NeverHard

Director, Security Operations, Information & Corporate Security at CPP Investments — NeverHard

Director, Security Operations, Information & Corporate Security at CPP Investments in Toronto, Ontario. Apply on NeverHard.

Company
CPP Investments
Location
Toronto, Ontario
Type
full_time
Purpose. Performance. People. Joining CPP Investments means joining one of the world’s most admired and respected institutional investors to drive a single mandate: to deliver strong, sustainable returns for generations of Canadians. With a long-term horizon and global reach, we deploy capital at scale across public and private markets. Our size, stability, and disciplined investment philosophy allow us to pursue complex opportunities and build enduring partnerships worldwide. For our people, this means meaningful work with tangible impact, real opportunity, and collaboration with exceptional colleagues who value partnership and performance. Here, you’ll contribute to outcomes that matter alongside team members committed to excellence and shared success. The Role As Director, Information Security Operations, you will play a critical role in protecting CPP Investments' technology, information, and business operations by leading the delivery and continuous evolution of enterprise security operations capabilities. This senior individual contributor role provides technical leadership across vulnerability management, AI security operations, security monitoring, detection engineering, incident response, data loss prevention, and insider risk. Working collaboratively across Technology & Data and business teams, you will influence security outcomes, lead complex initiatives, and strengthen CPP Investments' cyber resilience through expertise, partnership, and execution. The Team Information Security enables CPP Investments to protect its people, technology, information, and business operations by delivering secure, resilient, and risk-informed capabilities that support the organization's global investment mandate. The Security Operations team safeguards the organization through proactive monitoring, threat detection, vulnerability management, incident response, and continuous improvement of security capabilities. The team partners closely with Technology & Data and business stakeholders to strengthen cyber resilience and manage evolving security risks. Accountabilities Lead enterprise security operations across vulnerability management, AI security operations, security monitoring, detection engineering, incident response, data loss prevention, and insider risk. Drive risk-based vulnerability management across infrastructure and cloud environments by prioritizing remediation and partnering with stakeholders to reduce risk. Design, implement, and continuously improve security detections, AI-enabled security capabilities, and Security Operations Centre (SOC) processes. Act as Incident Commander during cyber security incidents, leading technical response, stakeholder communications, recovery activities, and post-incident improvements. Provide senior technical expertise and trusted guidance on security risks, controls, and remediation strategies while leading cross-functional security initiatives. Lead security operations audit activities, including evidence collection, control reviews, remediation planning, and reporting. Advance the maturity of Security Operations by developing operational metrics, contributing to strategic roadmaps, and mentoring peers through technical leadership and knowledge sharing. What You Bring Bachelor's degree in Computer Science, Information Technology, Cyber Security, Business, or a related discipline, or an equivalent combination of education and experience. 7–10+ years of progressive hands-on experience in information security with demonstrated expertise across multiple security operations disciplines. Professional security certification(s) such as CISSP, CISM, CISA, CCSP, GIAC (GCIH, GCFA, GDAT), SABSA, or equivalent are preferred. Strong technical knowledge of vulnerability management, incident response, detection engineering, cloud and container security, SIEM/XDR platforms, data loss prevention, and insider risk. Experience applying AI technologies or recognized AI security frameworks within security operations, with knowledge of security and regulatory frameworks including ISO 27001, NIST, COBIT, ITIL, OSFI B-13, PIPEDA, and SOX. Proven ability to communicate effectively with technical and executive audiences while leading complex cross-functional initiatives and security incidents. Demonstrated sound judgment, analytical thinking, collaboration, and a commitment to CPP Investments' Guiding Principles of Integrity, High Performance, and Partnership. You are motivated to contribute to something larger than yourself, approach complex challenges with rigor, and hold yourself to high standards in a collaborative, performance-driven environment. We provide colleagues with cutting-edge AI tools, dedicated learning time, and practical support to help them deliver with greater impact. Inclusion & Accessibility CPP Investments is committed to equitable access to employment and building a workforce that reflects diverse talent and perspectives. If you require accommodation at any stage of the recruitment process, please let us know and we will work with you to meet your needs. Attention: Protect Yourself from Fraud CPP Investments is committed to a secure and transparent recruitment process. We will never ask candidates for payment or financial information at any stage of hiring. All legitimate opportunities are posted on our careers page, and communications will come from our applicant tracking system, Workday. CPP Investments may use AI tools to help screen and assess applicants by analyzing resumes and applications for relevant skills and experience. These tools support, but do not replace, human decision-making. #LI-ONSITE