Head of Information Security - Montréal, Canada - WSP

WSP
WSP
Verified Company
Montréal, Canada

2 weeks ago

Sophia Lee

Posted by:

Sophia Lee

beBee Recruiter


Description

Position Summary

WSP's Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community.

This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.


The role of
Head of Information Security reports to our Chief Information Security Officer and is responsible for leading a team of Business and Regional Information Security Officers across WSPs global business.

It is a primarily internally facing role, though it may involve some interaction with clients and third parties.


This position requires a senior management professional with relevant experience and a strong working knowledge of IT security, risk management, regulatory compliance, information and public cloud service technology, IT operations management principles, and third-party security management.


Responsibilities:

-
Information Security Strategy:Collaborate with the CISO to define the organization's information security strategy, vision, and goals. Translate strategic objectives into actionable plans and initiatives that align with business objectives and industry best practices.
-
Team Leadership:Lead and manage a team of Information Security Officers located across WSPs regions. Provide guidance, mentorship, and support to ensure their professional development and effective execution of their responsibilities.
-
Information Security Governance:Oversee WSPs implementation and maintenance of its ISO27001 certified Data and Information Security Management System. Establish and maintain the Information Security Governance framework; including running the Information Security Committees; coordinating IS risk management, executive reporting and participate in other forums where information security input and approval is required based on documented policies and processes.
-
Risk Management:Oversee the identification, assessment, and mitigation of information security risks. Work closely with cross-functional teams to ensure risk management practices are embedded in business processes and projects. Monitor the effectiveness of risk mitigation measures and drive continuous improvement.
-
Security Awareness and Training:Develop and deliver comprehensive security awareness and training programs to promote a security-conscious culture throughout the organization. Collaborate with stakeholders to address security education needs and ensure employees understand their roles and responsibilities in protecting information assets.
-
Acquisition, Mergers and Integrations:Direct the security matters relating to all aspects of Acquisitions, Mergers, Integrations and Divestments. Including the security evaluation of potential acquisitions through to the integration of the acquired businesses into WSP's security ecosystem.
-
Client Support:Develop and maintain a program of client support, to ensure that all client security requirements are identified, assessed, delivered and reported to relevant business leaders.
-
Vendor and Third-Party Risk Management:Develop and maintain a robust vendor and third-party risk management program. Conduct assessments of vendors and service providers to ensure they meet information security requirements and adhere to contractual obligations.
-
Incident Response and Management:Develop and maintain an incident response plan and coordinate the response to information security incidents. Lead investigations, root cause analyses, and corrective actions to mitigate the impact of incidents and prevent future occurrences.
-
Security Incident Reporting and Metrics:Develop and maintain metrics, reports, and dashboards to track the effectiveness of the information security program. Provide regular updates to senior leadership on the organization's security posture and recommend remedial actions as needed.


Leadership and People Responsibilities:


  • Displays personal and team leadership in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • Assist in the training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.
  • Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands.
  • Capable of rapidly assimilating and internalizing complex business, technology, and risk management concepts and dependencies.
  • Capable of clearly defining, presenting and selling recommended strategies to senior management teams.
  • Critical thinker with strong problemsolving skills, pr

More jobs from WSP