- Senior
- Office in Brampton
Overview
Director, Information Security
We're seeking an experienced Director, Information Security to lead data privacy, compliance, and cybersecurity initiatives. The Director, Information Security will ensure our adherence to global data protection regulations (e.g., GDPR, CCPA, HIPAA, DFAR, CMMC) while implementing robust security frameworks (ISO 27001, NIST, SOC 2). This role will also be responsible for our Data Privacy Management Platform, ensuring secure and compliant data handling across digital platforms, customer data systems, and marketing technologies.
The ideal candidate has deep expertise in data governance, access controls, privacy impact assessments (PIAs), and third-party risk management. They will lead our efforts in integrating privacy-by-design principles into software development, ensuring that security and compliance are embedded across all business operations.
Responsibilities
Key Responsibilities:
- Oversee and manage our Data Privacy Management Platform, ensuring compliance with privacy laws and security best practices.
- Develop and enforce privacy and security policies for our customer data platforms (CDPs), identity management systems, and digital marketing technologies.
- Ensure compliance with GDPR, CCPA, HIPAA, and other global privacy frameworks, working closely with Legal, IT, and Marketing teams.
- Lead incident response, breach management, and regulatory reporting, ensuring adherence to data breach notification laws.
- Conduct privacy impact assessments (PIAs) and risk assessments for new technologies and data initiatives.
- Secure engineering processes and the software development lifecycle by implementing security measures such as code review, vulnerability testing, security education, and establishing DevSecOps practices.
- Oversee third-party Information Security risk management, ensuring vendor compliance with our security and privacy requirements.
- Lead security awareness and training programs for employees, contractors, and partners.
- Regularly report on security risks, compliance status, and emerging threats.
- Work with Canon Americas affiliates leadership on enterprise-wide security policies and data privacy management solutions.
Qualifications
To Succeed, You Will Need:
- Bachelor's Degree
- A minimum of 12 years of experience in information security, privacy, and compliance leadership roles.
- International Travel to Canon USA, and subsidiaries may be required.
- Expert knowledge of global data protection regulations (e.g., GDPR, CCPA, HIPAA, DFAR, CMMC) and how to operationalize compliance through policies, access controls, and technology.
- Experience managing Data Privacy Management Platforms and implementing privacy frameworks such as ISO 27701 (Privacy Information Management System), NIST Privacy Framework, and SOC 2 Privacy Criteria.
- Strong background in data governance, consent management, and privacy-by-design principles for digital platforms.
- Technical expertise in encryption, identity & access management (IAM), secure software development (DevSecOps), and cloud security.
- Experience leading cybersecurity risk assessments, vulnerability management, and incident response programs.
- Ability to collaborate across IT, Legal, Compliance, and Business teams to align privacy and security initiatives with organizational goals.
- Exceptional communication and leadership skills, with the ability to engage executive stakeholders and drive security awareness.
- Relevant certifications such as CISSP, CISM, CIPP (US/EU), CRISC, or ISO 27001 Lead Implementer are preferred.
- High-level of commitment to a quality work product and organizational ethics, integrity and compliance
- Ability to work effectively in a fast paced, team environment
- Strong interpersonal skills and the ability to effectively communicate, both verbally and in writing
- Demonstrated decision making and problem-solving skills
- High attention to detail with the ability to multi-task and meet deadlines with minimal supervision
Why Join?
HYBRID WORK
- We offer a Hybrid work schedule. You will be in the office Mondays and Wednesdays each week, and can work from home for the remainder of the week (subject to specific business needs requiring office attendance)
- When working from home, a reliable internet connection is required. Remote work is supported with cloud-based applications and collaboration tools
BENEFITS
- Comprehensive health coverage plan that includes medical, dental and vision
- Life insurance, disability and wellness programs
- Vacation, Paid Personal Time and Sick days
- Matching RRSP contribution & Profit-Sharing Program
- Tuition Assistance Program for professional continuing education
- Discounts on Canon products, retailers, memberships and more!
 
			 
			 
			 
			