Director, Information Security - IFS Copperleaf
Job in
Vancouver, BC, Canada
Listed on 2026-07-20
Listing for:
PVH (Tommy Hilfiger/Calvin Klein)
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, Data Security, Security Management & Operations
Job Description & How to Apply Below
Role Details
- Title:
Director, Information Security - Department:
Technology Experience (TX) - Reports To:
SVP Finance & Enterprise Solutions - Direct Reports:
Yes, people leader with oversight on full information security lifecycle across five areas:
Governance, Risk & Compliance (GRC);
Product & Application Security;
Security Operations & Threat Management;
Cloud & Infrastructure Security; and Trust & Customer Assurance.
- Security Strategy & Posture: Build a measurable, business-aligned security strategy across technology, networks, data, applications, cloud, and the secure use of AI. Own the security controls that protect personal data and partner with Legal and the DPO on the privacy program, embedding privacy-by-design into the product lifecycle.
- Risk, Governance & Compliance: Own enterprise security risk and the control framework. Own and operate the SOC 2 and ISO 27001 programs end to end, maintaining certification, audit, and regulatory readiness (GDPR, CCPA, PIPEDA). Own the security and data-protection controls and partner with Legal and the DPO on the privacy program.
- Security Operations & Resilience: Direct threat detection, incident response, vulnerability management, and business continuity so the organization can prevent, withstand, and recover from attacks.
- Customer Trust & Commercial Enablement: Enable enterprise sales and renewals by providing timely, credible, and risk-based customer assurance, turning a strong security posture into a competitive advantage with regulated and critical-infrastructure customers.
- People & Organizational Leadership: Build, structure, and develop a high-performing security team grounded in speed, focus, simplicity, accountability, and a clear "stay secure" culture across Copperleaf.
Duties & Responsibilities
- Security Strategy & Governance
- Develop, implement, and maintain an enterprise-wide information security strategy aligned to business objectives, available resources, and Copperleaf's Industrial-AI product context.
- Develop and maintain security standards and practices based on industry-leading frameworks.
- Establish, communicate, and enforce information security roles, responsibilities, and policies throughout the organization.
- Define a clear security engagement model and embed early-stage, "shift-left" security practices across delivery teams.
- Drive a security operating model that supports fast, focused decision-making while maintaining disciplined risk management.
- Risk Management & Compliance
- Own the Copperleaf security risk register and the enterprise risk-assessment and treatment process; implement and track mitigation plans for identified risks.
- Own the end-to-end SOC 2 and ISO 27001 programs.
- Ensure compliance with relevant regulations and standards and serve as liaison to external auditors, partners, and regulators.
- Co-develop practical AI and privacy governance with Product, IT, Legal, and the Head of AI, owning the security-and-controls dimension of the enterprise AI policy.
- Security Operations & Resilience
- Direct security operations across threat detection, monitoring, and response, leveraging SIEM, EDR, IAM, and related tooling.
- Lead incident response end to end, including rapid identification, containment, eradication, recovery, post-incident review, and continuous improvement.
- Oversee vulnerability management, threat intelligence, and proactive testing.
- Own business continuity and disaster-recovery planning and readiness for security-impacting events.
- Product, Cloud & AI Security
- Partner with R&D and Product to embed security into the software development lifecycle (SDLC).
- Demonstrate and maintain an effective security posture across cloud, on-premises, and private-cloud deployments, covering data, software, and systems, including deployment models used by regulated utilities and critical-infrastructure customers.
- Establish controls and guardrails for the secure development and use of AI across Copperleaf, in coordination with the Head of AI.
- Customer Trust & Commercial Enablement
- Own the Trust Center and the external security narrative used in sales and renewals; act as primary point of contact for customer security inquiries, questionnaires, and audits.
- Partner with Legal and commercial teams through customer negotiations, including reviewing and providing risk-based input on security schedules, data-protection terms, redlines, and customer-specific assurance commitments.
- Mature the security posture into a client-facing trust advantage.
- Leadership, Team & Organizational Development
- Own the organizational design and staffing model for the security function, sizing and structuring the team and its leadership to align with risk, demand, and business priorities.
- Directly manage, coach, and develop the Info Sec team across all five security functions, conducting regular performance and career-development reviews.
- Forecast changing business needs and align team skills and experience; provide technical leadership and guidance to deliver secure outcomes.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×