Jobs
>
Montréal

    Director of Information Security - Montréal, QC, Canada - AlayaCare

    Default job background
    Description

    AlayaCare

    AlayaCare is a revolutionary cloud-based home care software platform for agencies looking for innovation and efficiencies across the entire agency.

    View company page

    AlayaCare is revolutionizing the way home health care is delivered. Our leading cloud -based software allows our clients around the world to manage their employees, scheduling, billing, and enable better delivery of care. We are a fast-growing SaaS company with a team of 550+ team members across Canada, US, Australia, and Brazil. We aim to be the world leader in home healthcare software solutions. We pride ourselves on our open and transparent culture, our bias for action, and being committed to a workplace where we can be ourselves.

    About the Role:

    AlayaCare is seeking a dynamic and practical security leader to fill the role of Director of Information Security. The ideal candidate will possess deep expertise in Information Security, along with significant hands-on experience in a similar position within a B2B SaaS environment. You should be an outstanding communicator and a persuasive influencer, ready to enhance and shape all aspects of AlayaCare's Information Security posture.

    You will work closely with members of AlayaCare's management team, focusing on the key security elements of the company's overall governance, risk and compliance programs. Your leadership will extend to directing a dedicated security team and mobilizing dozens of internal security champions, particularly within our platform and Site Reliability Engineering (SRE) teams. Consequently, this position provides a unique chance to affect change across AlayaCare, influencing hundreds of employees and clients, and making a difference in the lives of millions.

    A day in the life:

    • Lead the development and execution of AlayaCare's information security vision across the company and its various product lines, including the seamless integration of acquisitions. Direct the Security Steering Committee, establishing a strategic plan and actionable items in alignment with the company's business objectives. Collaborate with the privacy officer, legal, and risk management teams to ensure comprehensive alignment.
    • Work in partnership with the Information Technology department to bolster corporate security measures, including identity and access management, network security, email security, and endpoint protection.
    • Oversee the security awareness program, utilizing the Knowbe4 platform to enhance organizational security and privacy consciousness.
    • Take charge of existing compliance with SOC1, SOC2, HIPAA, and future ones such as Hitrust. This includes hands-on involvement in the annual review of certain policies and vendor risk management, as well as owning specific policies, controls, automated tests, and evidence documentation. Utilize Vanta to streamline and centralize compliance-related information.
    • Engage in responding to RFPs, RFIs, and customer questionnaires regarding information security at AlayaCare. Develop a system that enables sales and account managers to autonomously access and provide up-to-date information to clients.
    • Foster the growth of a pragmatic security team by setting clear goals and expectations, outlining objectives, results, and key performance metrics for team members.
    • Collaborate with the Developer Experience team to establish and maintain a Secure Software Development Lifecycle (SSDLC), including the creation of Role-Based Access Control (RBAC) policies in a CI/CD environment and developing tools to support the deployment of secure software.
    • Design and oversee penetration testing programs and manage the remediation of identified critical issues.
    • Manage vulnerabilities within the AlayaCare Cloud Platform, ensuring they are visible in a centralized location and resolved in accordance with established SLAs.
    • Lead initiatives to increase the security of our AWS infrastructure in collaboration with DevOps teams, including the adoption of AWS security best practices, maintaining high scores in Security Hub through centralized AWS security policies, and leveraging a Secure Environment Accelerator based architecture.
    • Enhance the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) in partnership with the Customer Success department and Site Reliability Engineering teams, including conducting regular tabletop exercises with internal teams and key suppliers.
    • Influence the inclusion of security requirements in the security architecture runway, ensuring their delivery and implementation in collaboration with the Chief Architect, product management, and engineering leadership.
    • Spearhead the development and operation of the Security Operation Center for ongoing security monitoring and incident response.
    • Define and manage the information security budget, ensuring resources are allocated effectively to support security initiatives and goals.

