Talent.com
Hays
Senior Manager, Information SecurityHays • Toronto
Senior Manager, Information Security

Senior Manager, Information Security

Hays • Toronto
Il y a plus de 30 jours
Type de contrat
  • Temps plein
Description de poste
We are hiring a Senior Manager, Information Security, Risk andpliance on behalf of a well-established organization in Toronto.As the Senior Manager, Information Security, you aren't just checkingpliance boxes, you are an architect and the owner of securitypliance program, risk register, andernance processes. This is a planner-and-operator leadership role keeping the security strategy and roadmap current, decide what the security function works on next, and drive Engineering, IT, Product, and Legal to deliver against those priorities. In addition to doing hands-on work when needed, you set priorities, hold teams accountable, and report on whether the program is working. A core part of the role is making sure the function is staffed and resourced to deliver its mission, including knowing when to bring in external experts to supplement the team. You are a trusted and analytical rmender on which risks the organization accepts vs. remediates, how work is sequenced against business priorities, and how to spend resources and time against the highest impact risks in the most efficient way. Impact & Decision authority: This role owns the organization’s PCI DSS and SOC 2pliance programs, ensuring attestations are maintained cleanly and without lapse. You ensure the organization operates within the bounds of all relevant regulatory requirements. Beyondpliance, this role directs risk management, including deciding which risks to accept versus remediate. You provide accountability for oues, such as defensible customer data and efficient audit processes, rather than just tracking activity. Responsibilities:Security Strategy and Program Management
  • Own security strategy and multi-year roadmap as aerned program: initiatives tied to business objectives, with success criteria and key risks/dependencies.
  • Run the roadmap with program discipline (milestones, status reporting, dependency tracking) so work is prioritized by business impact, not handled reactively.
  • Staff and drive the Security Steeringmittee: agenda, metrics, and decisions on prioritization, resourcing, and policy approval.
Service Queue, Prioritization and Trend Analysis
  • Own the operating model for the security service queue. Every ticket has an owner, due date, and status, with enforced SLAs.
  • Set the criteria for prioritizing requests (business impact, risk, deadlines, effort) and make the call on ambiguous requests that don't fit a playbook.
  • Read the queue as a signal: spot recurring themes and emerging risks, and feed them into the strategy, roadmap, and Steeringmittee.
  • Report queue health and SLA performance to leadership in that context; escalate proactively.
AIernance
  • Lead and formalize AIernance Council as a cross-functional body (Legal, Privacy, Engineering, Information Security).
  • Own the framework for reviewing AI use cases (acceptable use, data privacy, auth, logging, DLP) and the decision on what's approved.
  • Define and report AIpliance KPIs so the org can see and enforce adherence to the AI and Acceptable Use policies.
  • Partner with IT/Engineering on monitoring and data-filtering controls, and on steering employees to approved enterprise models.
Security Metrics and Executive Reporting
  • Own a security metrics program that turns raw data into business-framed reporting for the Senior Leadership Team and Board.
  • Define the KPIs and KRIs the program is measured on (e.g. vulnerability remediation vs SLA, EDR coverage, phishing rates, audit findings) with multi-year maturity targets.
  • Stand up a security metrics dashboard that shows real-time metrics from our security and operational tooling.
People Leadership
  • Manage and develop team members in the Information Security team.
  • Own a skills matrix and staffing plan for the function: identify gaps and decide what's staffed internally vs. supplemented by external experts.
  • Bring in external specialists for audit peaks, point-in-time assessments, or capabilities not worth holding in-house, and manage those engagements.
  • Own people and technology resourcing, including budget implications.
Qualifications:
  • Craft experience: 8+ years of experience in information security, with a strong focus onpliance, GRC, or security program management.
  • People leadership experience: 3+ years of direct people management experience, with a proven ability to develop talent and build cohesive teams.
  • Deeppliance expertise: Hands-on experience owning and successfully navigating PCI DSS and SOC 2 Type II audit cycles.
  • Risk management: Proven track record of operating an enterprise risk register and translating risk into a prioritized engineering/IT roadmap.
  • Program management: Strong project and program management skills with meticulous organization, attention to detail, and a focus on driving accountability across Engineering, IT, Product, and Legal.
  • Vendor and resource management: Experience managing external specialists/consultants for point-in-time assessments or audit peaks.
  • Education and certifications: Active security certification (e.g., CISSP, CISM, CRISC, or equivalent) is highly preferred.
Additional Valuable Skills, Experience, or Credentials
  • Undergraduate Degree inputer Science, Cybersecurity, Business, or a related field, or equivalent practical experience.
  • Experience managing AIernance or emerging technology risk is a strong asset.
  • Experience designing and executing incident response tabletop exercises and security awareness programs.
What Success Looks Like in Year 1
  • PCI DSS and SOC 2 Type II audits werepleted cleanly: no material findings, attestations maintained without lapse.
  • Risk register live and current: open risks owned, dated, tied to business impact, and driving roadmap decisions.
  • Service-queue SLAs defined and met, with a documented prioritization model and a quarterly trend read feeding the roadmap.
  • Security metrics program live: KPI/KRI set reported monthly to leadership and quarterly to the riskmittee/Board.
  • AIernance Council runs on a consistent cadence with a documented review framework and firstpliance KPIs reported.
  • First annualpany-wide tabletoppleted; security awareness program delivered with results tracked against benchmarks.
  • The Information Security department is appropriately staffed and resourced to deliver the mission.
Créer une alerte emploi pour cette recherche

