Director Information Security
Navacord · Toronto, Ontario, Canada
Apply & track with Apply EdgeWHY THIS ROLE MATTERS : The Director, Information Security is responsible for strengthening the organization's cybersecurity posture through risk management, security governance, policy development, and the delivery of cybersecurity initiatives. This role partners closely with business stakeholders, technology teams, third-party providers, and managed security service providers (MSPs) to assess risk, implement controls, and ensure compliance with security standards and regulatory requirements.WHAT YOU’LL BE RESPONSIBLE FOR:Policy & Standards
- Develop, review, and maintain security policies, standards, and procedures aligned with industry frameworks (NIST, ISO 27001, CIS, SOC 2, etc.)
- Ensure policies stay current with regulatory, contractual, and business requirementsRisk Assessment & Advisory
- Assess security controls, gaps, and risk for new technologies, projects, and initiatives
- Evaluate third-party/vendor security controls and manage vendor risk assessments
- Conduct enterprise and project-level risk assessments
- Serve as a security advisor to business and engineering teams on control design and risk trade-offs
- Create and manage exception registryRisk Governance
- Establish and maintain a risk register; track identified risks through remediation or acceptance
- Manage the security exception process, including intake, review, approval, and tracking
- Own risk reporting to leadership, risk committees, and the board as neededAudit & Compliance
- Serve as primary point of contact for internal and external security audits
- Respond to customer security questionnaires and due diligence requests
- Support certification and compliance efforts (SOC 2, ISO 27001, etc.)
- Strategy
- Contribute to and help build the organization's security strategy and roadmap
- Identify emerging risks and recommend program improvementsCyber Program Delivery OverviewContributing, tracking and monitoring delivery of key cyber programs aligned to Cyber strategy and roadmap.Ensure costs are captured and reported on a timely basisIncident ManagementAssist on all cyber events as it pertains to investigation, coordinating, and reportingWHAT YOU BRING TO THE ROLE:
- 8+ years in information security, with 3+ years in a governance, risk, or advisory leadership role
- Strong knowledge of security frameworks (NIST CSF, ISO 27001, SOC 2, CIS Controls)
- Experience running risk registers, exception processes, and vendor risk programs
- Experience with audits and customer security due diligence
- Strong communication skills; able to translate technical risk for executive audiences
- Relevant certifications preferred (CISSP, CISM, CRISC)WHAT WE OFFER:
- Health and Dental Benefits
- RRSP Match Program
- Bonus
- Hybrid Work Environment
- Paid Vacation Time
- Sick Days
- Additional PTO availableThis is for a new role.Navacord DOES NOT utilize artificial intelligence in the screening, assessment, or selection of applicants for this position