Job DescriptionThe OpportunityWSP's Information Security Office is responsible for deploying and governing the information security framework across both the IT organization and the wider business community. This includes the governance mechanisms, policies, processes, technologies, and training required to protect WSP information and that of our clients.
As the
Business Information Security Officer, Digital & Industrial Solutions; you will play a critical role in securing the digital and industrial solutions that WSP designs, develops, and brings to market. Working at the intersection of technology, security, innovation, and commercial strategy, you will help embed security, privacy, and trust into products, platforms, and services from concept through launch and ongoing operation.
Partnering closely with Digital Solutions, engineering, architecture, product leadership, and customer-facing teams, you will enable innovation while ensuring solutions meet customer, industry, and regulatory security expectations.
Your Impact- Serve as the primary security leader for WSP's externally facing digital and industrial products, platforms, and services.
- Embed security-by-design and privacy-by-design principles throughout the entire product and solution lifecycle, from concept and development through deployment and operation.
- Govern secure software development and DevSecOps practices, including threat modeling, secure coding standards, code scanning, CI/CD security controls, vulnerability management, and penetration testing.
- Provide security architecture guidance for cloud-native, AI/ML, data-driven, and connected IoT/OT solutions.
- Identify, assess, track, and communicate security risks while driving remediation efforts with delivery and engineering teams.
- Support client engagements, proposals, due diligence activities, and security questionnaires to help position security as a business differentiator.
- Establish and maintain security certifications, attestations, and compliance requirements such as ISO/IEC 27001 and SOC 2.
- Oversee software supply-chain security, third-party risk assessments, and secure adoption of external technologies and services.
- Monitor emerging technologies including AI, generative AI, connected infrastructure, digital twins, and operational technology, providing practical security guidance to support innovation.
- Partner with the CISO and Information Security Office to ensure alignment with the Global Information Security Framework and contribute to ongoing security governance and reporting.
- Champion a strong security culture by building awareness and capabilities across product, engineering, and solution teams.
The Skills That Set You Apart- 8+ years of senior-level experience in information security, including product, application, cloud, or solution security.
- Demonstrated experience securing customer-facing products, SaaS platforms, cloud services, or commercial digital solutions.
- Strong knowledge of secure software development and DevSecOps practices, including threat modeling, SAST, DAST, SCA, CI/CD security, and vulnerability management.
- Experience with cloud security across Azure, AWS, and/or Google Cloud platforms.
- Working knowledge of application security, API security, encryption, authentication, authorization, PKI, and secure integration patterns.
- Professional security certification such as CISSP, CISM, CCSP, CSSLP, or an equivalent credential.
- Experience applying governance and security frameworks such as ISO/IEC 2700x, NIST, SOC 2, COBIT, and ITIL.
- Strong understanding of risk management principles and their application within engineering and delivery environments.
- Knowledge of privacy and cybersecurity regulations applicable to global organizations and commercial technology solutions.
- Ability to influence senior leaders, customers, engineers, and business stakeholders while leading through collaboration rather than authority.
- Exceptional communication, relationship-building, problem-solving, and strategic thinking skills.
- Ability to work effectively across international teams and multiple time zones.
Preferred Qualifications- Experience with Operational Technology (OT), Industrial Control Systems (ICS/SCADA), IoT, or connected infrastructure security.
- Exposure to AI/ML and generative AI security.
- Experience supporting sales pursuits, customer due diligence reviews, and security assessments.
- Experience obtaining or maintaining security certifications such as ISO/IEC 27001 or SOC 2 Type II.
- Product management, commercial, or go-to-market experience.
- Master's degree in Information Technology, Computer Science, Engineering, or a related discipline.
CompensationAB, BC, NT, NU, SK & YT:
$194,700 - $257,900MB & ON:
$177,600 - $244,600NB, NL, NS, PE & QC:
$175,800 - $233,500Disclosure:The final salary awarded for this role may vary from the above range based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs. The wage range provided in this job posting may be subject to change for business purposes.
Ready to Secure What's Next?Join WSP and help shape the future of secure digital and industrial innovation. This is an opportunity to influence the development of cutting-edge solutions, build trust with clients around the world, and strengthen the security foundation of technologies that make a meaningful impact on communities and industries. Bring your expertise, curiosity, and leadership to a team where security enables innovation and where your contributions will help redefine what's possible.
#LI-Hybrid