Senior Manager, Information Security & IT
The Opportunity
Our client is an established and growing technology company. Reporting to the CITO, they are hiring a Senior Manager, Information Security & IT to lead the information security program while providing leadership to the corporate IT function. You will take ownership of security governance, cyber risk and compliance, cybersecurity preparedness and response, and core security practices, while leading the team responsible for day-to-day corporate technology.
This is a hybrid role working three days per week on site in Toronto.
Why this role?
This is an opportunity to take meaningful ownership of two functions that are essential to how a growing technology company operates, protects its business, and scales. You will lead the information security program while providing leadership to corporate IT, giving you the scope to shape priorities, strengthen foundational practices, and build more effective and scalable ways of working across both functions.
Your influence will extend from day-to-day operations to the highest levels of the organization. You will provide executive leadership and the Audit Committee with clear insight into security risk, compliance, and priorities, helping inform decisions about where the business needs to invest and evolve. At the same time, you will remain close to the work, leading cybersecurity preparedness and response, advancing identity, endpoint, vulnerability, and monitoring practices, and guiding the team responsible for the technology employees rely on every day.
This is an opportunity to make a visible impact. You will have the autonomy to strengthen the company’s security posture, mature security and IT operations, develop the team, and introduce practical improvements that support the organization as it continues to grow and evolve.
As their new Senior Manager, Information Security & IT, you will:
- Lead information security. You will own and evolve the company’s information security program, setting priorities across governance, risk management, policies, controls, and security practices. You will take a practical, risk-based approach to strengthening the organization’s overall security posture.
- Drive compliance and assurance. You will lead security compliance and assurance activities across SOC 2, HIPAA, GDPR, CCPA, audits, penetration testing, customer security reviews, and cyber insurance requirements. You will ensure requirements are understood, controls are effective, and the organization is prepared to demonstrate its security practices to customers, auditors, and other stakeholders.
- Strengthen security operations. You will oversee identity and access management, endpoint security, vulnerability management, and security monitoring across the corporate environment. You will identify gaps, prioritize improvements, and strengthen the practices and controls that protect the organization, its systems, and its information.
- Lead incident preparedness and response. You will own cybersecurity incident response, ensuring the organization is prepared to respond effectively when issues arise. You will lead escalation, remediation, and follow-up, bringing the right people together and ensuring lessons learned translate into stronger practices.
- Lead corporate IT. You will lead and develop the corporate IT team and oversee employee technology, SaaS administration, onboarding and offboarding, and core IT operations. You will create clarity around priorities while helping the team deliver reliable, secure, and effective technology support across the organization.
- Improve how security and IT operate. You will manage security and IT vendors and identify opportunities to improve effectiveness, automation, and cost. You will balance immediate operational needs with longer-term improvements that make both functions more scalable and efficient.
- Communicate risk and priorities. You will provide clear reporting on security risk, compliance, and key priorities to executive leadership and the Audit Committee. You will translate complex security and technology considerations into practical insights that support informed decision-making.
You bring:
- The experience. You have progressive experience across information security and corporate IT, with meaningful responsibility in both areas. You have led security programs, risk management and compliance initiatives, and cybersecurity incident response, while also overseeing modern corporate technology environments and IT teams.
- The security and compliance knowledge. You bring strong knowledge of identity and access management, endpoint security, SaaS environments, vulnerability management, security monitoring, and controls. You have working knowledge of frameworks and requirements such as SOC 2, HIPAA, GDPR, and CCPA and understand how to translate them into practical security and compliance practices.
- The technical judgment. You can assess risk, make thoughtful trade-offs, and determine where attention and investment will have the greatest impact. You are comfortable moving between strategic priorities and hands-on problem-solving when the situation calls for it.
- The leadership. You know how to provide direction, develop people, and create accountability while staying connected to the day-to-day realities of the team. You can bring structure and focus to evolving security and IT priorities while supporting a responsive, effective corporate technology function.
- The communication skills. You can translate complex security, risk, and technology topics into clear, practical information for different audiences. You are comfortable working with technical teams, executives, auditors, customers, and external partners, building trust and helping stakeholders understand risks, priorities, and recommended actions.
Compensation:
The base salary range for this position is $150,000 - $165,000, plus bonus.
Your compensation will be determined based on your skills and experience, as well as the scope and complexity of the role. We welcome open conversations about compensation and are happy to discuss the approach and overall package throughout the hiring process.
Apply now.
We encourage applications from candidates who reflect the diversity of the communities we serve, particularly individuals from Black, Indigenous, and racialized communities, persons with disabilities, 2SLGBTQIA+ individuals, and those with lived experience. If you have 70% of the qualifications we are looking for, we encourage you to apply to express your interest.
What you can expect from the interview process:
- A virtual interview with a Talent Advisor to discuss your interest in joining the company and in the role. The conversation will be recorded using BrightHire, an AI-powered video interview tool. More details will be shared when you are invited to interview.
- A virtual interview with the Hiring Manager focused on your information security and corporate IT leadership experience, your approach to managing cyber risk and compliance, and how you lead security and IT priorities across the organization.
- A final interview with key business partners, providing an opportunity to discuss your approach, leadership style, and how you would collaborate across the organization to strengthen information security and corporate IT.
Should you require accommodation in any aspect of the selection process, please contact us at [email protected], and we will be happy to help.
#LI-Hybrid
#LI-DNI