Skip to content

Open nowPosted 12 days ago

Assistant Vice President, Information Security

firstnational34 open roles

Where
16 York St, Toronto, ON, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAssistant Vice President, Information Securityfirstnational · 16 York St, Toronto, ON, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on firstnational's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 12 days ago

The posting

We are hiring an Assistant Vice President, Information Security

Reporting To:

VP, Technology Governance, Risk and Performance

Full-Time/Part- Time:

Full-time

Posting Date:

September 21, 2026

Closing Date:

October 26, 2026

Hours of Work:

8:30 a.m. – 5:00 p.m.

Grade: Office Location:     

20.4 Toronto, ON Great location! Steps away from the main public transit station

What we offer:

Highly competitive compensation package which includes, base salary, bonus, benefits, and career advancement opportunities!   *Eligibility for benefits is dependent on the terms of employment  

  The Opportunity   The Assistant Vice President, Information Security is First National’s enterprise cybersecurity leader within Product and Technology. The role sets cybersecurity direction, operates the Information Security function, improves cyber resilience, and enables secure delivery across applications, infrastructure, cloud, identity, data, integrations, and AI.    The AVP combines technical credibility with executive leadership, sound risk judgment, and disciplined execution. The role initially reports to the Chief Product and Technology Officer and is expected to transition to the Vice President, Technology Governance, Risk and Performance as the target operating model is established, while retaining direct escalation access to the CPTO for material cyber incidents or risk exposures.    How you will contribute:   Cybersecurity Strategy, Governance and Assurance 

Define and execute the cybersecurity strategy and capability roadmap aligned to business priorities, technology modernization, risk appetite, client obligations, and the Product and Technology operating model. 

Serve as the senior cybersecurity authority within Product and Technology, advising executives and governance forums on material risk, incidents, exceptions, investment priorities, and security performance. Operate first line cyber risk management while accountable business and technology owners remain responsible for remediation and residual risk decisions within delegated authority. 

Maintain and continuously improve the Information Security Management System, policies, standards, control requirements, cybersecurity compliance activities, and performance measures. Maintain strong ISO 27001 aligned practices and support applicable regulatory, contractual, client, and internal policy requirements. 

Lead the Information Security responsibilities for SOC 1 and SOC 2 audits and attestations, including security control ownership, evidence readiness, management responses, remediation, and external auditor support, in partnership with Technology Governance, Risk and Performance. 

Own the security response to client questionnaires, due diligence, audits, assurance reviews, and control assessments from third party underwriting and servicing clients and strategic partners. Act as the senior security contact for client security teams and maintain reusable approved responses, control narratives, and evidence to improve speed and consistency. 

Security Operations, Incident Response & Cyber Resilience

Lead security monitoring, managed detection and response, threat intelligence, detection engineering, incident response, and digital forensics coordination, with clear service levels and performance expectations for managed security providers. 

Lead the technical cyber response during material incidents and coordinate with technology, business, legal, privacy, communications, risk, and other enterprise leaders on crisis management, notification, service recovery, and business continuity actions. 

Maintain and test cyber incident playbooks, executive and technical exercises, and recovery scenarios, using incidents, threat intelligence, control testing, and exercises to drive continuous improvement and tracked corrective actions. 

Security Engineering, Identity, Cloud and Application Security 

Define practical security architecture standards, reusable patterns, Zero Trust principles, and minimum control requirements across cloud, infrastructure, networks, end user computing, applications, APIs, integrations, data platforms, and emerging technology.  Set identity security requirements across authentication, privileged access, access governance, conditional access, service identities, secrets, certificates, and excessive or persistent access, while partnering with Enterprise IT and Infrastructure on endpoint, network, cloud, logging, backup, and hardening controls.  Embed security into engineering practices and delivery pipelines through secure coding, threat modelling, dependency and secrets scanning, SAST, DAST, penetration testing, API security, software supply chain controls, and proportionate automated security gates.  Own the vulnerability and exposure management program, including discovery, risk prioritization, remediation standards, exception governance, validation, aging visibility, and escalation. Engineering, Infrastructure, and service owners remain accountable for remediation.  Prioritize material security debt in legacy and proprietary applications and use penetration testing, attack simulation, red team, or purple team techniques where they provide clear risk reduction or validate material controls. 

AI, Data, Third Party and Human Risk 

Define cybersecurity guardrails for AI and automation, including identity, sensitive data handling, secrets, model and prompt attack risks, third party AI services, logging, monitoring, abuse protection, and secure integration patterns, while partnering with Product, Engineering, Data, Privacy, Legal, and Risk on broader governance. 

Set technical data protection requirements for access, leakage prevention, monitoring, and protection of sensitive customer and business information while data governance and privacy accountabilities remain with their respective owners. 

Own the cybersecurity assessment, security requirements, risk recommendations, and monitoring components of critical third party and cloud service risk, while Procurement, vendor management, business owners, and Enterprise Risk retain their broader lifecycle accountabilities. 

