Director of Information Security
The Director of Information Security will develop and execute the organization's cybersecurity strategy and roadmap. They will lead governance, risk management, compliance, and security operations to protect critical business assets.
- On-site
- Toronto, ON
- Posted Aug 27, 2026
- Apply by Sep 26, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
About the Opportunity Our client is seeking an accomplished cybersecurity leader to establish, mature, and continuously evolve their enterprise security program. This individual will be responsible for protecting critical business systems and information assets while ensuring security practices support broader business objectives. Reporting to executive leadership, the successful candidate will lead governance, risk management, security operations, compliance programs, incident response, and security architecture initiatives across a complex enterprise environment. This role requires a strategic mindset along with hands on technical experience in the cybersecurity space. What You'll Be Doing Develop and execute the organization's information security roadmap and long-term cybersecurity strategy. Lead enterprise-wide risk management and security governance programs. Partner with business and technology stakeholders to embed security requirements into projects and operational processes. Oversee compliance initiatives involving privacy, regulatory, and industry security standards. Direct vulnerability management, threat monitoring, security investigations, and incident response activities. Establish and maintain security policies, standards, and operational procedures. Drive identity and access management initiatives, including privileged access controls and modern authentication practices. Evaluate and manage third-party security risk across vendors and strategic partners. Lead employee security awareness programs and promote a security-first culture. Manage security budgets, resource planning, vendor relationships, and security investments. Build, mentor, and develop a high-performing information security team. What We're Looking For 15+ years of a combination of Technology and Cybersecurity experience. 5+ years of leadership experience managing security teams and enterprise initiatives. Strong background in cybersecurity governance, risk management, compliance, and security operations. Experience working with frameworks and regulatory requirements such as ISO 27001, NIST, PCI DSS, PIPEDA, GDPR, or similar standards. Must have experience implementing GRC policies and procedures. Solid understanding of enterprise infrastructure, cloud security, network architecture, and modern security controls. Proven ability to communicate security risks and recommendations to executive and board-level stakeholders. Strong relationship-building, leadership, and change-management skills. CISSP, CISM, CISA, or similar certifications are considered assets.
What you’ll do
The Director of Information Security will develop and execute the organization's cybersecurity strategy and roadmap. They will lead governance, risk management, compliance, and security operations to protect critical business assets.
Requirements
Candidates need over 15 years of technology and cybersecurity experience, including at least 5 years in a leadership role. Proficiency in security frameworks like ISO 27001 and NIST, along with certifications like CISSP or CISM, is highly valued.
Listed skills
- CompliancePreferred
- Risk ManagementPreferred
- Team LeadershipPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Strategy
- Risk Management
- Security Governance
- Compliance
- Incident Response
- Security Architecture
- Vulnerability Management
- Identity And Access Management
- Third-Party Risk Management
- Security Awareness
- Budget Management
- Team Leadership
- Cloud Security
- Network Architecture
- GRC Policies
- Stakeholder Communication
Job areas
- Security & Safety
- Technology
- Management & Leadership
- Retail
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 10+ years
- Apply by
- Sep 26, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Director
- Application method
- Direct apply is available
