Information Security Manager
In an average week you will spend more time with your colleagues than you will with your family & friends, so it is important that a work environment is a good one. We understand the importance of a healthy work environment and follow some simple principles to ensure that our team environment is an enjoyable, safe space where everyone is empowered to use their intelligence, experience, and decision-making abilities to effect positive change.
- Community – It takes a team effort to reach our goals, we are all in it together. We are committed to incentives which reward the whole team when the team succeeds and continually investing in growing the skills of our team.
- Safe – We want to hear the ideas of team members, consider them without prejudice and take the time to discuss the merits of each idea. Innovation is a trial-and-error process; we accept the risks that some ideas will fail. The success of new ideas is owned by the team, but the failures are not.
- Dependable – Our teams are self-managing scrums; every team member must be able to depend on their teammates and their teammates depend on them.
- Structured – We have a clear organizational structure, roadmap, individual responsibilities, and decision-making spheres. We work together to meet our shared goals but respect each others expertise in the decisions they make.
- Impactful – We have a clear goal in our projects and the impacts of our work can be easily measured.
Our commitment to our team is to maintain a working environment that allows our team members to use all their skills and expertise in a collaborative way with other team members, to maintain a team which is greater than the sum of its parts and have fun along the way.
ABOUT THE ROLE
We are looking for an Information Security Manager, reporting to the Chief Technology Officer, to play a key role in the execution of our long-term technology strategy. The incumbent will be responsible for ensuring that best practices for information security are defined, implemented and maintained within all aspects of our infrastructure.
The primary responsibilities of the Information Security Manager are to:
- Maintain internal Information Security policies, performing regular audits of our systems and infrastructure to validate compliance with the policies.
- Maintain our Information Security Incident Response Plan, ensuring the plan remains aligned with our evolving infrastructure, legal and regulatory obligations, and industry best practices.
- Continually research evolving cybersecurity risk mitigation techniques, software updates and emerging tools that may be applicable to improving our overall security posture.
- Collaborate with internal software development teams, IT Services, and IT Solutions teams to ensure that information security best practices are incorporated into all activities.
- Perform regular penetration tests to validate our security posture is robust.
WHAT YOU BRING
- 5+ years experience as an information security practitioner.
- Extensive knowledge of security best practices in a Windows environment, both server and endpoints.
- Extensive knowledge of network security best practices, specifically with Cisco solutions.
- Hands on experience applying information security best practices to cloud solutions, i.e., O365 and Azure.
- Hands on experience with next generation security solutions, e.g., Cylance, Crowdstrike, Darktrace.
- A bachelor’s degree in Computer Science or Management Information Systems or above (or equivalent).
- A relevant certification in information security, such as CISSP.
NOT REQUIRED BUT NICE TO HAVE
- Experience with threat modelling frameworks, e.g., MITRE ATT&CK, STRIDE.
- Cisco professional certification, i.e., CCNA or CCNP.
- Hands on experience administering Security Awareness Training programs.
- Experience with Red team attacks or tabletop exercises.
- Experience in the Insurance or Financial Services industries.
- Bilingualism (French and English).
WHAT WE OFFER
We offer a great package to our team members, including:
- Competitive salary and bonus
- Vacation and additional personal leave
- RRSP matching
- Company cell phone
- Full group benefits (50% paid by us)
- AAA office space in the heart of Montreal or Napierville
- Work from home and set your own schedule flexibility