Duties and ResponsibilitiesNetwork Architecture & Segmentation- Design, implement, and maintain a fully segmented network architecture across all Remco locations and business units - ensuring that each division (RSS, Logistics, Warehouse, K Town) and each functional zone (operations, finance, warehouse floor, guest/IoT and data backup) operates on a separate, isolated network segment.
- Manage Data Center physical security, UPS systems, backup power infrastructure, and facility controls to ensure continuous availability, safety, and reliability of critical IT operations.
- Implement and manage VLAN architecture to enforce logical separation between business units, preventing lateral movement across the network in the event of a breach.
- Design and maintain network segmentation between corporate systems, operational systems (TMW, TruckMate, WMS, EDI and data backup), and external-facing systems; ensure no flat network exists across any Remco site.
- Manage all firewalls, routers, switches, and wireless access points across all locations; ensure firmware is current, rules are reviewed quarterly, and access control lists are enforced.
- Maintain site-to-site VPN connectivity between all Remco locations and WMS SaaS; manage remote access VPN for authorized staff with MFA enforced.
- Conduct quarterly network segmentation audits; document all network topology and update diagrams with every change.
- Evaluate and implement SD-WAN or similar technologies to improve network resilience and performance across multi-site operations.
Cybersecurity - Primary Mandate- Own and continuously improve Remco's cybersecurity posture; develop and maintain a cybersecurity roadmap approved by the Director of IT and updated annually.
- Implement and maintain a layered security framework covering endpoint protection, network security, email security, identity and access management (IAM), data loss prevention (DLP), and vulnerability management.
- Deploy and manage next-generation firewall (NGFW) solutions with intrusion detection and prevention (IDS/IPS) capabilities across all locations.
- Maintain network security posture by ensuring compliance with NIST and COBIT frameworks, implementing security best practices, and continuously monitoring and improving network security controls.
- Implement and enforce multi-factor authentication (MFA) for all user accounts, remote access, and privileged access - no exceptions.
- Manage privileged access management (PAM); maintain a principle of least privilege across all systems (RBAC); conduct quarterly access reviews and remove unnecessary permissions.
- Deploy, configure, and manage Endpoint Detection and Response (EDR) and Managed Detection and Response (MDR) solutions across all Remco endpoints, including servers, workstations, laptops, and mobile devices, to provide continuous threat detection, monitoring, and incident response.
- Manage email security including anti-phishing, anti-spam, and email authentication (SPF, DKIM, DMARC) across all Remco domains.
- Conduct regular vulnerability scans across all systems and networks; prioritize and remediate findings within defined SLAs (critical: 48 hours, high: 7 days, medium: 30 days).
- Manage security patch deployment for all operating systems, applications, and firmware; maintain a documented patching schedule and compliance rate of 60 95%.
- Lead Remco's Cyber Incident Response process in accordance with the IT Incident Response Plan; serve as Incident Lead for all P1 and P2 cybersecurity events; notify the Director of IT immediately upon confirmation of a P1 security incident.
- Conduct annual cybersecurity risk assessment including PEN testing; present findings and remediation plan to the Director of IT.
- Implement and manage security information and event management (SIEM) or log management solution; monitor for anomalies and threats on an ongoing basis.
- Manage cyber insurance requirements; ensure technical controls align with policy conditions; coordinate with the Director of IT on annual renewal submissions.
- Develop and deliver annual cybersecurity awareness training for all Remco staff; conduct phishing simulation exercises at least twice per year.
- Ensure compliance with PIPEDA and applicable provincial privacy legislation; maintain a data inventory and implement appropriate data protection controls.
Multi-Division Infrastructure Management- Manage all server infrastructure (physical and virtual) across Remco's locations; ensure uptime, performance, and capacity meet operational requirements for all divisions against established KPIs.
- Oversee infrastructure supporting critical operational systems: TMW (Transportation Management), TruckMate, WMS (Kf6rber/HighJump), EDI, Omnitracs, Appian, TGI, and accounting systems - ensuring each is properly integrated, maintained, and backed up.
- Manage the Microsoft 365 tenants including Exchange Online, SharePoint, Teams, and Azure AD; enforce conditional access policies, licensing, and security configurations.
- Oversee the VoIP/SIP trunk telephony platform across all locations; ensure call quality, failover, and continuity of communications.
- Maintain a current and accurate asset register for all IT hardware and software across all divisions and locations via a CMDB; manage the asset lifecycle from procurement to decommissioning.
- Plan and manage IT infrastructure projects including hardware refresh cycles, software upgrades, and new location buildouts (e.g. Ottawa Sheffield Rd. facility); develop project plans and report progress to the Director of IT.
