Sylogist
Director of Information Security
Job Summary
The role involves developing and overseeing security protocols, compliance programs, and risk management strategies, with a focus on cloud infrastructure, network security, and privacy standards. The candidate should have extensive experience in information security, cloud management, and relevant certifications like CISSP or Azure Security certifications. Responsibilities include incident response, vulnerability assessments, implementing identity and access controls, and managing vendor and cloud risk. The position emphasizes strategic planning, compliance, and collaboration with technical teams to ensure security and privacy across the organization.
Required Skills
Benefits
Job Description
Company Overview
At Sylogist, we are purpose-driven to “empower the good our customers do.”
We provide SaaS-based software solutions to the non-profit, government, and education sectors, and we take immense pride in the work of our customers and the products we build to support them. Our team is collaborative, enthusiastic and delivers on our promises. If you want to apply your skills to improve trusted technology that supports over 2000 customers around the world, then let’s talk!
Position Overview:
Reporting to the Chief Information & Technology Officer (CITO), the Director, Information Security will be responsible for developing, implementing, and overseeing security protocols, compliance programs, and risk management strategies across Sylogist. The successful candidate will bring a strong background in cloud infrastructure management, compliance frameworks, and strategic security planning.
Responsibilities Include:
- Enhance security team accomplishments and competencies by planning the delivery of solutions and responding to technical RFPs and miscellaneous questions.
- Define security protocols by evaluating business strategies and requirements.
- Develop, review, and approve installation requirements for LANs, WANs, VPNs, firewalls, routers, and related network devices.
- Execute corporate identity and access control by implementing Azure AD solutions, MFA, and Privileged Access Management (PAM).
- Respond to and investigate security incidents, providing thorough post-event analysis.
- Manage secure phishing programs and ensure compliance through tools and ongoing training.
- Develop and maintain a corporate security roadmap to include ongoing system upgrades.
- Conduct vulnerability scans, penetration tests, and incident response drills.
- Verify security systems by developing and implementing test scripts.
- Stay current on emerging security practices and standards; participate in educational opportunities, review professional publications, and engage in professional organizations.
- Partner with DevOps and architectural teams on security best practices.
- Document and review corporate policies to ensure compliance with NIST and other industry standards.
- Review and ensure product compliance with privacy requirements (GDPR, CCPA, PIPEDA, and global privacy laws).
- Implement data classification, encryption (at rest/in transit), and DLP solutions.
- Develop, implement, and document disaster recovery and business continuity plans.
- Conduct Privacy Impact Assessments (PIAs) for new systems and data flows.
- Conduct quarterly security workshops on emerging threats (e.g., ransomware, social engineering).
- Maintain training records for compliance audits (SOC 2, ISO 27001).
- Vendor & Cloud Risk:
- Manage third-party risk assessments (including Microsoft Azure environments).
- Monitor compliance of SaaS vendors.
What We Look for in You
Must Haves
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 5+ years of experience in information security.
- Cloud infrastructure management experience.
- Certifications such as CISSP, CISM, Azure Solutions Architect Expert, Azure Security Architect Expert, or CCSP (preferred).
- Proficiency in Azure IaaS/PaaS, IaC (Terraform/Bicep), and SIEM tools.
- Deep knowledge of GDPR, SOC 2, NIST CSF, and PCI DSS.
- Experience managing global compliance programs.
- Strategic planning, vendor negotiation, and crisis management skills.
- Strong working knowledge of IT risks, cybersecurity, and operating systems.
- Excellent communication and interpersonal skills.
Nice-to-Haves
- Microsoft Azure security certification.
- Additional advanced security or cloud certifications.
- Experience with privacy compliance programs across multiple jurisdictions.
Why Join Sylogist?
We're an inclusive company that values the personal and professional growth of its employees! At Sylogist, you'll experience:
- A company where you can really make a meaningful impact
- A healthy work-life balance
- Benefits that cover health, wealth, and wellness
- Sylogist is a remote-first company.
Sylogist does not offer sponsorships. All candidates must provide proper employment documentation showing immediate eligibility to work in the country in which the role is based.
Sylogist
Sylogist is the most trusted provider of software for nonprofits and the public sector, built on Microsoft Dynamics 365 to modernize finance, fundraising and administration. Products include: ERP, CRM, payroll, grant and award management, victim notification and case management, business portals and payment processing.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.