Talent.com
Indigo
Director, Information SecurityIndigo • Toronto, ON, CA
Director, Information Security

Director, Information Security

Indigo • Toronto, ON, CA
4 days ago
Job type
  • Full-time
Job description

Company Description

Indigo is a physical and digital place inspired by and filled with books, ideas, beautifully designed lifestyle products, and the creative people who help make it all happen. We believe in real books, living life fully and generously, being kind to each other and to the environment, and that stories — big and little — connect us. Indigo is our customer's happy place — for joyful moments of discovery and to connect with people who share their passion for reading, their belief in ideas, and their commitment to making the world a better and more beautiful place.

OUR GUIDING PRINCIPLES

Our Mission is to inspire reading and enrich the lives of booklovers. As such, we believe in the power of people and their stories. We aim to attract top talent, nurture the potential of our employees, and create space for everyone to thrive. Our Guiding Principles are the few key ideas that are meant to influence everything we do, every day.

  • We Will Hire, Inspire, Promote and Retain the Best
  • We Will Be Customer Centric
  • We Will Be Entrepreneurial
  • We Will Be Committed to Caring About Each Other, Our Communities, and Our Environment
  • We Will Be Committed to True and Shared Value Creation
  • We Will Be Systems Thinking, Data Driven and AI enabled

Job Description

MISSION

Accountable for establishing and executing the enterprise information security strategy to guarantee the confidentiality, integrity, and availability of Indigo’s information assets. This role proactively manages enterprise technology risk, ensures strict compliance with regulatory and industry frameworks, and safeguards data through the leadership of Governance, Risk & Compliance (GRC), Security Architecture, and Security Operations.

KEY PERFORMANCE METRICS

  • Zero critical preventable security breaches.
  • Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) within established operational SLAs.
  • 100% compliance with critical regulatory and industry frameworks (, PCI-DSS, PIPEDA).
  • High completion rates for enterprise-wide security awareness training.

KEY ACCOUNTABILITIES

Strategic

  • Develop and implement a comprehensive enterprise information security strategy that aligns with Indigo's business objectives and risk tolerance.
  • Partner cross-functionally at the senior level to embed security-by-design principles into all foundational technology and retail store operations.
  • Set and manage operational and capital budgets to ensure the cost-effective execution of security infrastructure and compliance initiatives.

Functional

  • Enterprise Risk Management: Establish and maintain a continuous IT risk assessment framework to identify, quantify, and mitigate cybersecurity risks across retail, e-commerce, and corporate environments.
  • Regulatory Compliance: Guarantee strict adherence to critical data protection regulations and industry frameworks (, PCI-DSS, PIPEDA) through systematic control validations and comprehensive security audits.
  • Policy Governance: Formulate, publish, and enforce data-driven information security policies, standards, and operational guidelines across the organization.
  • Security Architecture Integration: Embed secure-by-design principles, NIST framework methodologies, and threat modeling into the lifecycle of all cloud, network, and retail store systems.
  • Identity & Access Management (IAM): Oversee the enforcement of Zero Trust architectures, privileged access management, and robust authentication mechanisms to protect all enterprise assets.
  • Threat Monitoring: Direct 24/7 Security Operations Center (SOC) activities, utilizing threat intelligence and data analytics to proactively detect and analyze anomalous network behavior.
  • Vulnerability Management: Execute systematic vulnerability scanning, penetration testing, and data-backed remediation prioritization to continuously reduce the organizational attack surface.
  • Incident Response: Lead the enterprise security incident response process, directing rapid containment strategies and conducting empirical root-cause analysis to prevent recurrence.
  • Security Awareness: Implement measurable, enterprise-wide security awareness training and phishing simulations to cultivate a resilient, security-first workforce.
  • Third-Party Risk Management: Assess and continuously monitor the cybersecurity posture of IT vendors, supply chain partners, and integrated platforms to ensure strict alignment with Indigo's risk tolerance.

