Business Information Security Officer- Digital and Industrial Solutions
The Business Information Security Officer will lead the security strategy for digital and industrial products, ensuring security-by-design principles are embedded throughout the product lifecycle. They will govern DevSecOps practices, manage security risks, and ensure compliance with global standards while partnering with engineering and business teams.
- Hybrid
- Montréal, QC
- Posted Aug 5, 2026
- 1 position
Job summary
WHAT IF YOU COULD REDEFINE WHAT'S POSSIBLE? WITH US, YOU CAN. With us, you can. You want Purpose. Growth. Opportunity. People who get it. We are the home of ambitious, passionate, and innovative world shapers. With an unmatched breadth and depth of engineering, advisory and science-based expertise, our global minds unite to power local solutions. We are pathfinders and impact makers. We are Visioneers. We are WSP. THE OPPORTUNITY WSP's Information Security Office is responsible for deploying and governing the information security framework across both the IT organization and the wider business community. This includes the governance mechanisms, policies, processes, technologies, and training required to protect WSP information and that of our clients. As the Business Information Security Officer, Digital & Industrial Solutions; you will play a critical role in securing the digital and industrial solutions that WSP designs, develops, and brings to market. Working at the intersection of technology, security, innovation, and commercial strategy, you will help embed security, privacy, and trust into products, platforms, and services from concept through launch and ongoing operation. Partnering closely with Digital Solutions, engineering, architecture, product leadership, and customer-facing teams, you will enable innovation while ensuring solutions meet customer, industry, and regulatory security expectations. YOUR IMPACT * Serve as the primary security leader for WSP's externally facing digital and industrial products, platforms, and services. * Embed security-by-design and privacy-by-design principles throughout the entire product and solution lifecycle, from concept and development through deployment and operation. * Govern secure software development and DevSecOps practices, including threat modeling, secure coding standards, code scanning, CI/CD security controls, vulnerability management, and penetration testing. * Provide security architecture guidance for cloud-native, AI/ML, data-driven, and connected IoT/OT solutions. * Identify, assess, track, and communicate security risks while driving remediation efforts with delivery and engineering teams. * Support client engagements, proposals, due diligence activities, and security questionnaires to help position security as a business differentiator. * Establish and maintain security certifications, attestations, and compliance requirements such as ISO/IEC 27001 and SOC 2. * Oversee software supply-chain security, third-party risk assessments, and secure adoption of external technologies and services. * Monitor emerging technologies including AI, generative AI, connected infrastructure, digital twins, and operational technology, providing practical security guidance to support innovation. * Partner with the CISO and Information Security Office to ensure alignment with the Global Information Security Framework and contribute to ongoing security governance and reporting. * Champion a strong security culture by building awareness and capabilities across product, engineering, and solution teams. THE SKILLS THAT SET YOU APART * 8+ years of senior-level experience in information security, including product, application, cloud, or solution security. * Demonstrated experience securing customer-facing products, SaaS platforms, cloud services, or commercial digital solutions. * Strong knowledge of secure software development and DevSecOps practices, including threat modeling, SAST, DAST, SCA, CI/CD security, and vulnerability management. * Experience with cloud security across Azure, AWS, and/or Google Cloud platforms. * Working knowledge of application security, API security, encryption, authentication, authorization, PKI, and secure integration patterns. * Professional security certification such as CISSP, CISM, CCSP, CSSLP, or an equivalent credential. * Experience applying governance and security frameworks such as ISO/IEC 2700x, NIST, SOC 2, COBIT, and ITIL. * Strong understanding of risk management principles and their application within engineering and delivery environments. * Knowledge of privacy and cybersecurity regulations applicable to global organizations and commercial technology solutions. * Ability to influence senior leaders, customers, engineers, and business stakeholders while leading through collaboration rather than authority. * Exceptional communication, relationship-building, problem-solving, and strategic thinking skills. * Ability to work effectively across international teams and multiple time zones. PREFERRED QUALIFICATIONS * Experience with Operational Technology (OT), Industrial Control Systems (ICS/SCADA), IoT, or connected infrastructure security. * Exposure to AI/ML and generative AI security. * Experience supporting sales pursuits, customer due diligence reviews, and security assessments. * Experience obtaining or maintaining security certifications such as ISO/IEC 27001 or SOC 2 Type II. * Product management, commercial, or go-to-market experience. * Master's degree in Information Technology, Computer Science, Engineering, or a related discipline. WHY CHOOSE WSP? Why Choose WSP? We exist to shape communities to advance humanity. The brightest engineers, advisors and scientists