jobs Logo

Top Benefits

Cutting-edge AI tools
Dedicated learning time

About the role

Purpose. Performance. People.

Joining CPP Investments means joining one of the world’s most admired and respected institutional investors to drive a single mandate: to deliver strong, sustainable returns for generations of Canadians. With a long-term horizon and global reach, we deploy capital at scale across public and private markets. Our size, stability, and disciplined investment philosophy allow us to pursue complex opportunities and build enduring partnerships worldwide. For our people, this means meaningful work with tangible impact, real opportunity, and collaboration with exceptional colleagues who value partnership and performance. Here, you’ll contribute to outcomes that matter alongside team members committed to excellence and shared success.

The Role

As Director, Information Security Operations, you will play a critical role in protecting CPP Investments' technology, information, and business operations by leading the delivery and continuous evolution of enterprise security operations capabilities.

This senior individual contributor role provides technical leadership across vulnerability management, AI security operations, security monitoring, detection engineering, incident response, data loss prevention, and insider risk. Working collaboratively across Technology & Data and business teams, you will influence security outcomes, lead complex initiatives, and strengthen CPP Investments' cyber resilience through expertise, partnership, and execution.

The Team

Information Security enables CPP Investments to protect its people, technology, information, and business operations by delivering secure, resilient, and risk-informed capabilities that support the organization's global investment mandate. The Security Operations team safeguards the organization through proactive monitoring, threat detection, vulnerability management, incident response, and continuous improvement of security capabilities. The team partners closely with Technology & Data and business stakeholders to strengthen cyber resilience and manage evolving security risks. Accountabilities Lead enterprise security operations across vulnerability management, AI security operations, security monitoring, detection engineering, incident response, data loss prevention, and insider risk. Drive risk-based vulnerability management across infrastructure and cloud environments by prioritizing remediation and partnering with stakeholders to reduce risk. Design, implement, and continuously improve security detections, AI-enabled security capabilities, and Security Operations Centre (SOC) processes. Act as Incident Commander during cyber security incidents, leading technical response, stakeholder communications, recovery activities, and post-incident improvements. Provide senior technical expertise and trusted guidance on security risks, controls, and remediation strategies while leading cross-functional security initiatives. Lead security operations audit activities, including evidence collection, control reviews, remediation planning, and reporting. Advance the maturity of Security Operations by developing operational metrics, contributing to strategic roadmaps, and mentoring peers through technical leadership and knowledge sharing. What You Bring Bachelor's degree in Computer Science, Information Technology, Cyber Security, Business, or a related discipline, or an equivalent combination of education and experience. 7–10+ years of progressive hands-on experience in information security with demonstrated expertise across multiple security operations disciplines. Professional security certification(s) such as CISSP, CISM, CISA, CCSP, GIAC (GCIH, GCFA, GDAT), SABSA, or equivalent are preferred. Strong technical knowledge of vulnerability management, incident response, detection engineering, cloud and container security, SIEM/XDR platforms, data loss prevention, and insider risk. Experience applying AI technologies or recognized AI security frameworks within security operations, with knowledge of security and regulatory frameworks including ISO 27001, NIST, COBIT, ITIL, OSFI B-13, PIPEDA, and SOX. Proven ability to communicate effectively with technical and executive audiences while leading complex cross-functional initiatives and security incidents. Demonstrated sound judgment, analytical thinking, collaboration, and a commitment to CPP Investments' Guiding Principles of Integrity, High Performance, and Partnership.

You are motivated to contribute to something larger than yourself, approach complex challenges with rigor, and hold yourself to high standards in a collaborative, performance-driven environment.

We provide colleagues with cutting-edge AI tools, dedicated learning time, and practical support to help them deliver with greater impact. Inclusion & Accessibility CPP Investments is committed to equitable access to employment and building a workforce that reflects diverse talent and perspectives. If you require accommodation at any stage of the recruitment process, please let us know and we will work with you to meet your needs. Attention: Protect Yourself from Fraud CPP Investments is committed to a secure and transparent recruitment process. We will never ask candidates for payment or financial information at any stage of hiring. All legitimate opportunities are posted on our careers page, and communications will come from our applicant tracking system, Workday.

CPP Investments may use AI tools to help screen and assess applicants by analyzing resumes and applications for relevant skills and experience. These tools support, but do not replace, human decision-making.

#LI-ONSITE

About CPP Investments | Investissements RPC

Financial Services
1001-5000

CPP Investments is a professional investment management organization with a vital purpose: to help provide a foundation on which Canadians build financial security in retirement. To help maximize the CPP Fund for generations to come, we invest across all major asset classes: public equities, private equities, real estate, infrastructure and fixed income instruments.

Commenting Policy Keep It Clean: Comments that include offensive, abusive, defamatory, obscene or inappropriate content will be deleted. Keep It Courteous: We do not permit personal attacks. Posts that attack representatives, including our Social Media Manager or other commenters, will be deleted. Keep It on Topic: Posts not relevant to the topic, or others’ comments, will be deleted. Keep Personal Information Private: Our social pages are public. For your own safety, do not post your personal information – or someone else’s. Such posts will be deleted. Keep it Spam-Free: Posts assumed to be spam will be deleted. Keep It Legal: Posts referencing illegal activity or ongoing legal matters, financial matters or internal business decisions will be deleted. Keep It Within Rules: We adhere to this social network’s Terms of Use and Code of Conduct. All comments are subject to those rules.

Opinions expressed on these pages are those of their respective users only and do not necessarily reflect the views of CPP Investments, its management or employees. We are not responsible for the content of comments on this page, and disclaim any and all liability to the fullest extent permitted by law.

Employees of CPP Investments, affiliated companies, representatives, dealers or agents, please note: Members of our Social Media Management team will handle any factual corrections and answer any comments as appropriate questions here. You are welcome to join the conversation but please disclose your affiliation with CPP Investments.

Similar Jobs