Reporting to the Chief Information Officer, the Vice President, Security and IT Operations is responsible for establishing and leading Lassonde's North American shared services function for infrastructure, IT operations, end-user support and cybersecurity. The incumbent will unify Canadian and US teams, tools and processes into one operating model, with one service desk, one set of service levels and one security posture across our 19 plants and offices.
This is a foundational executive role responsible for defining the strategy, operating model and governance required to support business growth, manufacturing modernization and enterprise technology transformation, while strengthening cybersecurity, operational resilience and risk management, while serving as a strategic partner to the Executive Leadership Team and business leaders. The successful candidate will also provide trusted counsel on cybersecurity, operational resilience and technology risk to the Audit Committee, the Board and our insurers.
Job advantages - A competitive salary with opportunities for advancement and career development.
- Access to a group insurance plan & a pension plan with employer contributions.
- Telemedicine & employee and family assistance programs.
- Recognition & wellness programs for employees.
Key activitiesStrategy and Stakeholder Engagement: - Define the North American cybersecurity and IT operations strategy and multi-year roadmap in collaboration with the CIO.
- Partner with functional leaders to understand their priorities and offer secure, practical solutions.
- Own a single cybersecurity scorecard, and report on cyber risk, maturity and program progress.
- Own the cyber insurance relationship, including renewals and the evidence underwriters require, and respond to customer security assessments.
Operating Model and Leadership: - Stand up one North American Security and IT Operations shared services function: charter, operating model, RACI, service catalogue and KPIs.
- Bring the Canadian and US teams together under one leadership, one way of working and one set of standards.
- Recruit, develop and lead a team across infrastructure, network, cloud, IT service management, end-user support, security operations and identity.
- Manage the function's budget, vendor strategy and sourcing model, including managed services, security operations centre (SOC) and incident response partners, and consolidate contracts and tools across Canada and the US.
Infrastructure, Cloud and IT Operations: - Own the North American infrastructure estate across plants, distribution centres and offices.
- Define and execute the infrastructure roadmap to ensure the modernization, harmonization and evolution of the organization's technology capabilities.
- Ensure plant connectivity and infrastructure deliver the availability manufacturing requires, and are ready for plant digitalization, IoT and AI workloads.
- Manage capacity, performance, lifecycle and cost, including cloud consumption and FinOps practices.
- Run one North American service desk on one ITSM platform to ensure efficient and consistent service.
- Establish ITIL-based incident, problems, change, request and asset management, with monitoring, automation and AI-assisted.
- Deliver a consistent employee technology experience across North America.
- Publish service levels the business can hold IT to, and report performance on a regular scorecard.
- Provide 24/7 support coverage for manufacturing operations.
- Organize field and site support to deliver reliable, responsive service across all locations and support the adoption of new tools and technologies throughout the organization, with service available in both English and French.
Cybersecurity, Operational Technology Security & Operational Resilience: - Lead the security program, continuously assessing maturity, establishing a realistic target state, and strengthening the organization's security posture.
- Lead identity and access management, the 24/7 managed security operations centre (SOC), vulnerability and patch management, and security awareness for all employees.
- Embed secure-by-design practices in transformation programs, cloud adoption and AI initiatives, and use AI for defence within the company's AI governance.
- Lead the OT cybersecurity program across our plants in partnership with Manufacturing and Operations: asset inventory, IT/OT network segmentation, OT monitoring and aligned controls.
- Lead IT/OT network segmentation initiatives that enable plant digitalization, connected technologies and manufacturing modernization while protecting production uptime and operational safety.
- Secure third-party and vendor remote access to plant networks.
- Strengthen the organization's resilience to limit the impact of cyber incidents and preserve operational continuity across all manufacturing sites.
- Own one North American incident response model, including playbooks, out-of-band communications and crisis coordination with stakeholders.
- Run recurring tabletop exercises with executives and teams, and drive their recommendations to completion.
Risk, Compliance and Trust: - Lead cybersecurity and data protection components of regulatory obligation and compliance requirements in collaboration with key stakeholders.
- Lead, in partnership with Legal, Privacy, Finance and Internal Audit, the cybersecurity and data protection aspects of the organization's regulatory and compliance obligations, including IT general controls for financial reporting.
- Manage third-party and supplier security risk and emerging threats, including AI-enabled fraud.
- Ensure audit readiness and provide clear, reliable evidence for internal and external audits.
Required training and experience - Bachelor's degree in a relevant discipline (computer science, engineering, information security or related field); an advanced degree (MBA, MSc or equivalent) is preferred.
- CISSP, CISM or equivalent security certification preferred.
- Minimum 15 years of progressive experience in IT infrastructure, operations and cybersecurity, with at least 5 years in a senior leadership role, and a meaningful portion in manufacturing, CPG or food and beverage.
- Proven leadership of OT and plant-floor security across multiple industrial sites.
- Proven track record building or transforming an infrastructure, IT operations and security function across multi-site, multi-country operations, ideally including Canada and the US, including consolidating service desks, tools and teams into one shared services model.
- Experience leading the response to major cybersecurity incidents and running tabletop exercises with executive teams.
- Experience operating in a publicly traded environment, including IT general controls, audit readiness, cyber insurance and reporting to an Audit Committee or Board.
- Deep working knowledge of security frameworks (CIS Controls v8, NIST CSF, IEC 62443), security operations (managed SOC, SIEM, EDR, SOAR), identity and privileged access management, cloud and network security, and OT/ICS security.
- Deep working knowledge of infrastructure, hybrid cloud, networks and IT service management (ITIL) in a 24/7 manufacturing environment, and current on emerging threats.
Skills sought - Excellent command of English, written and spoken, required to lead teams and work with partners across Canada and the United States; French is an asset.
- A business-minded approach to security, with the ability to calibrate risk to the organization's maturity and communicate complex trade-propose pragmatic solutions.
- Executive presence and credibility to brief the Audit Committee, the Board, insurers and customers on cyber risk.
- Leadership grounded in respect and trust, with the ability to build cohesive, engaged teams across two countries and work constructively with internal teams and external partners.
- Calm, decisive leadership during incidents, crises and high-pressure situations.
- Demonstrated ability to establish a new function, recruit and develop talent, and operate effectively in environments where structure and processes are still being built.
- Demonstrated change leadership in complex organizations.
- Strong knowledge of governance, compliance and privacy frameworks applicable in Canada and the United States, including Quebec Law 25, PIPEDA, U.S. state privacy regimes, and IT general control requirements.
Specific conditions regarding the position: - Based in Rougemont, with regular presence at offices and plants.
- Ability and willingness to travel within Canada and the United States as required by the business.
- Availability to lead the response to major security incidents and crisis situations outside regular business hours.
Work location
Rougemont, QC
Published date
October 9, 2026
Type of position
Permanent
Schedule Type
Full-time