Impartition TI
Gestionnaire de la sécurité de l'information
À propos du poste
You will own information security for Corpshore Canada, and you will spend a meaningful share of your time proving that posture to other people's risk committees. In an outsourcing business, security is not only a control function. It is a commercial one, because a failed security review kills a deal before pricing is ever discussed.
Vos responsabilités
Own the information security programme covering policy, controls, monitoring, vulnerability management and incident response. Lead client security assessments, questionnaires and audits, and build the reusable evidence base that stops the same questions being answered from scratch every time. Manage the control framework and drive readiness toward SOC 2 or ISO 27001 as the business requires, and ask the operator which is targeted. Own privacy-adjacent security obligations under PIPEDA and Quebec Law 25, including breach assessment and notification processes, in partnership with the Privacy Officer. Run security awareness training across a workforce that handles client personal information daily, which is where the real risk sits. Manage third-party and supply chain security review alongside Purchasing. Lead incident response, including the client communication that follows. Support delivery teams working on client security engagements where internal capability informs external work.
Votre profil
At least five years in information security with at least two owning a programme or leading a function. Practical command of security frameworks including SOC 2, ISO 27001 or NIST CSF. Experience responding to enterprise client security assessments, which is a distinct skill from running controls. Incident response experience in a real incident, not only a tabletop. Understanding of Canadian privacy law as it intersects with security. English at C1.
Atouts supplémentaires
CISSP, CISM or equivalent. Experience in BPO, managed services or another environment processing third-party personal data at volume. Cloud security depth. Experience achieving a first SOC 2 or ISO certification.
Ce que nous offrons
A programme to build with executive backing, because the commercial case for it is obvious here. Group health and dental benefits. RRSP participation. Funded certification and training. Direct involvement in client-facing commercial work, which most internal security roles never touch.
Comment postuler
Notre processus
- 1. Notre équipe de recrutement examine chaque candidature reçue par rapport aux exigences du poste.
- 2. Les candidats retenus sont invités à une entrevue, qui peut comporter une évaluation liée au poste.
- 3. Nous communiquons la décision à chaque personne interviewée, que sa candidature progresse ou non.
La plupart des décisions suivent dans les quelques semaines qui suivent la date de clôture. Les postes urgents sont traités en priorité.
