Senior Manager, Information Security
Job description
.
About the role
You will architect and drive the execution of enterprise-grade IT security strategies that shield Konrad's internal platforms and client deliverables from evolving cyber threats. You will own the design of security controls and governance models that safeguard critical data assets and ensure business continuity across engagements. In this leadership capacity, you will interpret complex regulatory landscapes and translate them into actionable policies that resonate with both technical engineers and executive sponsors. You will act as the authoritative voice for Konrad's security posture during client interactions, responding to rigorous assessments from some of the world's most demanding brands. The role requires a solutions-oriented mindset that balances risk management with the delivery of innovative digital experiences in a fast-paced consultancy. You will foster a culture where security is embedded into every sprint, every deployment, and every client touchpoint. Finally, you will mentor and elevate the security practices of your peers and reports, ensuring that the team operates at the highest standard of resilience and compliance.
Key facts
What you'll do
Develop and maintain a comprehensive IT security strategy that protects Konrad's internal tools, systems, and proprietary data against unauthorized access and advanced persistent threats.
Lead the design and execution of compliance initiatives to ensure alignment with client security requirements and industry frameworks such as SOC 2 and ISO 27001.
Serve as the primary liaison for client security assessments, owning the production of artifacts and responses that demonstrate Konrad's security maturity to enterprise stakeholders.
Manage end-to-end security audits, risk assessments, and vulnerability management programs, driving remediation plans and tracking risk reduction over time.
Champion security best practices by collaborating with IT, engineering, product, and consulting teams to integrate controls into internal operations and client delivery lifecycles.
Define and evolve security policies, standards, and procedures that reflect current threats, regulatory changes, and emerging technologies in the digital landscape.
Oversee the implementation of identity and access management controls, ensuring least-privilege principles are enforced across cloud platforms and on-premises environments.
Monitor the threat landscape and drive the adoption of protective measures for cloud security, network architecture, and secure software development lifecycle practices.
Coordinate incident response readiness activities, including playbooks, detection rules, and communication protocols to minimize business impact during events.
Establish metrics and reporting mechanisms that provide leadership with clear visibility into the state of Konrad's security posture and risk trends.
Partner with procurement and legal teams to evaluate third-party vendors and ensure contractual security obligations are met before engagement kickoff.
Promote a culture of continuous improvement by introducing security tooling, automation, and training that scales with the growth of the organization.
Act as a subject matter expert for leadership, translating technical risk into business terms that inform strategic decision-making and client conversations.
Support the development of internal roadmaps that prioritize security initiatives based on risk, impact, and resource availability.
Requirements
Bring 8 or more years of progressive experience in IT and information security, demonstrating growth in scope, responsibility, and impact over time.
Show a proven track record of managing internal IT security and compliance programs within environments such as digital agencies, technology firms, or consulting practices.
Demonstrate deep familiarity with common security frameworks and regulatory standards, including but not limited to SOC 2, ISO 27001, GDPR, and CCPA.
Maintain a strong technical background with hands-on understanding of cloud security, network architecture, access management, and secure software development practices.
Exhibit exceptional communication and negotiation skills, capable of articulating complex security concepts to technical teams and non-technical client executives alike.
Obtain industry-recognized security certifications such as CISSP, CISM, or CISA as a strong asset that validates your expertise and commitment.
Work effectively in a collaborative setting and commit to an in-person presence at the Toronto office four days per week to enable close teamwork and leadership visibility.
Display integrity, accountability, and a proactive approach to identifying and escalating security concerns before they impact the business.
Engage with continuous learning to keep current with evolving threats, technologies, and expectations of global clients.
Practical notes
Hours
See source
Travel
See source
Visa
See source
Deadlines
See source