Talent.com
Indigo Books & Music
Team Lead, Information Security & Risk ManagementIndigo Books & Music • Toronto, Ontario, Canada
Team Lead, Information Security & Risk Management

Team Lead, Information Security & Risk Management

Indigo Books & Music • Toronto, Ontario, Canada
Il y a plus de 30 jours
Type de contrat
  • Temps plein
Description de poste

The Information Security Lead provides cybersecurity expertise across Security Awareness Identity and Access Management (IAM) Cloud Security Security Risk Assessments and Security Projects. The role works closely with business and IT teams to identify and manage security risks support the implementation of security controls and ensure security requirements are considered in new technologies and projects. As a senior member of the Information Security team the position serves as a trusted advisor providing guidance and support to help protect the organization while enabling business objectives.

KEY PERFORMANCE METRICS

  • High completion rates for enterprise security awareness training and positive phishing simulation metrics.
  • Successful design implementation and management of Identity and Access Management (IAM) controls including Azure PIM and PAM.
  • Timely completion of security risk assessments for new technologies applications and vendors.
  • Strong cloud security posture maintained across Azure and SaaS environments.
  • Successful support of PCI DSS compliance activities and audits.

KEY ACCOUNTABILITIES

Strategic

  • Act as the security representative on business and technology initiatives serving as a trusted advisor to protect the organization while enabling business objectives.
  • Lead and support cybersecurity projects from planning through implementation ensuring security requirements are incorporated into project designs and deployments.
  • Coordinate with internal stakeholders vendors and consultants to deliver strategic security solutions.

Functional

  • System Inventory: Maintain an accurate and up-to-date inventory of critical information systems and data assets to support risk assessments compliance audits and continuous security monitoring.
  • Risk Management: Support the cybersecurity IT risk management framework by identifying quantifying and mitigating cybersecurity risks across corporate retail and e-commerce environments. Maintain the IT risk register and facilitate data-driven risk decisions to prioritize remediation efforts.
  • Security Awareness: Manage the enterprise security awareness and phishing simulation program. Develop and deliver security awareness campaigns and communications. Monitor training completion and phishing metrics. Support security culture initiatives across the organization.
  • Identity & Access Management (IAM): Support the design and implementation of Identity and Access Management controls. Manage and improve processes related to user access privileged access and multi-factor authentication. Lead IAM initiatives including Azure PIM and Privileged Access Management (PAM) projects. Collaborate with IT teams to strengthen identity governance and access controls. Conduct periodic access reviews of access to critical information systems.
  • Disaster Recovery: Participate in the development testing and execution of disaster recovery procedures and business continuity plans to ensure the resilience and availability of critical information assets and systems.
  • Tabletop Exercises: Facilitate cross-functional incident response and disaster recovery tabletop exercises to validate playbooks evaluate organizational readiness and identify actionable improvements.
  • Cloud Security: Support the implementation and operation of cloud security controls across Azure and SaaS environments. Review cloud solutions and provide security recommendations. Participate in cloud security assessments and remediation activities. Work with internal teams and service providers to improve cloud security posture.
  • Security Risk Assessments: Conduct security assessments for new technologies applications vendors and business initiatives. Identify security risks and recommend appropriate mitigating controls. Review solution designs and architectures from a security perspective. Support risk management activities for strategic business and IT projects.
  • Security Operations & Incident Response: Support investigation and remediation of security incidents. Participate in incident response activities and lessons learned reviews. Work with managed security providers and IT teams to address security issues. Support continuous improvement of security monitoring and response processes.
  • Compliance Support: Support PCI DSS compliance activities audits and assessments. Assist with security documentation evidence collection and remediation efforts. Collaborate with governance risk and compliance teams on security initiatives.
  • Vendor & Solution Reviews: Participate in vendor security reviews and product evaluations. Support RFPs and selection of security technologies and services. Review vendor security documentation and recommend security requirements.