People

  • Accountable for the overall engagement, productivity, turnover and bench strength of the team
  • Supports the creation and maintenance of a talent succession plan
  • Collaborate with others to drive flexible and iterative solutions, quickly and easily
  • Share technical knowledge with others and actively seek to learn from those more knowledgeable than yourself
  • Help others see the impacts of their efforts and proactively engage other functions to get input
  • Encourage others to freely share their point of view and be open to feedback
  • Understand and follow Indigo's core HR process - staffing, performance management, rewards, and development
  • Ensures all team members are provided with clear performance objectives that are aligned with Indigo Functional and Departmental goals
  • Has the ability to see the total organization with an integrated perspective
  • Develops positive and productive peer relationships

Cultural

  • Model Indigo’s beliefs and convey a positive image in everything you do
  • Understands/demonstrates in a manner that promotes, and is aligned with, Indigo's Mission, Vision, Beliefs
  • As a leader, hold others accountable in maintaining the integrity of Indigo's culture
  • Celebrate diversity of thought and have an open mindset
  • Take an active role in fostering a culture of continual learning, taking risks without the fear of making mistakes
  • Embrace, champion, and influence change through your team and/or the organization

SCOPE

Reports to: VP, Enterprise IT

Manager once Removed (MOR): Chief Technology & AI Officer

KEY RELATIONSHIPS

Internal:

  • IT
  • Digital
  • Finance
  • Supply Chain
  • Commercial Group
  • Creative
  • Consumer Experience
  • Human Resources
  • Retail leadership

External:

  • Approved Vendors
  • External auditors
  • Regulatory bodies

Qualifications

Work Experience / Education / Certifications

  • Bachelor's or master’s degree in computer science, Information Systems, or other related field with at least 15 years of Information Technology experience.
  • Minimum of 10 years’ experience working in a leadership position.
  • A professional certification (or suitable compensating experience) in the audit (CISA, etc) or security field (CISSP or CISM for instance) considered an asset.
  • Strong experience working with frameworks and regulations (PCI, ISO, PIPEDA, GDPR, etc).
  • Strong understanding of network design, tiered and secure architectures.

Competencies / Skills / Attributes

  • Strategic thinker with analytical and problem-solving experience.
  • A strong ability to influence and discuss complex technology problems in business language.
  • Must be an excellent and polished communicator who may be called upon to create and present materials to the Executive Committee and the Board of Directors.
  • Fast-learner and multi-tasker with the ability to adjust their outlook and leadership style to respond to quickly changing business priorities.

Create a job alert for this search

Director, Information Security • Toronto, ON, CA

Similar jobs

VP of Information Security - Pre-IPO Tech Leader

AndiamoToronto, ON, CA
Permanent

Vice President of Information Security - Pre-IPO Tech Leader.We are seeking an accomplished and technically strong.Vice President of Information Security.In this role, you will provide leadership a... Show more

 • Promoted

Director, Security Operations, Information & Corporate Security

CPP Investments | Investissements RPCToronto, ON, CA
Full-time

Make an impact at a global and dynamic investment organization.When you join CPP Investments, you are joining one of the world’s most admired and respected institutional investors.As a professional... Show more

 • Promoted

Director of Information Security Operations and Risk Management

Canada Pension Plan Investment BoardToronto, ON, CA
Full-time

Lead information security operations in a global investment firm as the Director of Security Operations.Ensure effective incident response and enhance organizational security posture.In this senior... Show more

 • Promoted

Information Security Manager Contract Role

O2E BrandsToronto, ON, CA
Temporary

Elevate your cybersecurity career with O2E Brands as an Information Security Manager on a 12-month contract.Lead and oversee critical security operations in a hybrid work environment.O2E Brands is ... Show more

 • Promoted • New!

