Dye & Durham, a leading global provider of cloud–based software and technology solutions, provides critical information services and workflows used by clients all over the world to manage their process, information, and regulatory requirements. The company is focused on an unwavering commitment to customer excellence and to the personal and professional growth of its employees. It offers rewarding opportunities for those with legal, tech, financial services and government relations expertise. With clients that include major law firms, financial service institutions and government organizations in Canada, the United Kingdom, Ireland, South Africa and Australia, a fulfilling career awaits you at Dye & Durham.
The Director, Information Security (InfoSec) is responsible for leading and evolving the organisation's global information security function, ensuring the protection of corporate systems, employee productivity platforms, customer-facing products, data, and technology assets. This role will define and execute the security strategy, strengthen cyber resilience, manage security risk, and implement scalable security controls that support business growth and regulatory compliance.
The successful candidate will build and mature security capabilities from the ground up, improving legacy environments, embedding security best practices across the organisation, and ensuring robust monitoring, governance, and risk management frameworks are in place. Through strong leadership and technical expertise, this role will have a significant impact on safeguarding the organisation, supporting customer trust, and enabling secure business operations globally.
Key Responsibilities
- Lead the global information security function and provide strategic direction across all security domains.
- Develop and implement the organisation's information security strategy, operating model, and roadmap.
- Oversee security for corporate platforms, including email, collaboration, and productivity tools.
- Ensure the security of customer-facing products, applications, and technology services.
- Build and mature security capabilities and processes, establishing scalable security programmes from the ground up.
- Identify, assess, and mitigate cyber security risks through effective governance and risk management practices.
- Lead vulnerability management, penetration testing, threat detection, and ongoing security monitoring activities.
- Implement compensating controls to address audit findings, compliance requirements, and identified risks.
- Improve and modernise legacy systems while maintaining appropriate security controls and business continuity.
- Partner with technology, infrastructure, engineering, product, legal, privacy, and risk teams to embed security-by-design principles.
- Lead incident response planning, preparedness, and crisis management activities.
- Develop executive reporting, security metrics, and dashboards to communicate security posture and programme maturity.
- Build, mentor, and lead a high-performing Information Security team.
Skills, Knowledge and Expertise
- 10+ years of experience in Information Security, Cyber Security, Technology Risk, or related technology leadership roles.
- Experience building, transforming, or scaling security functions within growing organisations.
- Strong technical foundation in infrastructure, IT operations, systems administration, networking, or network security.
- Demonstrated experience leading security operations, vulnerability management, penetration testing, and incident response programmes.
- Strong understanding of security frameworks and industry standards such as ISO 27001, NIST, CIS Controls, SOC 2, and PCI DSS.
- Experience implementing governance, risk, and compliance frameworks, including audit remediation and compensating controls.
- Knowledge of cloud security, identity and access management, application security, and secure software development practices.
- Proven ability to communicate technical risks and security priorities to executive and non-technical stakeholders.
- Strong leadership, stakeholder management, and team development capabilities.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, or equivalent are highly desirable.
Benefits
At Dye & Durham we strive to be visionaries! As a leader in our field, we ensure our employees are ready for the next challenge in their journey with us by offering internal and external training opportunities. We offer competitive salaries and a whole host of benefits including healthcare, pension, company discounts, wellness programs, and paid days off to move house or volunteer for your favourite charity.
#DDhp
Do you share our DNA?