commercial Group
  • Creative
  • Consumer Experience
  • Human Resources
  • Retail leadership

External:

  • Approved Vendors
  • External auditors
  • Regulatory bodies

Qualifications

Work Experience / Education / Certifications

  • Bachelor's or master’s degree in computer science, Information Systems, or other related field with at least 15 years of Information Technology experience.
  • Minimum of 10 years’ experience working in a leadership position.
  • A professional certification (or suitable compensating experience) in the audit (CISA, etc) or security field (CISSP or CISM for instance) considered an asset.
  • Strong experience working with frameworks and regulations (PCI, ISO, PIPEDA, GDPR, etc).
  • Strong understanding of network design, tiered and secure architectures.

Competencies / Skills / Attributes

  • Strategic thinker with analytical and problem-solving experience.
  • A strong ability to influence and discuss complex technology problems in business language.
  • Must be an excellent and polished communicator who may be called upon to create and present materials to the Executive Committee and the Board of Directors.
  • Fast-learner and multi-tasker with the ability to adjust their outlook and leadership style to respond to quickly changing business priorities.

Créer une alerte emploi pour cette recherche

Director, Information Security • Toronto, ON, CA

Offres similaires

Remote Director of IT Security Role

DirectiveToronto, ON, CA
Télétravail
Temps plein

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Voir plus

 • Offre sponsorisée

Manager Of Information Security - $112,583 - $162,125 A Year

MorningstarNorth York, Canada
Temps plein

Manages information security compliance and privacy across the organization, leading a team and ensuring adherence to policies and regulations.Focuses on risk management, audits, and reporting. Voir plus

 • Offre sponsorisée

Strategic Information Security Architect

ColliersToronto, ON, CA
Temps plein

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Voir plus

 • Offre sponsorisée

Senior Cloud Security Engineer, Information Security

Peoples GroupToronto, ON, CA
Temps plein

We are hiring for this position out of our Toronto, Vancouver and Calgary offices.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that i... Voir plus

 • Offre sponsorisée

Director of IT Security for Directive Consulting

DirectiveToronto, ON, CA
Temps plein

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Voir plus

 • Offre sponsorisée

Director, Cybersecurity & Information Security - C$160,000 - C$170,000 A Year

FinanceitEast York, Canada
Temps plein

Directs cybersecurity and information security programs, focusing on risk assessment, monitoring, and implementing solutions to protect company data.Collaborates with various departments and extern... Voir plus

 • Offre sponsorisée

Sr. Director, Network Security Engineering - $150,800 - $251,300 A Year

McKessonToronto County, Canada
Temps plein

Directs network security engineering, ensuring infrastructure confidentiality, integrity, and availability, and implementing enterprise-wide security strategies. Voir plus

 • Offre sponsorisée

Enterprise Security Specialist

Cprvisionwhitchurch stouffville, on, Canada
Temps plein

Enterprise Security Specialist.Location: Stouffville, ON • Department: R&D • Reports to: Chief Technology Officer (CTO) • Salary: $120,000 - $135,000 • Openings: 1.Lead the development, implementat... Voir plus

 • Offre sponsorisée

Director, Information Security

TeranetToronto, Canada
Temps plein

Take a leadership role at Teranet as the Director of Information Security, where you will innovate security operations and ensure compliance in a dynamic technological landscape.Focus on enhancing ... Voir plus

 • Offre sponsorisée

Senior Director, Information Security Officer - C$185,772.5 - C$204,349.8 A Year

Toronto Community Housing CorporationToronto, Canada
Temps plein +1

Job Title:Senior Director, Information Security OfficerReports To:Lily Chen, Chief Financial OfficerHiring Manager:Lily Chen (lily.Work Location:729 Petrolia Road, TorontoJob Type:Permanent Full Ti... Voir plus

 • Offre sponsorisée

Senior Manager, Information Security Photonic Inc. - C$142,000 - C$178,000 A Year

PhotonicEast York, Canada
Temps plein

Lead and enhance the information security program for a deep tech company, establishing strategic plans, managing security operations, incident response, and collaborating with IT. Voir plus

 • Offre sponsorisée

Managing Director - Information Security Technology Risk - C$170,000 - C$200,000 A Year

BmoEast York, Canada
Temps plein

Oversees information security and technology risk, developing risk frameworks, providing expertise, and ensuring compliance with regulatory requirements and corporate policies.Manages teams and col... Voir plus

 • Offre sponsorisée

Chief Information Security Officer

CohereToronto, Canada
Temps plein

The OpportunityCohere seeks a Chief Information Security Officer who can help shape Cohere's security strategy & the broader conversation around securing AI at scale.You know how to build trust acr... Voir plus

 • Offre sponsorisée

Vice President, Information Systems & Chief Information Security Officer

Centric SoftwareToronto, Canada
Temps plein

About Centric SoftwareCentric Software is a global leader, providing an innovative and AI-enabled product-concept-to-commercialization platform for retailers, brands and manufacturers of all sizes.... Voir plus

 • Offre sponsorisée

Senior Consultant in Information Security

Control Gap Inc.Toronto, ON, CA
Temps plein

Make an impact as a Senior Consultant at CyberGuard Advantage, focusing on cybersecurity and compliance.Deliver insights into risk management and strengthen clients’ security postures.As a Senior I... Voir plus

 • Offre sponsorisée

Senior Manager, Information Security - C$95,000 - C$142,400 A Year

MeridianToronto, Canada
Temps plein

Toronto Corporate Office,3280 Bloor St W(Centre Tower, 7th Floor)Etobicoke, ON M8X 2X3, CAN St Catharines Corporate Office,75 Corporate Park DrSt Catharines, ON L2S 3W3, CAN At Meridian our aspirat... Voir plus

 • Offre sponsorisée

Senior Associate, Information Security

UNAVAILABLEtoronto, on, Canada
Temps plein

Publicis Groupe is the largest Communications Group worldwide and the leader in Digital and Interactive Communications.Publicis has activities spanning 108 countries on five continents and employs ... Voir plus

 • Offre sponsorisée • Nouvelle offre

Director, Information Security

Teranet Inc.toronto, on, Canada
Temps plein

Teranet is Canada’s leader in the delivery and transformation of statutory registry services with extensive expertise in land and commercial registries.We also market insightful property and data s... Voir plus

 • Offre sponsorisée

Information Security Manager

Insight GlobalToronto, ON, CA
Temps plein

Demonstrated history of technical leadership and strategic thinking in security roles.Extensive experience leading and managing complex security investigations and threat hunting engagements.Bachel... Voir plus

 • Offre sponsorisée

Director, Cloud Security & Iam Engineering - $125,000 - $210,000 A Year

S&P GlobalToronto County, Canada
Temps plein

Director role managing Identity and Access Management in cloud environments.Responsibilities include user account management and solution implementation. Voir plus