We are hiring an Assistant Vice President, Information Security
Reporting To
VP, Technology Governance, Risk and Performance
Full-Time/Part- Time
Full-time
Posting Date
September 21, 2026
Closing Date
October 26, 2026
Hours Of Work
8:30 a.m. – 5:00 p.m.
Grade
Office Location:
20.4
Toronto, ON
Great location! Steps away from the main public transit station
What We Offer
Highly competitive compensation package which includes, base salary, bonus, benefits, and career advancement opportunities!
- Eligibility for benefits is dependent on the terms of employment
The Opportunity
The Assistant Vice President, Information Security is First National’s enterprise cybersecurity leader within Product and Technology. The role sets cybersecurity direction, operates the Information Security function, improves cyber resilience, and enables secure delivery across applications, infrastructure, cloud, identity, data, integrations, and AI.
The AVP combines technical credibility with executive leadership, sound risk judgment, and disciplined execution. The role initially reports to the Chief Product and Technology Officer and is expected to transition to the Vice President, Technology Governance, Risk and Performance as the target operating model is established, while retaining direct escalation access to the CPTO for material cyber incidents or risk exposures.
How You Will Contribute
Cybersecurity Strategy, Governance and Assurance
- Define and execute the cybersecurity strategy and capability roadmap aligned to business priorities, technology modernization, risk appetite, client obligations, and the Product and Technology operating model.
- Serve as the senior cybersecurity authority within Product and Technology, advising executives and governance forums on material risk, incidents, exceptions, investment priorities, and security performance. Operate first line cyber risk management while accountable business and technology owners remain responsible for remediation and residual risk decisions within delegated authority.
- Maintain and continuously improve the Information Security Management System, policies, standards, control requirements, cybersecurity compliance activities, and performance measures. Maintain strong ISO 27001 aligned practices and support applicable regulatory, contractual, client, and internal policy requirements.
- Lead the Information Security responsibilities for SOC 1 and SOC 2 audits and attestations, including security control ownership, evidence readiness, management responses, remediation, and external auditor support, in partnership with Technology Governance, Risk and Performance.
- Own the security response to client questionnaires, due diligence, audits, assurance reviews, and control assessments from third party underwriting and servicing clients and strategic partners. Act as the senior security contact for client security teams and maintain reusable approved responses, control narratives, and evidence to improve speed and consistency.
Security Operations, Incident Response & Cyber Resilience
- Lead security monitoring, managed detection and response, threat intelligence, detection engineering, incident response, and digital forensics coordination, with clear service levels and performance expectations for managed security providers.
- Lead the technical cyber response during material incidents and coordinate with technology, business, legal, privacy, communications, risk, and other enterprise leaders on crisis management, notification, service recovery, and business continuity actions.
- Maintain and test cyber incident playbooks, executive and technical exercises, and recovery scenarios, using incidents, threat intelligence, control testing, and exercises to drive continuous improvement and tracked corrective actions.
Security Engineering, Identity, Cloud and Application Security
- Define practical security architecture standards, reusable patterns, Zero Trust principles, and minimum control requirements across cloud, infrastructure, networks, end user computing, applications, APIs, integrations, data platforms, and emerging technology.
- Set identity security requirements across authentication, privileged access, access governance, conditional access, service identities, secrets, certificates, and excessive or persistent access, while partnering with Enterprise IT and Infrastructure on endpoint, network, cloud, logging, backup, and hardening controls.
- Embed security into engineering practices and delivery pipelines through secure coding, threat modelling, dependency and secrets scanning, SAST, DAST, penetration testing, API security, software supply chain controls, and proportionate automated security gates.
- Own the vulnerability and exposure management program, including discovery, risk prioritization, remediation standards, exception governance, validation, aging visibility, and escalation. Engineering, Infrastructure, and service owners remain accountable for remediation.
- Prioritize material security debt in legacy and proprietary applications and use penetration testing, attack simulation, red team, or purple team techniques where they provide clear risk reduction or validate material controls.
AI, Data, Third Party and Human Risk
- Define cybersecurity guardrails for AI and automation, including identity, sensitive data handling, secrets, model and prompt attack risks, third party AI services, logging, monitoring, abuse protection, and secure integration patterns, while partnering with Product, Engineering, Data, Privacy, Legal, and Risk on broader governance.
- Set technical data protection requirements for access, leakage prevention, monitoring, and protection of sensitive customer and business information while data governance and privacy accountabilities remain with their respective owners.
- Own the cybersecurity assessment, security requirements, risk recommendations, and monitoring components of critical third party and cloud service risk, while Procurement, vendor management, business owners, and Enterprise Risk retain their broader lifecycle accountabilities.
- Lead an effective security awareness and human risk program using role based education and targeted interventions for higher risk populations and activities.