from across the globe call WSP home. • Proudly Canadian – we are a Top 100 Employer in Canada for 2026. • A global community of brilliant minds – your next idea, mentor, or opportunity is always within reach. • Limitless opportunities start here. Whether it's across the country or around the globe, we help you tailor your role to match your ambition — because your growth drives ours. • Flexible work, real balance – we recognize the importance of balance in our lives and encourage you to prioritize the balance in yours. #WeAreWSP COMPENSATION AB, BC, NT, NU, SK & YT: $194,700 - $257,900 MB & ON: $177,600 - $244,600 NB, NL, NS, PE & QC: $175,800 - $233,500 Disclosure: The final salary awarded for this role may vary from the above range based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs. The wage range provided in this job posting may be subject to change for business purposes. READY TO SECURE WHAT'S NEXT? Join WSP and help shape the future of secure digital and industrial innovation. This is an opportunity to influence the development of cutting-edge solutions, build trust with clients around the world, and strengthen the security foundation of technologies that make a meaningful impact on communities and industries. Bring your expertise, curiosity, and leadership to a team where security enables innovation and where your contributions will help redefine what's possible. #LI-Hybrid At WSP, we exist to shape communities to advance humanity. It’s why we bring people together who are wired to solve complex challenges - engineers, scientists, advisors, and technical experts who are driven by a common passion - to redefine what’s possible and shape what comes next. We are Visioneers. As one of the world’s leading professional services firms, we partner with clients across transportation, infrastructure, environment, buildings, energy, water, mining and metals. We pair deep local knowledge with global insights to pioneer solutions designed to leave a lasting, positive impact. At WSP, you’ll join a community of brilliant minds that push boundaries every day - applying deep expertise and fuelling innovation to help create a more connected and resilient future. Here, your ideas are valued, your growth is supported, and you are encouraged to bring your authentic self to work. We empower our people to collaborate across disciplines, challenge the status quo, and shape a career with purpose. Join us. Please Note: Health and Safety is a core paramount value of WSP. Given the importance of keeping one another safe it is expected that you comply with our Health, Safety & Environment (HSE) policy at all times as well as client HSE policies when working at client locations. Full details here [https://www.wsp.com/en-ca/corporate/ca/health-safety]. Some safety-sensitive positions involve fieldwork and may include work in a variety of environmental conditions, such as remote or isolated areas, working alone, and in inclement weather (within safe and reasonable limits). WSP welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process. WSP is committed to the principles of employment equity. Only the candidates selected will be contacted. WSP does not accept unsolicited resumes from agencies. Full details here [https://www.wsp.com/en-ca/careers/notice-to-staffing-agencies].
What you’ll do
The Business Information Security Officer will lead the security strategy for digital and industrial products, ensuring security-by-design principles are embedded throughout the product lifecycle. They will govern DevSecOps practices, manage security risks, and ensure compliance with global standards while partnering with engineering and business teams.
Requirements
Candidates must have 8+ years of senior-level experience in information security, specifically within product, cloud, or application security. A professional certification such as CISSP, CISM, or CCSP is required, along with strong knowledge of secure software development and risk management frameworks.
Benefits
• Flexible work policy • Professional development opportunities • Global networking • Inclusive work environment
Listed skills
- CommunicationPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Information security
- Product security
- DevSecOps
- Cloud security
- Risk management
- Governance
- Compliance
- Threat modeling
- Software supply-chain security
- Security architecture
- Identity and access management
- Encryption
- Vulnerability management
- Strategic leadership
- Stakeholder management
- Communication
- Employment Equity
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Influencing Skills
- Go-to-Market Strategy
- Cloud-Native Computing
- Cloud Services
- Product Leadership
- Generative Artificial Intelligence
- Certified Cloud Security Professional (CCSP)
- Influencing Without Authority
- CI/CD
- Digital Twin
- Curiosity
- Security Governance
- Technology Solutions
- Emerging Technologies
- Resilience
- Google Cloud Platform (GCP)
- IT Security Architecture
- Supply Chain Security
- Infrastructure Security
- Application Programming Interface (API)
- Artificial Intelligence
- Amazon Web Services
- Penetration Testing
- Application Security
- Software Development
- Authentications
- Microsoft Azure
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Software As A Service (SaaS)
- Cloud Security
Job areas
- Technology
- Security & Safety
- Engineering
- Management & Leadership
- Consulting
- Business Information Security Officer
- Business / Management Consultant
- Management and Organization Analysts
- Management Analysts
Additional details
- Minimum education
- Master’s degree
- Minimum experience
- 10+ years
- Posting language
- English
- Working hours
- 40 hours per week
