Director, Information Security & Security Programs
Toronto, ON, CA Burnaby, BC, CA Ottawa, ON, CA Montréal, QC, CA Calgary, AB, CA Edmonton, AB, CA Vancouver, BC, CA
Join our team and what we'll accomplish together
We live in and work in a fully digital world where security risk management and cyber resilience are critical. As one of Canada’s preeminent owners and operators of critical infrastructure, evolving geopolitical threats and new regulatory regimes are the new business reality. Protecting information and ensuring the resiliency of networks and services is paramount. At TELUS, we aspire to the highest standards in staying ahead of the adversary, tackling the toughest security challenges head-on with top talent and leading with our expertise in cybersecurity risk management.
The Information Security & Security Programs team is committed to providing excellence in the programs that secure our internal and customers’ data and systems. Our Secure-by-Design approach identifies cybersecurity risks up front and works with stakeholders to implement controls early in the technology lifecycle, improving our overall cybersecurity posture. We partner across TELUS to communicate regulatory obligations, contractual commitments, share best practices and extend our cybersecurity framework to newly acquired companies, third parties and other stakeholders.
What you’ll do
As the Director, Information Security & Security Programs you will:
- Inspire and empower a team of security and technology professionals, working internationally across many teams (Secure-by-Design, Governance/Risk Management/Compliance, Culture of Security, Vulnerability Assessment and Testing, Third party Security Risk and Acquisition Security) with your vision, strategy and program execution management
- Partner closely with multiple internal and external stakeholders to understand and assess their business requirements, security risks and threats, and design and deliver secure-by-design solutions
- Aggregate and communicate overall security risk, in the business context, to executive leaders
- Continuously strengthen the TELUS brand as trustworthy, reliable and innovative through strategic vision and leadership encompassing legal and regulatory obligations, contractual security obligations, voluntary security frameworks, governance, policies and programs
- Partner closely with business teams to ensure compliance with internationally recognized cybersecurity frameworks, standards (NIST, PCI, SOC2, etc) and the contractual physical, personnel and cybersecurity requirements of federal and provincial governments, and other regulated sectors.
- Assess and test TELUS and third-party networks and systems to identify and remediate security vulnerabilities, while evolving automation and re-use capabilities.
- Foster high team member engagement and collaboration by practicing our culture of embracing diverse perspectives and experiences, and supporting development
- Attract talent from a domestic and global pool of cybersecurity professionals
What you bring
- Strong program management and financial management capabilities
- Expert knowledge of both security technologies and the security of technologies including generative artificial intelligence, post-quantum cryptography, blockchain, 5G and private wireless networks, cloud and network security, large scale identity and authentication systems, SaaS platforms, team member device security, Governance, Risk and Compliance (GRC) / security awareness platforms, and security data analytics / security incident and event management platforms
- Expert knowledge of the Canadian cybersecurity regulatory landscape, security in contracting and third party risk management frameworks, programs and tools
- Experience in the cybersecurity and cyber resilience of critical infrastructures
- Ability to communicate complex/technical topics, data insights, and stories that are clear and easily understood by a diverse range of audiences including executives
- 10 or more years of experience leading cross-functional security teams
- Degree in Engineering, Computer Science or related technology discipline
- Must possess or be eligible to obtain the Government of Canada Secret Level security clearance or higher
Great-to-haves
- Extensive leadership experience in a CSO/CISO or public sector cybersecurity organization
- Broad knowledge of security laws, regulations, frameworks, standards, controls and technologies across multiple domains
- Both government and private sector experience
- Master’s degree in Engineering, Computer Science, or Business Administration
- GICSP and CISSP or equivalent certification
- Fluency in English & French
Advanced knowledge of English is required because you will most of the time interact in English with external parties (clients, suppliers, candidates, external partners, etc.); interact in English with internal parties (colleagues, internal partners, stakeholders, etc.); and work with IT tools whose interface is only accessible in English as part of this position's main responsibilities given its national scope.