Director, Security Operations, Information & Corporate Security
CPP Investments View all jobs
- Toronto, ON
- Permanent
- Full-time
- Lead the Security Operations Center, monitor emerging threats, oversee DFIR capabilities, enable outcomes-based metrics, and work closely with internal and external stakeholders for incident responses to determine appropriate courses of actions
- Direct improvements to SIEM and SOC efforts for continuous maturity to response times and SLA compliance
- Work closely with the Managing Director to ensure that information security and risk management are embedded within the culture
- Implement the next generation of cyber controls and threat analytics by leveraging automation, machine learning, and rich data sets.
- Identify and drive the end-to-end remediation of discovered or potential security vulnerabilities and mature operational security processes and procedures.
- With the Director, IT Risk Management, execute periodic security testing and reviews, promptly remediate any findings, and ensure policies, controls, and procedures are effective, documented, and understood by relevant stakeholders/roles through training and education.
- Effectively communicate investigative findings and strategies to technical staff, executive leadership, legal counsel, and internal and external clients
- Bachelor’s degree, with a technology or business emphasis, or equivalent education and experience.
- Possess one or more of the following industry certifications:
- CISSP / CISA / CISM
- CCSP – Certified Cloud Security Professional
- SABSA - Security Architecture
- Other industry recognized Information Security certifications
- Demonstrated knowledge of current cloud platforms, services and security best practices for their protection
- Demonstrated knowledge and understanding of information security industry standards (e.g., ISO17799, ISO27001, NIST, COBIT, ITIL, etc.), and legislative/regulatory requirements (e.g., SAS-70, SOX, B198, PIPEDA, etc.)
- Minimum of 7-10 years experience in information security including:
- Security Management, Policy & Procedure development, Governance Frameworks, Security Programs
- Experience working with MSS partners
- Developing and implementing cloud security architectures
- Risk Assessment, Risk Management
- Security Architecture, IS Infrastructure Processes
- Operational security (network architecture, application, systems)
- Strong vendor management
- Strong sense of teamwork
- Ability to create solutions to fit a diverse and complex environment
- Adaptable to new technologies and challenges not previously encountered
- Able to build strong relationships and communicate effectively with a diverse set of stakeholders, including business leaders, operational staff and technical engineers
- Proven project management experience
- Excellent written and oral communication skills, with the ability to work with both technical and business users
- Self-motivated with acute attention to detail
- Innovative and proactive
- Exemplify CPP Investments’ Guiding Principles of Integrity, High Performance and Partnership