    What you bring to the team:

    • 10+ years of experience in information security, including at least 3 years at a managerial level.
    • Excellent communication skills for both customer and executive levels. Capable of explaining complex concepts in simple terms while considering the business strategy. Additionally, you should be able to describe technical concepts, for example how AWS VPC Flow Logs can be utilized for the detection or analysis of security incidents.
    • You should understand at a high level, the technical aspects of web software and, preferably, have had a technical role at some point in your career. It's important to have deep understanding of the Secure Software Development Life Cycle (S-SDLC), vulnerabilities management, and infrastructure security in mobile, web, and cloud environments.
    • You have experience in driving security compliance certifications such as SOC or ISO and understand common frameworks like NIST.
    • A talent magnet – skilled in recruiting, developing, and leading people. You inspire others to do their best work.
    • Excellent interpersonal, collaboration, and communication skills, including writing abilities.
    • Strong project management skills with a high sense of urgency.
    • A firm believer in automating everything and adopting an "everything as code" philosophy, thereby shifting security to the left with integrated automated controls.
    • Experience with Vanta is a plus, to automate and centralize controls and tests for compliance.
    • Experience in fast-growing SaaS start-ups.
    • You possess a demonstrable growth mindset.
    • You are motivated to make a difference in the world by helping the most vulnerable individuals.

    Location, and in-office requirements:

    AlayaCare supports a flexible hybrid working model, expecting that our employees have a regular in-office presence at their closest office location while offering flexibility for some remote work. Our team encourages in-person collaboration and with this, the preferred candidate location for this position would be within the Greater Montreal Area.

    What Makes AlayaCare a Great Place to Work:

    • Our products have a positive impact on the lives of countless care workers and care recipients Equity in a well-funded, high-growth company
    • Work where you feel most engaged and productive with our Superflex working models, whether that be at home or in one of our beautiful offices
    • Competitive compensation including equity in a growing, well-funded company
    • Comprehensive group benefits program, including telemedicine, effective on your first day
    • Employee expense program for health, wellness, lifestyle, productivity expenses and more
    • Parental leave top-up plan
    • Flexible vacation policy
    • Wellness Fridays for extra time to unwind
    • Paid Volunteer Time off Program
    • Career growth and development opportunities
    • An entrepreneurial culture of transparency, collaboration, and innovation
    • We are recognized as Deloitte's Technology Fast 50TM program award for our rapid revenue growth, entrepreneurial spirit, and bold innovation

    If this sounds like the perfect job for you, apply today. As well as joining a great culture and a market-leading company, you will be part of a team making a positive difference in the post-acute care market. If this isn't the job for you, you may know someone who is a perfect fit. Please feel free to share this opportunity.

    If you want to explore AlayaCare further, please visit our website .

    Better outcomes, better belonging

    Our team members are unique—like our products and the customer groups that we service. AlayaCare employees bring different strengths, perspectives, and experiences to their roles and to our products that enable better care. We are committed to offering a people-centric culture where all employees belong and feel heard.

    Having a pulse on our employee feedback is important to us as we aim to continuously evolve Diversity, Equity, Inclusion, Belonging, and Accessibility within AlayaCare's policies, total rewards offerings, discussions, learning & development programs, and community partnerships. All qualified applicants will receive equal consideration.

    If you require accommodation as part of the recruitment and selection process, please reach out to . Please note, we do not accept unsolicited headhunter or agency resumes.

    Explore more InfoSec / Cybersecurity career opportunities

    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

    #J-18808-Ljbffr


  • Agropur Saint-Hubert, Canada

    Job Type: · Regular · Working at Agropur means choosing a committed employer who invests daily to give its employees the means to develop professionally. It is also means being part of a large family where simplicity and honesty are lived on a daily basis and where the management ...


  • WSP Montréal, Canada

    **Position Summary** · WSP's Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technolog ...


  • PSP Investments Montréal, Canada

    ABOUT US · We're one of Canada's largest pension investment managers, with CAD$243.7 billion of net assets as at March 31, 2023. · We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Reserve Force. He ...


