Director, Information Security Governance

2 days ago


Waterloo, Canada MCAP Full time

**Director, Information Security Governance**

**MCAP at a Glance**

Joining MCAP means you will be a part of our diverse workforce of highly talented individuals who are recognized for their expertise and success At MCAP, your professional expertise, commitment to teamwork and passion for service excellence are recognized and rewarded with competitive total rewards offering, a career with continuous learning and development (formal & informal training), and exciting opportunities in a dynamic, entrepreneurial environment.

**The Role**

This position will be accountable for governance, risk, and control activities within MCAP’s Information Security program.

The role will be responsible for leading a team of professionals to build and maintain these programs.

You will act as a trusted advisor, ensuring that governance, risk, and compliance issues are identified, understood, and managed effectively within the information security program. You will provide communication and education to raise awareness and will effectively promote a culture of compliance and control and actively identify business process improvement opportunities.

This position will be accountable for cyber threat and risk assessments and risk monitoring. This will involve evaluation of threats and risks to the confidentiality, integrity and availability of MCAP assets and documenting the required capabilities and control measures to mitigate risks.

This position will be accountable for establishing capabilities to reduce the risks of data loss prevention in order to prevent unintended or risk data exposure.

This position will be accountable to ensure that controls are established, measured and maintained and comply with regulatory and industry best practices.

**Training and Education**
- Ensure MCAP’s enterprise level security awareness program is created, delivered, maintained and measured.
- Ensure awareness training and education provided to specialized areas (e.g. phishing campaigns, secure code development).
- Shift enterprise mindset to ‘security by design’.

**Risk Management & Policy**
- Create, maintain and evaluate security policies, standards and procedures to provide the direction for the information security program.
- Ensure policies are being followed, correcting violations as well as approving and tracking exceptions
- Evaluate threats and risks to the confidentiality, integrity and availability of information assets
- Ongoing review of identified risks to identity and respond to changes in risk landscape
- Create and maintain KRI’s to describe our risk posture.

**Compliance, Audit & Review**
- Track compliance obligations and monitor organizational adherence, making recommendations to meet new or changing requirements
- Review current state of compliance adherence, identify gaps and recommend gap-closure initiatives
- Evaluate risks associated with third-party suppliers and partner with vendor owner for response and remediation.

**Data Security**
- Identify and implement capabilities to help reduce and or prevent sensitive data from being inappropriately shared, transferred or used.
- Identify and implement capabilities to Monitor and control data movement within and outside, aiming to protect against data breaches.
- Restrict data use and transfer according to data sensitivity and handling instructions to prevent unintended or risk data exposure.

**What You Bring To The Team**
- 10+ years in information security with a focus on governance, risk and compliance
- Strong knowledge in security governance, risk and compliance practices & frameworks (e.g. NIST, ISO, CIS)
- Strong knowledge of enterprise business continuity processes, procedures, and standards
- Multiple years of experience with incident response and frameworks
- Team management
- Demonstrated ability to create and maintain corporate level security and privacy policy, procedures, etc
- Creation and management of security awareness training programs
- Proven experience in developing a framework for process managing, monitoring, training and auditing
- Demonstrated ability to effectively engage leadership at all levels and to navigate through a large organization
- Demonstrated talent for building relationships, fostering collaboration, leading transformational change;
- Experience in the Finance Services industry mortgages
- Experience and general knowledge of security tools and technology
- Experience and general knowledge of systems, networks and cloud architectures
- Experience with risk analysis, penetration testing, and vulnerability management
- Experience and knowledge with information security and IT governance frameworks (e.g. CIS, NIST, ISO, SOC2, COBIT, ITIL)
- Minimum knowledge of cloud native development practices and design patterns using private or public cloud providers required
- Basic understanding of cloud patterns and infrastructure management using private or public cloud providers required
- Ability to prioritize in a dynamic, strate



  • Waterloo, Ontario, NVK, Canada Waystone Governance Ltd. Full time $60,000 - $90,000 per year

    Waystone leads the way in specialist services for the asset management industry. Partnering institutional investors, investment funds and asset managers, Waystone builds, supports and protects investment structures and strategies worldwide. With over 20 years' experience and a comprehensive range of specialist services to its name, Waystone is now serving...


  • Waterloo, Ontario, Canada Sun Life Full time $65,000 - $105,000

    You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...


  • Waterloo, Canada Sandvine Full time

    **Transform the way the world runs networks** **The Opportunity** The Internal Auditor, Information Security will be responsible for management of the internal ISMS audit policies and procedures including planning and execution of annual and adhoc audits as needed. They will also be responsible for issuing and monitoring the correction of nonconformities,...


  • Waterloo, Canada Sun Life Full time

    You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...


  • Waterloo, Canada Sun Life Full time

    You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...


  • Waterloo, Canada IMS Full time

    **Company Overview** At IMS, we're transforming the way the world drives. As a leading provider of connected car and telematics solutions, we deliver cutting-edge services and analytics to insurers, governments, and enterprises worldwide. Our cloud-based DriveSync® platform is at the heart of what we do - an industry-recognized solution that empowers...


  • Waterloo, Canada Equitable CA Full time

    At Equitable, we realize that your work life is not just about performing a job; it's about being part of a workplace that helps you grow and reach your full potential. Within our friendly and collaborative work environment, we recognize that the key to our growth and success is a dedicated, motivated and client-responsive staff. Join Equitable...


  • Waterloo, Canada Trustwave Full time

    About Trustwave The Information Security Advisor function provides a single point of contact for all security-related activities for designated customer accounts, and takes a key leadership role by providing extensive hands-on guidance in the development and implementation of security policies as related to designated accounts. The role extends further by...


  • Waterloo, Canada Trustwave Full time

    About Trustwave The Information Security Advisor function provides a single point of contact for all security-related activities for designated customer accounts, and takes a key leadership role by providing extensive hands-on guidance in the development and implementation of security policies as related to designated accounts. The role extends further by...


  • Waterloo, Ontario, Canada Carta Full time $120,000 - $200,000 per year

    The Company You'll JoinCarta connects founders, investors, and limited partners through world-class software, purpose-built for everyone in venture capital, private equity and private credit. Trusted by 65,000+ companies in 160+ countries, Carta's platform of software and services lays the groundwork so you can build, invest, and scale with...