Director, Information Security

Dye & Durham Corporation

Toronto

Hybrid

CAD 150,000 - 230,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Healthcare
Pension
Employee discounts
Wellness programs
Volunteer days

Job summary

Dye & Durham Corporation in Toronto, Canada, is seeking a Director of Information Security to lead and evolve the global security function, protecting systems, data, and services across the business. You will define security strategy, build mature capabilities, and partner with technology, product, legal, and risk teams to embed security by design and ensure regulatory compliance.

This role requires 10+ years of leadership in information security and a proven track record of building security

Qualifications

  • 10+ years in information security or technology risk leadership.
  • Experience scaling security in growing organizations.
  • Strong governance, risk, and compliance capabilities.
  • Proven ability to communicate risks to executives.
  • Certifications like CISSP/CISM are highly desirable.

Responsibilities

  • Lead the global information security function and set strategic direction.
  • Develop and implement the information security strategy and roadmap.
  • Oversee security for corporate platforms and customer-facing products.
  • Lead vulnerability management, penetration testing, and incident response.
  • Embed security-by-design across products and engineering.
  • Develop executive security reporting and dashboards.
  • Build and mentor the security team.

Skills

Information security leadership
Vulnerability management
Incident response
Security architecture
Regulatory compliance
Cloud security
ISO 27001
NIST
CIS Controls
Communication to executives

Education

CISSP
CISM
Bachelor degree in CS/InfoSec

Tools

Cloud platforms
Security monitoring tools

Job description

The Director, Information Security (InfoSec) is responsible for leading and evolving the organisation's global information security function, ensuring the protection of corporate systems, employee productivity platforms, customer-facing products, data, and technology assets. This role will define and execute the security strategy, strengthen cyber resilience, manage security risk, and implement scalable security controls that support business growth and regulatory compliance.

The successful candidate will build and mature security capabilities from the ground up, improving legacy environments, embedding security best practices across the organisation, and ensuring robust monitoring, governance, and risk management frameworks are in place. Through strong leadership and technical expertise, this role will have a significant impact on safeguarding the organisation, supporting customer trust, and enabling secure business operations globally.

Key Responsibilities
  • Lead the global information security function and provide strategic direction across all security domains.
  • Develop and implement the organisation's information security strategy, operating model, and roadmap.
  • Oversee security for corporate platforms, including email, collaboration, and productivity tools.
  • Ensure the security of customer-facing products, applications, and technology services.
  • Build and mature security capabilities and processes, establishing scalable security programmes from the ground up.
  • Identify, assess, and mitigate cyber security risks through effective governance and risk management practices.
  • Lead vulnerability management, penetration testing, threat detection, and ongoing security monitoring activities.
  • Implement compensating controls to address audit findings, compliance requirements, and identified risks.
  • Improve and modernise legacy systems while maintaining appropriate security controls and business continuity.
  • Partner with technology, infrastructure, engineering, product, legal, privacy, and risk teams to embed security-by-design principles.
  • Lead incident response planning, preparedness, and crisis management activities.
  • Develop executive reporting, security metrics, and dashboards to communicate security posture and programme maturity.
  • Build, mentor, and lead a high-performing Information Security team.
Skills, Knowledge and Expertise
  • 10+ years of experience in Information Security, Cyber Security, Technology Risk, or related technology leadership roles.
  • Experience building, transforming, or scaling security functions within growing organisations.
  • Strong technical foundation in infrastructure, IT operations, systems administration, networking, or network security.
  • Demonstrated experience leading security operations, vulnerability management, penetration testing, and incident response programmes.
  • Strong understanding of security frameworks and industry standards such as ISO 27001, NIST, CIS Controls, SOC 2, and PCI DSS.
  • Experience implementing governance, risk, and compliance frameworks, including audit remediation and compensating controls.
  • Knowledge of cloud security, identity and access management, application security, and secure software development practices.
  • Proven ability to communicate technical risks and security priorities to executive and non-technical stakeholders.
  • Strong leadership, stakeholder management, and team development capabilities.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, or equivalent are highly desirable.
Benefits

At Dye & Durham we strive to be visionaries! As a leader in our field, we ensure our employees are ready for the next challenge in their journey with us by offering internal and external training opportunities. We offer competitive salaries and a whole host of benefits including healthcare, pension, company discounts, wellness programs, and paid days off to move house or volunteer for your favourite charity.

#DDhp

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, IT Operations
Director, IT Operations

Dye & Durham Corporation • Toronto

Hybrid
CAD 145,000 - 175,000
Healthcare
Pension
Company discounts
+2
Senior Information Security Architect
Senior Information Security Architect

Placements24 • Kimberley

Hybrid
CAD 140,000 - 180,000
Performance-based bonuses
Home office stipend
Remote-friendly benefits
+1
Manager, Cyber Security
Manager, Cyber Security

Clear Destination Inc. • Toronto

On-site
CAD 150,000 - 170,000
Senior Software Security Engineer
Senior Software Security Engineer

TimePlay • Toronto

On-site
CAD 120,000 - 180,000
IT Security Administrator
IT Security Administrator

ROBINSON • Winnipeg

On-site
CAD 70,000 - 100,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Information Security Architect
Information Security Architect

Placements24 • Kimberley

Hybrid
CAD 120,000 - 180,000
Equity participation or stock options
Health benefits and wellness programs
Training and certifications budget
+1
IT Manager
IT Manager

Edwards & Pearce • Grimsby

Hybrid
CAD 120,000 - 180,000
Hybrid work model
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • Canada

Remote
CAD 130,000 - 170,000
Remote-first environment
Biannual in-person team sprints
USD 2,000 learning budget
+4
Information Security Specialist
Information Security Specialist

Dexian • Toronto

On-site
CAD 90,000 - 110,000