- Manage the IT budget; prepare annual IT capital and operating expenditure plans; track actuals vs. budget monthly and report variances to the Director of IT.
- Evaluate and manage all IT vendor and service provider relationships including contract negotiation, SLA monitoring, and performance reviews.
Backup, Disaster Recovery & Business Continuity- Design and maintain a comprehensive backup strategy for all critical systems; ensure backups are automated, encrypted, offsite or cloud-replicated, and tested monthly.
- Maintain and test the IT Disaster Recovery Plan (DRP) at least annually in alignment with the Business Impact Analysis (BIA), ensuring documented and validated Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical systems.
- Implement and support a 3-2-1 backup strategy by maintaining three copies of data, stored on two different types of media, with at least one copy kept offsite or in immutable/cloud storage.
- Ensure TMW, TruckMate, and WMS have documented recovery procedures; test restoration from backup at least once per year and document results.
- Maintain hot or warm standby capability for mission-critical systems where operationally required; present recommendations to the Director of IT on priority systems.
- Lead the IT response to any system outage or data loss event; implement the Incident Response Plan and provide status updates to the Director of IT every 30 minutes during a P1 event.
IT Team Leadership & Service Delivery- Lead, develop, and manage the IT team including Systems Administrators and support staff; set clear performance expectations, conduct regular 1:1s, and deliver annual performance reviews.
- Establish and enforce IT service management standards including a ticketing system, SLA targets for incident and request resolution, and escalation procedures.
- Implement and maintain a change management process; ensure all infrastructure changes are reviewed, approved, tested in a non-production environment, and communicated to affected stakeholders before deployment.
- Provide executive-level IT reporting to the Director of IT on a monthly basis covering infrastructure health, cybersecurity posture, open incidents, project status, and budget.
- Develop and maintain IT policies and procedures including Acceptable Use Policy, Password Policy, Patch Management Policy, Incident Response Plan, and Data Classification Policy.
- Manage IT onboarding and offboarding processes; ensure all user accounts are provisioned and deprovisioned on the employee's first and last day respectively - no exceptions.
Requirements and Qualifications- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field is preferred.
- Minimum 7-10 years of progressive IT infrastructure experience, with at least 3-5 years in a senior or management role.
- Demonstrated experience designing and managing segmented network environments across multiple locations and business units.
- Proven track record of owning cybersecurity in a mid-size organization - not just supporting it but leading it.
- Experience in a transportation, logistics, warehousing, or multi-division operations environment is a strong asset.
- Experience managing Microsoft 365, Azure AD, and hybrid cloud environments.
- Experience with TMS and WMS system infrastructure (TMW, TruckMate, Kf6rber, or equivalent) is a significant asset.
- Experience managing IT vendor relationships, contracts, and SLAs.
- Experience developing and testing disaster recovery and business continuity plans.
Technical Skills- Deep expertise in network design and segmentation: VLANs, firewalls (Cisco, Fortinet, Palo Alto, or equivalent), SD-WAN, routing and switching.
- Strong working knowledge of cybersecurity frameworks: NIST CSF, CIS Controls, or ISO 27001.
- Hands-on experience with EDR platforms (CrowdStrike, SentinelOne, Microsoft Defender, or equivalent).
- Experience with SIEM or log management platforms (Splunk, Microsoft Sentinel, or equivalent).
- Proficient in Microsoft 365 administration, Azure AD, Conditional Access, and Intune/MDM.
- Experience with backup and DR platforms (Veeam, Zerto, Azure Backup, or equivalent).
- Working knowledge of VoIP/SIP infrastructure administration.
- Scripting ability (PowerShell, Python, or Bash) for automation and administration tasks is an asset.
Competencies- Security-first mindset - instinctively evaluates every decision through a risk and security lens.
- Strong leadership and team management skills; able to develop and hold accountable a small IT team.
- Executive-level communication skills - able to translate complex technical risk into clear business language for the Director of IT and President.
- Proactive and accountable - surfaces issues early with a proposed solution, never waits to be asked.
- Comfortable operating in a fast-paced, operationally intensive logistics environment where IT downtime has immediate business impact.
- Bilingual (English/French) is an asset given Remco's Montreal operations.
- Available for on-call response to P1 incidents outside business hours.
Certifications- CISSP (Certified Information Systems Security Professional) strongly preferred
- CISM (Certified Information Security Manager) strongly preferred
- CompTIA Security+ - minimum baseline if CISSP/CISM not held
- Microsoft Certified: Azure Administrator (AZ-104) or equivalent - preferred
- CCNA / CCNP (Cisco Certified Network Associate / Professional) preferred for network depth
- ITIL Foundation - asset for service management framework
Additional Information:This post represents a current vacancy.
We use automated tools to support application screening.