Head of Information Security

Found in: Jooble CA O C2 - 2 weeks ago


Montréal QC, Canada WSP Full time
Head of Information Security / VP of Information Security [OneIT]

WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.

The role of Head of Information Security reports to our Chief Information Security Officer and is responsible for leading a team of Business and Regional Information Security Officers across WSPs global business. It is a primarily internally facing role, though it may involve some interaction with clients and third parties.

This position requires a senior management professional with relevant experience and a strong working knowledge of IT security, risk management, regulatory compliance, information and public cloud service technology, IT operations management principles, and third-party security management.

Responsibilities :

  • Information Security Strategy: Collaborate with the CISO to define the organization's information security strategy, vision, and goals. Translate strategic objectives into actionable plans and initiatives that align with business objectives and industry best practices.
  • Team Leadership: Lead and manage a team of Information Security Officers located across WSPs regions. Provide guidance, mentorship, and support to ensure their professional development and effective execution of their responsibilities.
  • Information Security Governance: Oversee WSPs implementation and maintenance of itsISO27001 certified Data and Information Security Management System. Establish and maintain theInformation Security Governance framework; including running theInformation Security Committees; coordinating IS risk management, executive reporting and participate in other forums where information security input and approval is required based on documented policies and processes.
  • Risk Management: Oversee the identification, assessment, and mitigation of information security risks. Work closely with cross-functional teams to ensure risk management practices are embedded in business processes and projects. Monitor the effectiveness of risk mitigation measures and drive continuous improvement.
  • Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs to promote a security-conscious culture throughout the organization. Collaborate with stakeholders to address security education needs and ensure employees understand their roles and responsibilities in protecting information assets.
  • Acquisition, Mergers and Integrations: Direct the security matters relating to all aspects of Acquisitions, Mergers, Integrations and Divestments. Including the security evaluation of potential acquisitions through to the integration of the acquired businesses into WSP’s security ecosystem.
  • Client Support: Develop and maintain a program of client support, to ensure that all client security requirements are identified, assessed, delivered and reported to relevant business leaders.
  • Vendor and Third-Party Risk Management: Develop and maintain a robust vendor and third-party risk management program. Conduct assessments of vendors and service providers to ensure they meet information security requirements and adhere to contractual obligations.
  • Incident Response and Management: Develop and maintain an incident response plan and coordinate the response to information security incidents. Lead investigations, root cause analyses, and corrective actions to mitigate the impact of incidents and prevent future occurrences.
  • Security Incident Reporting and Metrics: Develop and maintain metrics, reports, and dashboards to track the effectiveness of the information security program. Provide regular updates to senior leadership on the organization's security posture and recommend remedial actions as needed.

Leadership and People Responsibilities:

  • Displays personal and team leadership in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • Assist in the training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.
  • Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands.
  • Capable of rapidly assimilating and internalizing complex business, technology, and risk management concepts and dependencies.
  • Capable of clearly defining, presenting and selling recommended strategies to senior management teams.
  • Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals.
  • Accommodation of schedule for international conference calls.

Finance/Budgetary Responsibilities:

  • Support the CISO in developing the budget projections based on objectives
  • Responsible for the budget for the Information Security Office

Requirements:

Required

  • 10+ years related senior level experience in Information Security, IT risk, IT Audit or a similar position involving IT and business change, including leading a team of IT professionals.
  • Graduate of a four-year college or university, preferably with a degree in computer science or information management, or Professional certification in one or more of the following disciplines — IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA).
  • Working (not necessarily technical) knowledge of security technologies (encryption, data protection, network intrusion prevention, host intrusion prevention, firewalls, privilege access, etc.)
  • Working (not necessarily technical) knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, PKI, IPSec, Firewall, SSH, SSL, DES, LAN/WAN, and TCP/IP
  • Knowledge of security best practices (applications, network and client setups)
  • Experience with IT Governance frameworks such as COBIT, ITIL and ISO 2700x
  • Experience with governance, compliance and audit within IT environments
  • Experience of risk management, including risk analysis, mitigation and monitoring
  • Knowledge of information security regulations applicable to WSP
  • Fluent Bilingual English and French

Preferred

  • Master's degree in IT, Computer Science, Engineering or related field

WSPis one of the world's leading professional services firms. Our purpose is to future proof our cities and environments.