Senior Manager, Information Security • Toronto

Offres similaires

Information Security Consultant

CONFLUX SYSTEMSMarkham, York Region, CA
Temps plein

This request is to on-board resource for Application security team focusing on threat modelling, security architecture.Work with application teams and complete threat model.Develop and deliver secu... Voir plus

 • Offre sponsorisée

Senior Cybersecurity Manager Transforming Public Transport Security

ALSTOM GruppeToronto
Temps plein

Become a pivotal force in transportation safety as a Senior Cybersecurity Manager.Utilize your expertise in cybersecurity and system management in a hybrid work setting.This strategic role requires... Voir plus

 • Offre sponsorisée

Senior Cloud Security Engineer, Information Security

Peoples GroupToronto, ON, CA
Temps plein

We are hiring for this position out of our Toronto, Vancouver and Calgary offices.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that i... Voir plus

 • Offre sponsorisée

Strategic Information Security Architect

ColliersToronto, ON, CA
Temps plein

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Voir plus

 • Offre sponsorisée

Information Security Governance Analyst

Ontario Medical AssociationToronto, ON, CA
Temps plein

Advance the cybersecurity landscape as an Information Security Governance Analyst.Focus on compliance oversight, risk management strategies, and security improvements in a flexible hybrid environme... Voir plus

 • Offre sponsorisée

Senior Manager - IT Governance Risk and Control

Enercare Inc.Markham, ON, CA
Temps plein

Canada’s largest home and commercial services companies servicing over one million customers across Ontario, Manitoba, Saskatchewan, Alberta, British Columbia, Quebec and New Brunswick.Enercare is ... Voir plus

 • Offre sponsorisée

Senior Information Security Officer

SOCANToronto
Temps plein +1

Senior Information Security Officer (SISO).English required; French is an asset.Security Governance: develop, maintain, and socialize security policies, standards, procedures, and architecture guar... Voir plus

 • Offre sponsorisée

Senior IAM & Security Operations Lead

Rubicon PathToronto
Temps plein

A leading tech company in Toronto is seeking a Senior Security Specialist to develop and support OPS Secure environments.The role requires over 10 years of experience in identity and access managem... Voir plus

 • Offre sponsorisée

Senior Consultant in Information Security

Control Gap Inc.Toronto, Ontario, Canada
Temps plein

Make an impact as a Senior Consultant at CyberGuard Advantage, focusing on cybersecurity and compliance.Deliver insights into risk management and strengthen clients’ security postures.As a Senior I... Voir plus

 • Offre sponsorisée

Senior Consultant In Information Security

Control Gap Inc.Toronto, Canada
Temps plein

Make an impact as a Senior Consultant at CyberGuard Advantage, focusing on cybersecurity and compliance.Deliver insights into risk management and strengthen clients’ security postures.As a Senior I... Voir plus

 • Offre sponsorisée

Senior Information Security Specialist - C$96,900 - C$136,800 Par An

Institution FinancièreToronto, Canada
Temps plein

Une institution financière leader recherche un Spécialiste en Sécurité de l'information à Toronto.Le candidat fournira des conseils sur les programmes de sécurité et gérera l'évaluation des risques... Voir plus

 • Offre sponsorisée

Senior Manager, Technology Risk Governance & Compliance

Corus EntertainmentToronto, ON, CA
Temps plein

Risk Governance and Compliance.Toronto, ON (Hybrid, 2‑3 days in office).This role has a broad mandate, supporting both the Head of Enterprise Risk Management and the Head of Cybersecurity and Techn... Voir plus

 • Offre sponsorisée

Senior Information Security Analyst

ScotiabankToronto, ON, CA
Temps plein

Senior Information Security Analyst.Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Contributes to the successful delivery and operational supp... Voir plus

 • Offre sponsorisée

Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development CorporationToronto, ON, CA
Temps plein

Security Incident Response Manager.This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats.T... Voir plus

 • Offre sponsorisée

Senior Program Manager - Windows Security at AMD

AMDMarkham, ON, CA
Temps plein

Drive Windows Security features at AMD as a Senior Technical Program Manager, collaborating with Microsoft and OEM partners.Leverage your in-depth program management and technical abilities to enha... Voir plus

 • Offre sponsorisée

Senior Manager, Information Security - C$95,000 - C$142,400 A Year

MeridianNorth York, Canada
Temps plein

The Senior Manager will lead the cybersecurity team, implement the Cyber Security Strategy, and manage incident response. Voir plus

 • Offre sponsorisée

Senior Associate, Information Security

UNAVAILABLEtoronto, on, Canada
Temps plein

Publicis Groupe is the largest Communications Group worldwide and the leader in Digital and Interactive Communications.Publicis has activities spanning 108 countries on five continents and employs ... Voir plus

 • Offre sponsorisée

Senior Security Architect – Enterprise Security & DevSecOps

VancityToronto, ON, CA
Temps plein

A member-owned credit union is seeking a Senior Security Architect to design and implement secure technology solutions.This role includes mentoring junior architects, leading security assessments, ... Voir plus

 • Offre sponsorisée

Manager Of Information Security - $112,583 - $162,125 A Year

MorningstarToronto County, Canada
Temps plein

Leads and manages the Information Security Compliance team, ensuring compliance, privacy, and protection across the enterprise.Acts as a liaison between Information Security and Business, manages a... Voir plus

 • Offre sponsorisée

SENIOR SPECIALIST Cyber Architecture

City of TorontoToronto, ON, CA
Temps plein

SENIOR SPECIALIST Cyber Architecture.Consider Your Role with Aliant Resources and Our Municipal Government Client The City of Toronto.Aliant Resources is a dedicated provider of IT staffing service... Voir plus