Leadership and Operating Performance
- Build and lead a high performing Information Security team with clear accountabilities, modern technical depth, succession coverage, and a culture of ownership, transparency, and collaboration.
- Define the security operating model, workforce plan, capability roadmap, and sourcing approach across internal capability, managed services, and specialist expertise.
- Manage the security budget, tools, vendors, and service performance with clear linkage between spend, risk reduction, control effectiveness, remediation performance, incident response, and continuous improvement, rationalizing overlap where it adds cost or complexity without improving protection.
The Experience You Need
Leadership and Industry Experience
- Significant progressive experience in cybersecurity, information security, security engineering, or technology risk, typically including 12 or more years of relevant experience and several years leading multidisciplinary security teams or major enterprise security programs.
- Demonstrated experience advising senior executives and making risk based decisions during material cyber incidents, significant technology changes, or major control issues.
- Experience leading security through modernization, cloud adoption, managed service models, operating model change, or significant technology transformation. Experience in financial services, lending, payments, insurance, or another regulated and data intensive environment is strongly preferred.
Technical, Assurance and Regulatory Depth
- Strong practical knowledge of security operations, incident response, vulnerability management, identity and privileged access, cloud security, application and API security, DevSecOps, data protection, third party security, security architecture, cyber resilience, and software supply chain security.
- Strong experience with Microsoft Azure and Microsoft 365 security capabilities, with working familiarity across Microsoft Sentinel, Defender, Entra ID, Conditional Access, Purview, Intune, and GRC platforms used for cyber risk, controls, issues, evidence, audit, and assurance workflows.
- Strong working knowledge of ISO 27001, NIST Cybersecurity Framework, SOC control environments, Zero Trust principles, PIPEDA, applicable provincial privacy requirements, FSRA expectations where relevant, and client driven cyber expectations from regulated financial institutions, including relevant OSFI guidance where applicable through client or contractual obligations.
- Practical understanding of AI security risks and controls and the ability to challenge technical designs and remediation plans credibly without needing to personally perform every engineering task.
Education, Communication and Judgment
- Post-secondary degree or diploma in cybersecurity, computer science, engineering, technology, risk management, or a related discipline, or an equivalent combination of education and relevant experience. Professional certifications such as CISSP, CISM, CRISC, CISA, CCSP, or comparable credentials are preferred.
- Exceptional written and verbal communication, executive presence, sound judgment under pressure, and the ability to translate technical and regulatory risk into clear decisions, priorities, and accountabilities.
- Demonstrated ability to work across Product, Engineering, Infrastructure, Risk, Legal, Privacy, Compliance, Internal Audit, Human Resources, and business teams without creating unnecessary process or ambiguity.
- Professional fluency in English is required; French is an asset.
Relationships
- External Customers: Regular engagement with external auditors, assessors, regulators or supervisory authorities where applicable, client security teams, cybersecurity and technology vendors, managed security providers, strategic technology partners, consultants, and government or law enforcement authorities when authorized.
- Internal Customers: Frequent engagement with the CPTO, Vice President of Technology Governance, Risk and Performance, Product and Technology leaders, Enterprise Risk, Legal, Privacy, Compliance, Internal Audit, Human Resources, business executives, Engineering, Enterprise IT and Infrastructure, data owners, and operational leaders.
Working Environment And Physical Demands Analysis
- Office environment
- Periods of high volume with tight timelines
- Long periods of stationary position/sitting
- Prolonged periods of repetitive movement (i.e. using a keyboard and mouse)
- Long periods of time in viewing a computer screen
- Multi-tasking may include speaking to customers on a telephone call while looking up information on a computer program.
Why join First National?
- Competitive Compensation
- Comprehensive benefits program (i.e., Health Spending Account, Maternity and Parental Leave Top Up)
- Extensive training programs to set our employees up for success
- Modern office environment conducive to collaboration
- Supportive teamwork culture
- Opportunities to give back to the communities and work through events focused on a variety of charities
- Ongoing social events throughout the year
The Team You’ll Join
Founded in 1988, First National is one of Canada’s largest non-bank lenders. We provide residential mortgages exclusively through the mortgage broker channel and we are Canada’s largest commercial mortgage lender.
First National has been consistently recognized as a great place to work and we are proud that our employee engagement feedback is higher than our industry partners.
We would like to thank all applications for their interest in this existing vacancy, but only candidates selected for an interview will be contacted.
Artificial Intelligence is not used in our recruitment or hiring process for this role. #FNLOON
First National is proud to be an equal opportunity employer and is committed to diversity and inclusion regardless of race, color, religion, national origin, age, gender identity, physical or mental disability, sexual orientation and any other category protected by law.
First National supports requests for accommodation from applicants with disabilities; please contact Human Resources at [email protected] should you need an accommodation at any point in the recruitment process.