Director of IT Security leading the cybersecurity strategy for a remote workforce at Directive Consulting. Responsible for risk management, incident response, and compliance initiatives.
Responsibilities
Develop and execute the company's information security strategy and scalable security roadmap
Establish and maintain enterprise security policies, standards and governance frameworks
Present cybersecurity risks, recommendations and security metrics to executive leadership
Partner with department leaders to ensure security is integrated into business operations and decision-making
Conduct ongoing enterprise-wide cybersecurity risk assessments across infrastructure, endpoints, applications and business processes
Build and maintain the organization's cybersecurity risk register and remediation roadmap
Lead vulnerability management efforts and prioritize remediation based on business risk
Perform third-party vendor security assessments and ongoing vendor risk management
Own the organization's incident response program, including playbooks, tabletop exercises and post-incident reviews
Oversee endpoint security, identity and access management, privileged access controls, MFA and device security
Lead security compliance initiatives including SOC 2 Type II and future security certifications
Build and/or manage company-wide security awareness and phishing training programs
Educate employees on evolving cybersecurity threats, social engineering, AI usage and data protection best practices
Requirements
7+ years of experience in cybersecurity, information security or risk management
3+ years leading enterprise security programs or security teams
Demonstrated experience performing cybersecurity risk assessments and threat modeling
Strong knowledge of cloud-first and SaaS-based environments including Google Workspace, Salesforce, NetSuite, Okta and modern identity platforms
Experience implementing and maintaining security frameworks such as SOC 2, ISO 27001 or the NIST Cybersecurity Framework
Deep understanding of endpoint security, identity management, vulnerability management, incident response and security operations
Experience working within fully remote organizations supporting distributed workforces
Strong executive communication skills with the ability to translate technical risk into business impact
CISSP, CISM, CRISC, or equivalent cybersecurity certification is strongly preferred
Benefits
Medical, dental, vision plans, disability, and life insurance coverage for you and your family
100% employer-paid plan for you and a 50% employer contribution for your dependents
Access to certified therapists through Spring Health, membership to Headspace
Physical therapy through Omada, fertility support through Carrott, thousands of Aaptiv virtual workouts, complimentary One Medical membership for primary and virtual care
Unlimited PTO (2-week minimum), Paid Company Holidays, Your Birthday Off, End of Year Recharge (Closed December 24 - January 1), Paid Parental Leave
Traditional and Roth 401(k) with a 3% company match
Annual bonus based on tenure, which scales in total amount over time
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.