Lead an effective security awareness and human risk program using role based education and targeted interventions for higher risk populations and activities. 

Leadership and Operating Performance 

Build and lead a high performing Information Security team with clear accountabilities, modern technical depth, succession coverage, and a culture of ownership, transparency, and collaboration. 

Define the security operating model, workforce plan, capability roadmap, and sourcing approach across internal capability, managed services, and specialist expertise.  Manage the security budget, tools, vendors, and service performance with clear linkage between spend, risk reduction, control effectiveness, remediation performance, incident response, and continuous improvement, rationalizing overlap where it adds cost or complexity without improving protection. 

  The experience you need:   Leadership and Industry Experience 

Significant progressive experience in cybersecurity, information security, security engineering, or technology risk, typically including 12 or more years of relevant experience and several years leading multidisciplinary security teams or major enterprise security programs. 

Demonstrated experience advising senior executives and making risk based decisions during material cyber incidents, significant technology changes, or major control issues. 

Experience leading security through modernization, cloud adoption, managed service models, operating model change, or significant technology transformation. Experience in financial services, lending, payments, insurance, or another regulated and data intensive environment is strongly preferred. 

Technical, Assurance and Regulatory Depth 

Strong practical knowledge of security operations, incident response, vulnerability management, identity and privileged access, cloud security, application and API security, DevSecOps, data protection, third party security, security architecture, cyber resilience, and software supply chain security. 

Strong experience with Microsoft Azure and Microsoft 365 security capabilities, with working familiarity across Microsoft Sentinel, Defender, Entra ID, Conditional Access, Purview, Intune, and GRC platforms used for cyber risk, controls, issues, evidence, audit, and assurance workflows. 

Strong working knowledge of ISO 27001, NIST Cybersecurity Framework, SOC control environments, Zero Trust principles, PIPEDA, applicable provincial privacy requirements, FSRA expectations where relevant, and client driven cyber expectations from regulated financial institutions, including relevant OSFI guidance where applicable through client or contractual obligations. 

Practical understanding of AI security risks and controls and the ability to challenge technical designs and remediation plans credibly without needing to personally perform every engineering task. 

Education, Communication and Judgment 

Post-secondary degree or diploma in cybersecurity, computer science, engineering, technology, risk management, or a related discipline, or an equivalent combination of education and relevant experience. Professional certifications such as CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials are preferred. 

Exceptional written and verbal communication, executive presence, sound judgment under pressure, and the ability to translate technical and regulatory risk into clear decisions, priorities, and accountabilities. 

Demonstrated ability to work across Product, Engineering, Infrastructure, Risk, Legal, Privacy, Compliance, Internal Audit, Human Resources, and business teams without creating unnecessary process or ambiguity. Professional fluency in English is required; French is an asset. 

  Relationships:  

External Customers: Regular engagement with external auditors, assessors, regulators or supervisory authorities where applicable, client security teams, cybersecurity and technology vendors, managed security providers, strategic technology partners, consultants, and government or law enforcement authorities when authorized.

 

Internal Customers: Frequent engagement with the CPTO, Vice President of Technology Governance, Risk and Performance, Product and Technology leaders, Enterprise Risk, Legal, Privacy, Compliance, Internal Audit, Human Resources, business executives, Engineering, Enterprise IT and Infrastructure, data owners, and operational leaders.

  Working Environment and Physical Demands Analysis:  

Office environment Periods of high volume with tight timelines Long periods of stationary position/sitting Prolonged periods of repetitive movement (i.e. using a keyboard and mouse) Long periods of time in viewing a computer screen Multi-tasking may include speaking to customers on a telephone call while looking up information on a computer program.

  Why join First National?  

Competitive Compensation Comprehensive benefits program (i.e., Health Spending Account, Maternity and Parental Leave Top Up) Extensive training programs to set our employees up for success Modern office environment conducive to collaboration Supportive teamwork culture Opportunities to give back to the communities and work through events focused on a variety of charities Ongoing social events throughout the year

  The team you’ll join: Founded in 1988, First National is one of Canada’s largest non-bank lenders. We provide residential mortgages exclusively through the mortgage broker channel and we are Canada’s largest commercial mortgage lender. First National has been consistently recognized as a great place to work and we are proud that our employee engagement feedback is higher than our industry partners.     We would like to thank all applications for their interest in this existing vacancy, but only candidates selected for an interview will be contacted.   Artificial Intelligence is not used in our recruitment or hiring process for this role. #FNLOON First National is proud to be an equal opportunity employer and is committed to diversity and inclusion regardless of race, color, religion, national origin, age, gender identity, physical or mental disability, sexual orientation and any other category protected by law.   First National supports requests for accommodation from applicants with disabilities; please contact Human Resources at [email protected] should you need an accommodation at any point in the recruitment process.        

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against firstnational's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on firstnational's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    firstnational's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.