  • Addenda Capital Montréal, Canada

    City: · - Montréal, QC · - Status: · - Permanent, Full-time · **Who we Are** · Addenda Capital is a privately-owned investment management firm that favours a sustainable approach to wealth creation. The company offers a stimulating, positive and open-minded environment where inte ...


  • Alithya Montréal, Canada

    **Information Security Analyst** **:montreal · **Montreal, Quebec, Canada****: · Do you want to experience the essence of a large organization in a company with a personal touch? Come and work with us We are looking for creative, innovative, and collaborative people like you to j ...


  • Desjardins Montréal, Canada

    At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we ha ...


  • beBee Professionals Montreal, Canada Information Security Freelance

    BeBee Professionals is looking for an Information Security Analyst to join our team in Montreal. · The Information Security Analyst will be responsible for developing and implementing security measures to protect the company's computer networks and systems. The successful candida ...


  • National Bank of Canada Montréal, Canada

    **Primary Locations**:Montreal, Quebec**: · **Attendance**:Hybrid**: · **Employee Status**:Regular**: · **Schedule**:Full-time**: · National Bank is currently undergoing the most significant technological transformation in its history and has many career opportunities to offer. A ...


  • WSP Montréal, Canada

    **Position Summary** · WSP's Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technolog ...


  • SSENSE Montréal, Canada

    Company Description · Founded in 2003, SSENSE is pacing the vanguard of directional retail with its mix of luxury, streetwear, and avant-garde labels. · Currently serving 150 countries, generating an average of 88 million monthly page views, and achieving high double digit annual ...


  • Samsung Ads Montréal, Canada

    **Information Security Operations Manager** · **Life at Samsung Ads** · We are proud to build a world class organization that thrives on**:Collaborating closely,** **delivering quality and value in all that we do, breaking new ground and adapting quickly to a rapidly evolving ind ...


  • WSP Montréal, Canada

    **WSP **is one of the world's leading professional services firms. Our purpose is to future proof our cities and environments. · We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban pla ...


  • National Bank of Canada Montréal, Canada

    **Primary Locations**:Montreal, Quebec**: · **Attendance**:Hybrid**: · **Employee Status**:Regular**: · **Schedule**:Full-time**: · A career in cybersecurity at National Bank means contributing to its transformation and having a direct impact on clients. As an Information Securit ...


  • Fivesky Montréal, Canada

    Do you work with Global cybersecurity teams to assess, guide and rewrite policies and standards? Are you collaborating at all levels within your organization to enhance policies, ensure compliance, and support policy adoption efforts? If this sounds like you, you might be Fivesky ...


  • Universite Concordia Montréal, Canada

    **Open Positions: PhD and MASc, Information Systems Security**: · Last updated: April 17, 2024, 4:23 p.m. · Multiple PhD and MASc student positions are available at Concordia University's Security Research Centre. The hired students will work on emerging topics of cybersecurity o ...


  • Concordia University Montréal, Canada

    Last updated: April 17, 2024, 4:23 p.m. · Multiple PhD and MASc student positions are available at Concordia University's Security Research Centre. The hired students will work on emerging topics of cybersecurity operations using artificial intelligence with the researchers from ...


  • Business Development Bank of Canada Montréal, Canada

    We are banking at another level. · Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious ...


  • Points Montreal, Canada Full time /

    *** English Version Below *** Les voyages vont bien au-delà de leur destination ; ils sont tissés de chaque souvenir que l'on crée en chemin. Notre engagement consiste à redéfinir l'avenir du voyage en collaborant avec plus de 200 compagnies aériennes, établissements hôteliers, s ...


  • Cascades Saint-Bruno-de-Montarville, Canada

    **The challenge** · - Our beautiful family is growing: the information security team is currently looking for a information security analyst - · - At Cascades, the development of our talents is very important, and you will have the necessary support to grow and being involved in ...


  • Hitachi Systems Security Blainville, Canada

    Information security analysts play a key role in protecting our customers from cyberattacks as they are the first to see the security alerts and the first to respond to cybersecurity incidents. Their main role is to filter out the false positive alerts generated by the security c ...