We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation networks, from finding new ways to extract essential resources to developing renewable power sources for the future.

AtWSP:

  • We value ourpeople and our reputation
  • We are locally dedicated with international scale
  • We are future focused and challenge the status quo
  • We foster collaboration in everything we do
  • We have an empowering culture and hold ourselves accountable
Position Summary

WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.

The role of Head of Information Security reports to our Chief Information Security Officer and is responsible for leading a team of Business and Regional Information Security Officers across WSPs global business. It is a primarily internally facing role, though it may involve some interaction with clients and third parties.

This position requires a senior management professional with relevant experience and a strong working knowledge of IT security, risk management, regulatory compliance, information and public cloud service technology, IT operations management principles, and third-party security management.

Responsibilities :

  • Information Security Strategy: Collaborate with the CISO to define the organization's information security strategy, vision, and goals. Translate strategic objectives into actionable plans and initiatives that align with business objectives and industry best practices.
  • Team Leadership: Lead and manage a team of Information Security Officers located across WSPs regions. Provide guidance, mentorship, and support to ensure their professional development and effective execution of their responsibilities.
  • Information Security Governance: Oversee WSPs implementation and maintenance of itsISO27001 certified Data and Information Security Management System. Establish and maintain theInformation Security Governance framework; including running theInformation Security Committees; coordinating IS risk management, executive reporting and participate in other forums where information security input and approval is required based on documented policies and processes.
  • Risk Management: Oversee the identification, assessment, and mitigation of information security risks. Work closely with cross-functional teams to ensure risk management practices are embedded in business processes and projects. Monitor the effectiveness of risk mitigation measures and drive continuous improvement.
  • Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs to promote a security-conscious culture throughout the organization. Collaborate with stakeholders to address security education needs and ensure employees understand their roles and responsibilities in protecting information assets.
  • Acquisition, Mergers and Integrations: Direct the security matters relating to all aspects of Acquisitions, Mergers, Integrations and Divestments. Including the security evaluation of potential acquisitions through to the integration of the acquired businesses into WSP’s security ecosystem.
  • Client Support: Develop and maintain a program of client support, to ensure that all client security requirements are identified, assessed, delivered and reported to relevant business leaders.
  • Vendor and Third-Party Risk Management: Develop and maintain a robust vendor and third-party risk management program. Conduct assessments of vendors and service providers to ensure they meet information security requirements and adhere to contractual obligations.
  • Incident Response and Management: Develop and maintain an incident response plan and coordinate the response to information security incidents. Lead investigations, root cause analyses, and corrective actions to mitigate the impact of incidents and prevent future occurrences.
  • Security Incident Reporting and Metrics: Develop and maintain metrics, reports, and dashboards to track the effectiveness of the information security program. Provide regular updates to senior leadership on the organization's security posture and recommend remedial actions as needed.

Leadership and People Responsibilities:

  • Displays personal and team leadership in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • Assist in the training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.
  • Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands.
  • Capable of rapidly assimilating and internalizing complex business, technology, and risk management concepts and dependencies.
  • Capable of clearly defining, presenting and selling recommended strategies to senior management teams.
  • Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals.
  • Accommodation of schedule for international conference calls.