Director, Infrastructure Security

1PasswordToronto, Ontario, Canada
Full-time

About 1Password We’re building the foundation for a safe, productive digital future by ensuring every identity is authentic, every application sign‑in is secure, and every device is trusted.Over 18... Show more

 • Promoted

Information Security Lead

Fluid - Solutions de Talents/Workforce SolutionsToronto, ON, CA
Permanent

Job Title: Information Security Lead.Our client alaw firm is seeking an Information Security Lead responsible for the security, integrity, and availability of information assets.This role drives th... Show more

 • Promoted

Manager of Information Security

Insight GlobalToronto, Ontario, Canada
Full-time

Get AI‑powered advice on this job and more exclusive features.We are seeking a Manager, Information Security to lead initiatives that strengthen fraud detection, authentication, and Customer Identi... Show more

 • Promoted

Director, Information Security Operations

GreenShieldToronto, ON, CA
Full-time

The Director, Information Security Operations is a key enterprise leader accountable for shaping and advancing GreenShield’s security strategy to safeguard digital and cyber assets in alignment wit... Show more

 • Promoted

Director, Information Security

Indigo-Books-Toronto
Full-time

Compensation: CAD 170,000 - CAD 190,000 - yearly.Indigo is a physical and digital place inspired by and filled with books, ideas, beautifully designed lifestyle products, and the creative people wh... Show more

 • Promoted

Managing Director - Information Security Technology Risk

BMOToronto, Ontario, Canada
Temporary

Provides oversight over 1st line activities establishing the risk frameworks required to mitigate Non-Financial Risk exposures, to comply with regulatory requirements, Corporate Policies, Corporate... Show more

 • Promoted

Director of IT Ops & Cyber Security, Digital Transformation

Medisca Pharmaceuticals Inc.Toronto, ON, CA
Full-time

A leading health organization in Toronto is seeking a Director of IT Technical Services & Cyber Security to shape the digital transformation portfolio.This role demands over 15 years of IT leadersh... Show more

 • Promoted

Director of Information Security Operations with Global Impact

CPP Investments | Investissements RPCToronto, ON, CA
Full-time

Join an elite investment manager as the Director of Information Security Operations, responsible for leading security initiatives and implementing cutting-edge technology safeguards.Focus on threat... Show more

 • Promoted

Director Information Security

IndigoToronto
Full-time

Accountable for establishing and executing the enterprise information security strategy to guarantee the confidentiality, integrity, and availability of Indigo’s information assets.This role proact... Show more

 • Promoted

Information Security Director Role at CarltonOne

CarltonOneMarkham, York Region, CA
Full-time

CarltonOne seeks a skilled Director of Information Security & Cyber Risk to enhance our global security programs.Lead hands-on efforts to protect customer data and manage cyber risk in a B2B techno... Show more

 • Promoted

Director, Information Security Operations

TekRekToronto, Ontario, Canada
Full-time

This organization operates in a highly regulated industry with a significant digital footprint, managing sensitive data and critical services at scale.Security is treated as a core business functio... Show more

 • Promoted

Director of Information Security in Toronto

ManulifeToronto
Full-time

Lead Manulife's Information Risk Management program as a Director of Information Security in Toronto.Drive effective governance, align security with business goals, and achieve measurable outcomes.... Show more

 • Promoted

Strategic Director, Cybersecurity & Information Security

FinanceitToronto, Ontario, Canada
Full-time

A financial services provider in Toronto is looking for a Director of Cybersecurity & Information Security to implement and monitor security programs that protect the organization.The ideal candida... Show more

 • Promoted

Director, IT Security and Infrastructure

Yorkville UniversityToronto, ON, CA
Full-time

At Yorkville University and Toronto Film School, we believe education is more than the pursuit of knowledge – it is a catalyst for transformation.Our mission, grounded in democratizing education, i... Show more

 • Promoted

Information Security Manager

Insight GlobalToronto, ON, CA
Full-time

Demonstrated history of technical leadership and strategic thinking in security roles.Extensive experience leading and managing complex security investigations and threat hunting engagements.Bachel... Show more

 • Promoted

Senior Manager, Information Security Risk & Governance

Onico SolutionsRichmond Hill, York Region, CA
Permanent

Senior Manager, Information Security Risk & Governance.The Senior Manager, Information Security Risk & Governance leads the Information Security Risk Management and Governance programs.Their main o... Show more