BDO Canada LLP

Director, Information Security

BDO Canada LLP$120K — $150K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (Master's preferred).
  • 15+ years in information security roles, with 5+ in leadership.
  • Experience building enterprise security programs for organizations of 3,000-10,000 employees.
  • Knowledge of cloud security (Azure, AWS, M365) and hybrid IT environments.
  • Strong communication and presentation skills, capable of influencing at all organizational levels.

Responsibilities

  • Develop and execute a comprehensive enterprise information security strategy.
  • Establish a security governance framework aligned with standards like ISO 27001 and NIST.
  • Lead the organization's security roadmap focusing on people, process, and technology.
  • Present security posture updates and risk assessments to executive management and the board.
  • Oversee daily security operations including threat detection and incident response.
  • Build and mentor a high-performing information security team.
  • Manage third-party risk and ensure vendor security compliance.

Benefits

  • Award-winning, people-first work culture.
  • Opportunities for personal and professional growth.
  • Flexible benefits from day one including a competitive personal time off policy.
  • Support for community involvement and local charity initiatives.
  • Commitment to diversity, equity, and inclusion in the workplace.
Full Job Description
Your Opportunity

BDO Canada's National office is looking for a Director, Information Security, to join our National Information Technology team, responsible for leading the organization's global information security strategy, governance, and operations. This newly created role will develop and implement enterprise-wide security programs that protect company assets, data, and systems from internal and external threats, ensuring the confidentiality, integrity, and availability of our digital assets while enabling secure business growth across Canada and globally.

The Director will be the architect of BDO Canada's information security vision, strategy, and compliance and shape the continued growth and maturity of the ISMS program. BDO Canada's Information Security needs span regulatory, information security, privacy, and more. The Director will partner closely with executive leadership, IT, risk management, legal, and compliance teams to maintain a strong security posture protecting our people, clients, and data.

Key responsibilities include:

Strategic Leadership
  • Develop and execute a comprehensive enterprise information security strategy aligned with business goals and risk tolerance.
  • Establish a security governance framework, policies, and standards consistent with ISO 27001, SOC II, NIST, and other relevant frameworks.
  • Lead the creation and execution of the organization's security roadmap - encompassing people, process, and technology improvements.
  • Present regular security posture updates, metrics, and risk assessments to executive management and the board of directors.


Risk Management & Compliance
  • Identify, assess, and manage information security risks across corporate and operational environments.
  • Ensure compliance with applicable regulations and standards such as PIPEDA, GDPR, SOC 2, PCI DSS, and provincial/federal privacy laws.
  • Direct the execution of periodic security risk assessments, internal audits, and third-party reviews.
  • Partner with Legal and Privacy teams to oversee incident response, data breach notification, and regulatory reporting requirements.


Security Operations
  • Oversee day-to-day security operations, including threat detection, monitoring, vulnerability management, and incident response.
  • Lead the deployment and management of security technologies (SIEM, EDR/XDR, IAM, DLP, CASB, MFA, encryption, etc.).
  • Manage and continuously improve the Security Operations Center (SOC) and incident management processes.
  • Coordinate with IT infrastructure and cloud teams to ensure secure architecture design, patching, and access control.


Leadership & Collaboration
  • Build, mentor, and lead a high-performing information security team, fostering a culture of accountability and continuous improvement.
  • Partner with IT and business units to embed security-by-design principles into projects, procurement, and system development.
  • Collaborate with HR and Corporate Communications to drive security awareness and training programs for all employees.
  • Act as the organization's security spokesperson during audits, client assessments, and vendor negotiations.


Vendor and Third-Party Security
  • Oversee third-party risk management programs and ensure vendors meet the company's security standards.
  • Evaluate and approve security controls for external partnerships, SaaS platforms, and cloud providers.


How do we define success for your role?
  • You demonstrate BDO's core values through all aspects of your work: Integrity, Respect and Collaboration
  • You understand your client's industry, challenges, and opportunities; clients describe you as positive, professional, and delivering high quality work
  • You identify, recommend, and are focused on effective service delivery to your clients
  • You share in an inclusive and engaging work environment that develops, retains and attracts talent
  • You actively participate in the adoption of digital tools and strategies to drive an innovative workplace
  • You grow your expertise through learning and professional development


Your experience and education
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (Master's preferred).
  • 15+ years of progressive experience in information security roles, with 5+ years in a leadership capacity.
  • Demonstrated success building and leading enterprise security programs in an organization of similar scale (3,000-10,000 employees).
  • Strong knowledge of cloud security (Azure, AWS, M365), identity management, and modern hybrid IT environments.
  • Proven experience developing and managing security budgets and vendor contracts.
  • Exceptional communication and presentation skills, with the ability to influence at all levels of the organization.
  • Deep understanding of risk management, data protection, and business continuity principles.
  • Strategic thinker with the ability to balance security rigor and business agility.


Certifications (Preferred)
  • CISSP, CISM, CISA, CCISO, or equivalent executive-level security certification.
  • ISO 27001 Lead Implementer / Auditor, or NIST-based certification is an asset.


Total rewards that matter: We pay for performance with competitive total cash compensation that recognizes and rewards your contribution. We provide flexible benefits from day one, and a market leading personal time off policy. We are committed to supporting your overall wellness beyond working hours and provide reimbursement for wellness initiatives that fit your lifestyle.

Flexibility: All BDO personnel are expected to spend some of their time working in the office, at the client site, and virtually unless accommodations or alternative work arrangements are in place.

Our model is a blended approach designed to support the flexible needs of our people, the firm and our clients. It's about creating work experiences that meet everyone's needs and providing flexibility to adjust when, where and how we work to meet the expectations of our role.

Ready to make your mark at BDO? Click "Apply now" to send your up-to-date resume to one of our Talent Acquisition Specialists.

To explore other opportunities at BDO, check out our careers page.

About BDO Canada LLP

BDO Canada LLP is a leading accounting and advisory firm that provides a wide range of services to clients across Canada. The firm offers audit and assurance, tax, advisory, and consulting services to clients in various industries, including manufacturing, retail, real estate, and technology. BDO Canada LLP is part of the global BDO network, which operates in over 160 countries and employs over 80,000 people. The firm is committed to providing exceptional client service and helping clients achieve their business objectives.
Learn more about BDO Canada LLP
Size
4,000 employees
Industry

Similar Jobs

More Jobs at BDO Canada LLP

More Information Technology Jobs

Find similar Director, Information Security jobs: