Skip to content
Corpshore Canada

IT outsourcing

Information Security Manager

About the role

You will own information security for Corpshore Canada, and you will spend a meaningful share of your time proving that posture to other people's risk committees. In an outsourcing business, security is not only a control function. It is a commercial one, because a failed security review kills a deal before pricing is ever discussed.

What you will do

Own the information security programme covering policy, controls, monitoring, vulnerability management and incident response. Lead client security assessments, questionnaires and audits, and build the reusable evidence base that stops the same questions being answered from scratch every time. Manage the control framework and drive readiness toward SOC 2 or ISO 27001 as the business requires, and ask the operator which is targeted. Own privacy-adjacent security obligations under PIPEDA and Quebec Law 25, including breach assessment and notification processes, in partnership with the Privacy Officer. Run security awareness training across a workforce that handles client personal information daily, which is where the real risk sits. Manage third-party and supply chain security review alongside Purchasing. Lead incident response, including the client communication that follows. Support delivery teams working on client security engagements where internal capability informs external work.

What you bring

At least five years in information security with at least two owning a programme or leading a function. Practical command of security frameworks including SOC 2, ISO 27001 or NIST CSF. Experience responding to enterprise client security assessments, which is a distinct skill from running controls. Incident response experience in a real incident, not only a tabletop. Understanding of Canadian privacy law as it intersects with security. English at C1.

Nice to have

CISSP, CISM or equivalent. Experience in BPO, managed services or another environment processing third-party personal data at volume. Cloud security depth. Experience achieving a first SOC 2 or ISO certification.

What we offer

A programme to build with executive backing, because the commercial case for it is obvious here. Group health and dental benefits. RRSP participation. Funded certification and training. Direct involvement in client-facing commercial work, which most internal security roles never touch.

How to apply

PDF, DOC or DOCX, up to 10 MB.

Our process

  1. 1. Our talent team reviews every application against the role requirements.
  2. 2. Shortlisted candidates are invited to interview, which may include a role-related assessment.
  3. 3. We share the decision with everyone we interview, whether or not the application progresses.

Most decisions follow within a few weeks of the closing date. Urgent roles are prioritised.