People

  • Supports the creation and maintenance of a talent succession plan
  • Collaborate with others to drive flexible and iterative solutions quickly and easily
  • Share technical knowledge with others and actively seek to learn from those more knowledgeable than yourself
  • Help others see the impacts of their efforts and proactively engage other functions to get input
  • Encourage others to freely share their point of view and be open to feedback
  • Understand and follow Indigos core HR process - staffing performance management rewards and development
  • Has the ability to see the total organization with an integrated perspective
  • Develops positive and productive peer relationships

Cultural

  • Model Indigos beliefs and convey a positive image in everything you do
  • Understands/demonstrates in a manner that promotes and is aligned with Indigos Mission Vision Beliefs
  • As a leader hold others accountable in maintaining the integrity of Indigos culture
  • Celebrate diversity of thought and have an open mindset
  • Take an active role in fostering a culture of continual learning taking risks without the fear of making mistakes
  • Embrace champion and influence change through your team and/or the organization

SCOPE
Reports to: Director Information Security
Manager once Removed (MOR): VP Enterprise Technology

KEY RELATIONSHIPS

Internal:

  • IT Enterprise Applications
  • IT Information Security
  • PMO
  • Digital
  • Finance
  • Supply Chain
  • Commercial Group
  • Creative
  • Consumer Experience
  • Human Resources
  • Retail leadership

External:

  • Approved Vendors
  • External auditors
  • Regulatory bodies

Qualifications :

Work Experience / Education / Certifications

  • Bachelors degree in Computer Science Information Security or a related field.
  • 5 years of progressive experience in Information Security preferably in a
  • A professional certification in the security field (CISSP CISM or relevant cloud security certifications like AZ-500) is considered an asset.
  • Strong experience supporting frameworks and regulations (specifically PCI DSS).
  • Proven experience working with cloud environments (Azure preferred) and IAM/PAM solutions.

Competencies / Skills / Attributes

  • Analytical thinker with strong problem-solving capabilities.
  • Strong ability to influence and translate complex technology risks into business terms.
  • Excellent communicator capable of coordinating with cross-functional stakeholders and vendors.
  • Adaptable and capable of managing multiple priorities in a dynamic environment.


Remote Work :

No


Employment Type :

Full-time


Experience: years
Vacancy: 1
Créer une alerte emploi pour cette recherche

Team Lead, Information Security & Risk Management • Toronto, Ontario, Canada

Offres similaires

Cybersecurity Incident Manager

PwC CanadaToronto, ON, CA
Temps plein

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies.They work to identify vulnerabilities, develop secure systems, ... Voir plus

 • Offre sponsorisée

Senior It Security Risk & Remediation Lead - C$96,900 - C$136,800 A Year

TD BankEast York, Canada
Temps plein

Oversees IT security governance and compliance, including auditing and risk management within a financial institution. Voir plus

 • Offre sponsorisée

Incident and Release Management Lead Role

Fidelity Internationaltoronto, on, Canada
Temps plein

Fidelity Clearing Canada is looking for an Incident and Release Management Lead to streamline incident processes and oversee critical application updates.This role is essential for ensuring effecti... Voir plus

 • Offre sponsorisée

Senior IAM & Security Operations Lead

Rubicon PathToronto
Temps plein

A leading tech company in Toronto is seeking a Senior Security Specialist to develop and support OPS Secure environments.The role requires over 10 years of experience in identity and access managem... Voir plus

 • Offre sponsorisée

Manulife Senior Information Risk Position

Manulifetoronto, on, Canada
Temps plein

Become a key player at Manulife as a Senior Information Risk Consultant, focusing on cybersecurity and cloud risk.Work in a hybrid model to safeguard emerging technologies.In this strategic role wi... Voir plus

 • Offre sponsorisée

Senior Manager, Information Security - C$108,800 - C$163,200 A Year

TdToronto, Canada
Temps plein

Work Location:Toronto, Ontario, CanadaHours:37.Line of Business:Technology SolutionsPay Details:$108,800 - $163,200 CADTD is committed to providing fair and equitable compensation opportunities to ... Voir plus