Finance/Budgetary Responsibilities:

  • Support the CISO in developing the budget projections based on objectives
  • Responsible for the budget for the Information Security Office

Requirements:

Required

  • 10+ years related senior level experience in Information Security, IT risk, IT Audit or a similar position involving IT and business change, including leading a team of IT professionals.
  • Graduate of a four-year college or university, preferably with a degree in computer science or information management, or Professional certification in one or more of the following disciplines — IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA).
  • Working (not necessarily technical) knowledge of security technologies (encryption, data protection, network intrusion prevention, host intrusion prevention, firewalls, privilege access, etc.)
  • Working (not necessarily technical) knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, PKI, IPSec, Firewall, SSH, SSL, DES, LAN/WAN, and TCP/IP
  • Knowledge of security best practices (applications, network and client setups)
  • Experience with IT Governance frameworks such as COBIT, ITIL and ISO 2700x
  • Experience with governance, compliance and audit within IT environments
  • Experience of risk management, including risk analysis, mitigation and monitoring
  • Knowledge of information security regulations applicable to WSP
  • Fluent Bilingual English and French

Preferred

  • Master's degree in IT, Computer Science, Engineering or related field

WSPis one of the world's leading professional services firms. Our purpose is to future proof our cities and environments.

We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation networks, from finding new ways to extract essential resources to developing renewable power sources for the future.

AtWSP:

  • We value ourpeople and our reputation
  • We are locally dedicated with international scale
  • We are future focused and challenge the status quo
  • We foster collaboration in everything we do
  • We have an empowering culture and hold ourselves accountable
Please Note:
Health and Safety is a core paramount value of WSP. Given the importance of keeping one another safe it is expected that you comply with our Health, Safety & Environment (HSE) policy at all times as well as client HSE policies when working at client locations.

Offers of employment for safety-sensitive positions involving fieldwork are contingent upon candidates being able to perform key physical tasks of the job as described in the job posting and interview. This may include the ability to work in a variety of environmental conditions, such as remote or isolated areas, working alone, and in inclement weather (within safe and reasonable limits).

WSP welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.

WSP is committed to the principles of employment equity. Only the candidates selected will be contacted.

WSP does not accept unsolicited resumes from agencies. For more information please READ THE FULL POLICY.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr
  • Business Information Security Officer

    Found in: Jooble CA O C2 - 1 week ago


    Montréal, QC, Canada WSP Full time

    Position Summary WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our...

  • Information Security Specialist

    Found in: Jooble CA O C2 - 6 days ago


    Montréal, QC, Canada Banque de développement du Canada Full time

    We are banking at another level. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs. Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a...

  • Information Security Manager

    Found in: Jooble CA O C2 - 1 week ago


    Montréal, QC, Canada Barclay Simpson Full time

    Senior Information Security Manager required for a market-leading bank. The role will be focused on supporting the information security function with the management of 2 analysts. Responsibilities Adherence to the Information Security Standards by control owners Training and Awareness Programme Phishing Tests of staff, reporting and training ...


  • Montréal, Canada EDGE10 Group Full time

    EDGE10[DL1] Group is perfecting human performance. We provide the world's leading health, performance and physical testing platform to organisations around the world, empowering them with actionable insights, leading to efficient, high quality decision making. As market leader, we work with organisations across the medical and performance spectrums, from...

  • Security Researcher

    Found in: Jooble CA O C2 - 1 week ago


    Montréal, QC, Canada Ubisoft Entertainment Full time

    Ubisoft’s 19,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance, Rainbow Six, and many more to...

  • Security Researcher

    Found in: Jooble CA O C2 - 1 week ago


    Montréal, QC, Canada Ubisoft Full time

    Ubisoft Welcome to the official website for Ubisoft, creator of Assassin's Creed, Just Dance, Tom Clancy's video game series, Rayman, Far Cry, Watch Dogs and many others. Learn more about our breathtaking games here! View company page Ubisoft’s 19,000 team members, working across more than 30 countries around the world, are bound by a common...


  • Montréal, Canada Desjardins Full time

    At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should...

  • Consultant, Information Security

    Found in: Jooble CA O C2 - 1 week ago


    Brossard, QC, Canada CIBC Full time

    CIBC Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered. View company page We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients. At CIBC, we embrace your strengths and your...

  • Information Security Analyst

    Found in: Jooble CA O C2 - 6 days ago


    Brossard, QC, Canada Aviva Full time

    Aviva Our global corporate website for investors, shareholders, career hunters, the media and people interested in our social purpose. View company page Individually we are people, but together we are Aviva. Individually these are just words, but together they are our Values – Care, Commitment, Community, and Confidence. The Identity and Access...

