SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead, Information Security Strategy and Risk

FISPAN - Vancouver, BC, Canada - In-office - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

FISPAN is an Enterprise SaaS FinTech company that enables banks to deploy embedded financial products and services through corporate ERP and accounting platforms. Founded in 2016 and headquartered in Vancouver, FISPAN partners with Tier 1 banks including J.P. Morgan Chase, Wells Fargo, TD, and Bank of Montreal to fundamentally change how companies bank. This role leads information security strategy, risk management, and security architecture across the organization. You will partner closely with Engineering, Infrastructure, Product, GRC, and Legal teams to review material technical decisions, assess security controls, and enable teams to move quickly without introducing avoidable risk. Key responsibilities include: **Security Design & Risk Review**: Lead security and risk reviews for material technology, infrastructure, integration, product, and operational changes. Define security principles, control expectations, and risk guardrails across cloud, SaaS, data flows, identity, privileged access, and production environments. Provide security-by-design guidance for new systems, internet-facing services, AI capabilities, shared platforms, and sensitive data integrations. Support risk assessments, threat modeling, control reviews, and documented security decisions for significant initiatives. **Vulnerability Management & Security Testing**: Own the vulnerability management strategy and governance process across applications, infrastructure, cloud services, and shared platforms. Define risk-based severity, prioritization, remediation expectations, escalation, and exception handling. Identify recurring vulnerability patterns and drive lasting control improvements and measurable risk reduction. Provide oversight of high-severity vulnerabilities, external exposure, and emerging threats. **Security Strategy, Risk & Oversight**: Develop and maintain security strategy and priorities aligned with business objectives, regulatory obligations, and bank partner expectations. Identify material and emerging risks, recurring control weaknesses, and areas requiring broader security investment. Translate technical risks into clear business impact, priorities, and recommendations for leadership. Contribute to security governance, risk reporting, roadmap planning, and oversight of material exceptions and risk acceptances.

Similar roles