Director, Information Security
Job Summary
MISSION
Accountable for establishing and executing the enterprise information security strategy to guarantee the confidentiality integrity and availability of Indigos information assets. This role proactively manages enterprise technology risk ensures strict compliance with regulatory and industry frameworks and safeguards data through the leadership of Governance Risk & Compliance (GRC) Security Architecture and Security Operations.
KEY PERFORMANCE METRICS
- Zero critical preventable security breaches.
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) within established operational SLAs.
- 100% compliance with critical regulatory and industry frameworks (e.g. PCI-DSS PIPEDA).
- High completion rates for enterprise-wide security awareness training.
KEY ACCOUNTABILITIES
Strategic
- Develop and implement a comprehensive enterprise information security strategy that aligns with Indigos business objectives and risk tolerance.
- Partner cross-functionally at the senior level to embed security-by-design principles into all foundational technology and retail store operations.
- Set and manage operational and capital budgets to ensure the cost-effective execution of security infrastructure and compliance initiatives.
Functional
- Enterprise Risk Management: Establish and maintain a continuous IT risk assessment framework to identify quantify and mitigate cybersecurity risks across retail e-commerce and corporate environments.
- Regulatory Compliance: Guarantee strict adherence to critical data protection regulations and industry frameworks (e.g. PCI-DSS PIPEDA) through systematic control validations and comprehensive security audits.
- Policy Governance: Formulate publish and enforce data-driven information security policies standards and operational guidelines across the organization.
- Security Architecture Integration: Embed secure-by-design principles NIST framework methodologies and threat modeling into the lifecycle of all cloud network and retail store systems.
- Identity & Access Management (IAM): Oversee the enforcement of Zero Trust architectures privileged access management and robust authentication mechanisms to protect all enterprise assets.
- Threat Monitoring: Direct 24/7 Security Operations Center (SOC) activities utilizing threat intelligence and data analytics to proactively detect and analyze anomalous network behavior.
- Vulnerability Management: Execute systematic vulnerability scanning penetration testing and data-backed remediation prioritization to continuously reduce the organizational attack surface.
- Incident Response: Lead the enterprise security incident response process directing rapid containment strategies and conducting empirical root-cause analysis to prevent recurrence.
- Security Awareness: Implement measurable enterprise-wide security awareness training and phishing simulations to cultivate a resilient security-first workforce.
- Third-Party Risk Management: Assess and continuously monitor the cybersecurity posture of IT vendors supply chain partners and integrated platforms to ensure strict alignment with Indigos risk tolerance.
People
- Accountable for the overall engagement productivity turnover and bench strength of the team
- Supports the creation and maintenance of a talent succession plan
- Collaborate with others to drive flexible and iterative solutions quickly and easily
- Share technical knowledge with others and actively seek to learn from those more knowledgeable than yourself
- Help others see the impacts of their efforts and proactively engage other functions to get input
- Encourage others to freely share their point of view and be open to feedback
- Understand and follow Indigos core HR process - staffing performance management rewards and development
- Ensures all team members are provided with clear performance objectives that are aligned with Indigo Functional and Departmental goals
- Has the ability to see the total organization with an integrated perspective
- Develops positive and productive peer relationships
Cultural
- Model Indigos beliefs and convey a positive image in everything you do
- Understands/demonstrates in a manner that promotes and is aligned with Indigos Mission Vision Beliefs
- As a leader hold others accountable in maintaining the integrity of Indigos culture
- Celebrate diversity of thought and have an open mindset
- Take an active role in fostering a culture of continual learning taking risks without the fear of making mistakes
- Embrace champion and influence change through your team and/or the organization
SCOPE
Reports to: VP Enterprise IT
Manager once Removed (MOR): Chief Technology & AI Officer
KEY RELATIONSHIPS
Internal:
- IT
- Digital
- Finance
- Supply Chain
- Commercial Group
- Creative
- Consumer Experience
- Human Resources
- Retail leadership
External:
- Approved Vendors
- External auditors
- Regulatory bodies
Qualifications :
Work Experience / Education / Certifications
- Bachelors or masters degree in computer science Information Systems or other related field with at least 15 years of Information Technology experience.
- Minimum of 10 years experience working in a leadership position.
- A professional certification (or suitable compensating experience) in the audit (CISA etc) or security field (CISSP or CISM for instance) considered an asset.
- Strong experience working with frameworks and regulations (PCI ISO PIPEDA GDPR etc).
- Strong understanding of network design tiered and secure architectures.
Competencies / Skills / Attributes
- Strategic thinker with analytical and problem-solving experience.
- A strong ability to influence and discuss complex technology problems in business language.
- Must be an excellent and polished communicator who may be called upon to create and present materials to the Executive Committee and the Board of Directors.
- Fast-learner and multi-tasker with the ability to adjust their outlook and leadership style to respond to quickly changing business priorities.
Additional Information :
This posting is for a current opportunity within Indigo.
Indigo uses artificial intelligence (AI) tools to assist with certain aspects of the hiring process such as screening and assessments. These tools support our team but do not replace human judgment. We are committed to using AI responsibly fairly and in compliance with applicable employment and anti-discrimination laws. We regularly review these tools to help prevent bias or discrimination.
At Indigo Diversity Equity Inclusion and Accessibility are core to our values. We integrate these principles into our training policies and hiring practices and continuously evolve to reflect the needs of the communities we serve. We welcome applicants from all backgrounds and lived experiences including but not limited to individuals who identify as BIPOC (Black Indigenous and People of Colour) members of the LGBTQIA community and persons with disabilities. If you require an accommodation during the recruitment process please contact Human Resources at
Remote Work :
No
Employment Type :
Full-time
About Company
Dedicated to telling stories and creating experiences, Indigo is always looking for bright, energetic and customer-focused people who can help bring our exciting mission to life in one of our more than 170 Indigo, Indigospirit, Chapters and Coles stores across Canada. We offer a varie ... View more