
Job Overview
Location
Remote - Canada
Job Type
Full-time
Category
Software Engineering
Date Posted
July 2, 2026
Full Job Description
đź“‹ Description
- • Lead Directive’s information security strategy across a fully remote workforce operating in the United States, Canada, Mexico, and the United Kingdom.
- • Develop and execute a scalable cybersecurity roadmap to mature the organization’s security posture and align with business growth objectives.
- • Establish and maintain enterprise-wide security policies, standards, and governance frameworks compliant with industry best practices.
- • Present cybersecurity risks, metrics, and strategic recommendations directly to executive leadership and department heads.
- • Conduct ongoing enterprise-wide cybersecurity risk assessments covering infrastructure, endpoints, applications, and business processes.
- • Build and maintain a cybersecurity risk register and prioritize remediation efforts based on business impact and threat severity.
- • Perform third-party vendor security assessments and manage ongoing vendor risk exposure.
- • Configure and enforce data governance policies across distributed tools including Notion, Google Drive, and Stratos to prevent data silos.
- • Manage device security policies using Kandji MDM software to protect company assets and ensure endpoint compliance.
- • Own and operate the organization’s incident response program, including playbooks, tabletop exercises, and post-incident reviews.
- • Oversee endpoint security, identity and access management, privileged access controls, and multi-factor authentication (MFA) implementation.
- • Partner with the Senior IT Manager to implement technical security controls and monitor the health of the IT environment.
- • Coordinate with external security vendors and managed security providers to augment internal capabilities.
- • Lead compliance initiatives including SOC 2 Type II certification and prepare for future security audits and certifications.
- • Own customer security questionnaires and support enterprise sales by demonstrating Directive’s security posture to prospects.
- • Collaborate with Legal, Insurance, and Finance teams on privacy, data governance, and regulatory compliance requirements.
- • Maintain comprehensive documentation for security policies, controls, audit evidence, and compliance readiness.
- • Design and manage company-wide security awareness and phishing training programs to reduce human risk.
- • Promote a security-first culture across all departments through education on evolving threats, social engineering, AI risks, and data protection.
- • Define and track measurable security KPIs and provide regular executive reporting on organizational security maturity and trends.
- • Develop and oversee business continuity and disaster recovery planning to ensure operational resilience during security events.
- • Serve as a trusted strategic partner to executive leadership by balancing strong security practices with business agility and innovation.
- • Ensure all security initiatives support the company’s remote-first model and distributed workforce across multiple jurisdictions.
🎯 Requirements
- • 7+ years of experience in cybersecurity, information security, or risk management
- • 3+ years leading enterprise security programs or security teams
- • Demonstrated experience performing cybersecurity risk assessments and threat modeling
- • Strong knowledge of cloud-first and SaaS-based environments including Google Workspace, Salesforce, NetSuite, Okta, and modern identity platforms
- • Experience implementing and maintaining security frameworks such as SOC 2, ISO 27001, or the NIST Cybersecurity Framework
- • Deep understanding of endpoint security, identity management, vulnerability management, incident response, and security operations
🏖️ Benefits
- • Annual base salary range of $165,000–$200,000 CAD
- • 100% employer-paid medical, dental, vision, disability, and life insurance for employee; 50% employer contribution for dependents
- • Access to mental health support via Spring Health and Headspace membership
- • Physical wellness benefits including Omada physical therapy, Carrott fertility support, Aaptiv virtual workouts, and One Medical membership
- • Unlimited PTO with a 2-week minimum, paid company holidays, birthday off, End of Year Recharge (Dec 24–Jan 1), and paid parental leave
- • Traditional and Roth 401(k) with 3% company match
- • Annual bonus based on tenure, scaling in value over time
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About Directive Consulting LLC
Directive is a performance marketing agency for software companies, blending search, paid media, and content strategy to accelerate pipeline growth. Founded in 2014 and headquartered in Irvine, California, the agency serves B2B SaaS clients across North America and Europe through data-driven programs that integrate SEO, PPC, and lifecycle marketing. Services include paid search, paid social, marketing automation, and revenue operations consulting, delivered by cross-functional teams focused on measurable pipeline and ARR impact rather than vanity metrics.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Lavendo Inc.
2 months ago

Fieldguide Inc.
27 days ago

Baldwin Technology Company Inc.
3 months ago

Surglobal Inc.
3 months ago