  • Information Technology

    Found in: Jooble CA O C2 - 1 week ago


    Brossard, QC, Canada Hydro One Full time

    Hydro One is proud to be the largest electricity transmission and distribution provider in Ontario, serving nearly 1.4millioncustomers. Since then, we have worked to grow and evolve to meet the changing needs of our customers and communities across Ontario. Today, we’re focused on providing exceptional customer service and ensuring we are building safe...


  • Montréal, Canada ilir inc Full time

    Durée de l'emploi: Permanent - Langue de travail: Français - Heures de travail: 40 hours per week - Education: - Expérience: **Education**: - Bachelor's degree - Information technology - or equivalent experience **Work setting**: - Consulting firm **Tasks**: - Confer with clients to identify requirements - Document technical requirements to ensure...

  • Sr. Analyst, Information Security

    Found in: Jooble CA O C2 - 5 days ago


    Brossard, QC, Canada CIBC Full time

    CIBC Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered. View company page We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients. At CIBC, we embrace your strengths and your...

  • Security Researcher

    5 days ago


    Montréal, Canada Ubisoft Full time

    Company Description Ubisoft’s 20,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance, Rainbow...

  • Security Researcher

    2 days ago


    Montréal, Canada Ubisoft Full time

    Company Description Ubisoft’s 20,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance, Rainbow...

  • CATEGORY MANAGEMENT LEAD

    Found in: Jooble CA O C2 - 2 weeks ago


    Brossard, QC, Canada City of Toronto Full time

    CATEGORY MANAGEMENT LEAD (Information Technology & Cyber Security Categories) Job Category: Finance, Accounting & Purchasing Work Location: City Hall,100 Queen Street West Job Type & Duration: Full-Time,PermanentVacancy Shift Information: Monday to Friday, 35 hours per week Affiliation: Non-Union Number of Positions Open: 1 Posting Period:02-Feb-2024to...


  • Montréal, Canada Laurentian Bank Full time

    Seeing beyond numbers **TM** At Laurentian Bank, we believe we can change banking for the better. Founded in Montreal in 1846, Laurentian Bank helps families, businesses and communities thrive. Today, we have over 3,000 employees working together as One Team, to provide a broad range of financial services and advice-based solutions for customers across...


  • Montréal, Canada Fivesky Full time

    Do you work with Global cybersecurity teams to assess, guide and rewrite policies and standards? Are you collaborating at all levels within your organization to enhance policies, ensure compliance, and support policy adoption efforts? If this sounds like you, you might be Fivesky's **_Information Security Policy Analyst!_** **Who you are**: - 5-7 + years...


  • Montréal, Canada Fivesky Full time

    Do you work with Global cybersecurity teams to assess, guide and rewrite policies and standards? Are you collaborating at all levels within your organization to enhance policies, ensure compliance, and support policy adoption efforts? If this sounds like you, you might be Fivesky's **_Information Security Policy Analyst!_** **Who you are**: - 5-7 + years...

  • Economist/Head of Research

    Found in: Jooble CA O C2 - 2 weeks ago


    Montréal, QC, Canada Fednav Limited Full time

    Economist/Head of Research page is loaded Economist/Head of Research Apply locations Montreal time type Full time posted on Posted 8 Days Ago job requisition id JR100237 Fednav, headquartered in Montreal, is the largest international dry bulk shipping group in Canada engaged in worldwide ocean transportation. Fednav has five international offices...

  • Head of Devops

    Found in: Jooble CA O C2 - 1 week ago


    Montréal, QC, Canada Alteo Inc. Full time

    Job Description Alteo is looking for an IT Director for a permanent position based in Montreal. Your primary role will be to manage the operation and delivery of IT services. You will report to the Senior Director, Technologies, and manage three department heads in charge of IT infrastructure and operations, software development, and business intelligence....