Information Security Manager
Toronto, Ontario, Ca
Responsible for the implementation of a comprehensive information and technology security program including advisory, Contributed to the IS strategy and roadmap. Responsible for the maintenace of Information Security Policies, Standards, Guidelines and Operating procedures that align with the Corporate Strategy and 5 year plan including all necessary regulatory and legislative requirements. Ex. International Financial Reporting Standards (IFRS - CSOX), Payment Card Industry (PCI), Personal Information Protection and Electronic Documents Act, (PIPEDA)Capability Maturity Assessments to ensure the Policies and Standards are aligned with the capabilities of the technology.Liaison and advise with Corporate Security, Risk Governance and Compliance, Internal and External Audit services and Senior Executives and Chief Information OfficerDeveloped and Planed Vulnerability Assessments, Threat/Risk Assessments, Privacy of information classification, ownership and assessments, Project and special request Security Risk Assessments, Vendor Risk Assessments/5970 SAS70 type 2 Audit report reviews and Master Contract Agreement/Statement of work review and Security Incident response processAssess security and regulatory requirements CSOX, PCI, PIPEDA, INTERACEducate employees and contractors related to the enterprise security issues, policies, awareness, compliance, and threats. Information Security is Everyone's Business.Contribute to the disaster recovery plans, and business continuity plans.Manage all Information Security employee day to day activities and development plans.Manage the Information Security Budget and financial planning.Sustaining Manager for the Information Security compliance monitoring, reporting tools and activities. Governance/oversight of IT operational security tools, monitoring and reporting mechanisms.