 • Offre sponsorisée

Leadership Role in Cyber Risk Management

Capcotoronto, on, Canada
Temps plein

Capco seeks a Senior Leader in Cyber Risk Management to innovate and grow our services in the financial sector.Engage with top executives to drive effective governance and risk management.This role... Voir plus

 • Offre sponsorisée

Senior Manager, Technology Risk Governance & Compliance

Corus EntertainmentToronto, ON, CA
Temps plein

Risk Governance and Compliance.Toronto, ON (Hybrid, 2‑3 days in office).This role has a broad mandate, supporting both the Head of Enterprise Risk Management and the Head of Cybersecurity and Techn... Voir plus

 • Offre sponsorisée

Incident Management, Lead

Interac Corp.Toronto, ON, CA
Temps plein

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.At Interac, we design and deliver products and solutions that give Canadians control over their money ... Voir plus

 • Offre sponsorisée

Leadership Role In Cyber Risk Management

CapcoToronto, Canada
Temps plein

Lead and grow cyber risk management practice, advising senior executives on cyber and technology risk, leading consulting engagements, and overseeing delivery teams.Focus on financial services sector. Voir plus

 • Offre sponsorisée

Vulnerability Management Team Leader

Tree Top Staffing LLCToronto, Ontario, Canada
Temps plein

Become the Senior IT Manager specializing in Threat and Vulnerability, overseeing critical security initiatives.Guide our organization’s strategy to protect against threats and vulnerabilities.As S... Voir plus

 • Offre sponsorisée

Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development CorporationToronto, ON, CA
Temps plein

Security Incident Response Manager.This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats.T... Voir plus

 • Offre sponsorisée

Senior Credit Risk Leader — Team Management & Compliance

Industrial and Commercial Bank of China (Canada)Richmond Hill, York Region, CA
Temps plein

A prominent banking institution is seeking a Credit Risk Manager to lead their credit analysis team.This role involves overseeing underwriting, ensuring compliance with policies, and managing a cre... Voir plus

 • Offre sponsorisée

Cybersecurity Governance and Operations Leader

SOCANToronto, ON, CA
Temps plein

Shape the future of information security as a Senior Information Security Officer.Champion security governance while leading proactive risk management and incident response initiatives remotely.Thi... Voir plus

 • Offre sponsorisée

Senior Associate, Information Security

Publicis Groupe Holdings B.VToronto, ON, CA
Temps plein

The Senior Associate, Information Security is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendor... Voir plus

 • Offre sponsorisée

Senior Manager, Information Security - C$95,000 - C$142,400 A Year

MeridianNorth York, Canada
Temps plein

The Senior Manager will lead the cybersecurity team, implement the Cyber Security Strategy, and manage incident response. Voir plus

 • Offre sponsorisée

Managing Director - Information Security Technology Risk - C$170,000 - C$200,000 A Year

BmoToronto County, Canada
Temps plein

Oversees information security and technology risk, developing risk frameworks, providing expertise, and ensuring compliance with regulatory requirements and corporate policies.Manages teams and col... Voir plus

 • Offre sponsorisée

Information Security Manager

Insight GlobalToronto, Ontario, Canada
Temps plein

Demonstrated history of technical leadership and strategic thinking in security roles.Extensive experience leading and managing complex security investigations and threat hunting engagements.Bachel... Voir plus

 • Offre sponsorisée

Lead cybersecurity architect

Société Financière Manuvietoronto, on, Canada
Temps plein

At Manulife, we are changing the way we unlock value and secure the enterprise through technology and we want you to be part of it! We are growing our cybersecurity program with the vision to deliv... Voir plus

 • Offre sponsorisée

Cybersecurity Incident Manager

PwC South AfricaToronto, ON, CA
Temps plein

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies.They work to identify vulnerabilities, develop secure systems, ... Voir plus