Fispan

Lead, Information Security Strategy and Risk

Vancouver, British Columbia, CanadaFull timeLeadPosted about 15 hours ago
Apply on Fispan →

Sign in to see who you know at Fispan.

Our Business

FISPAN Services Inc. (FISPAN) is an Enterprise SaaS FinTech company that allows banks to deploy embedded financial products and services to create a seamless banking connection for their corporate clients. Our product aims to provide instant scale and reach for banks who want to remove friction and add value by enabling their commercial banking clients to access banking services through their preferred ERP / accounting platform.

Founded in 2016 and headquartered in downtown Vancouver, FISPAN is on a mission to create the best product in the FinTech industry and fundamentally change the way that companies bank. Being the market leader in ERP Banking, we work with the world’s Tier 1 banks with assets exceeding $3T, including J.P. Morgan Chase, Wells Fargo, TD and Bank of Montreal.

We are looking for dynamic and passionate individuals to join our high performance team and contribute to our rapid growth and exciting journey.

Role Summary

FISPAN is hiring a Lead, Information Security Strategy and Risk to help ensure security decisions, control designs, and technical changes are reviewed early and implemented with the right level of rigor. This role focuses on practical security architecture, design assurance, and risk reduction across product, engineering, infrastructure, and operational change.

You will partner closely with Engineering, Infrastructure, Product, GRC & Legal to review material technical decisions, assess security controls, and help teams move quickly without introducing avoidable risk. You will also lead key parts of FISPAN’s vulnerability management and penetration testing program, translating technical findings into clear remediation priorities and durable security improvements.

Key Responsibilities

Security Design & Risk Review

  • Lead security and risk reviews for material technology, infrastructure, integration, product, and operational changes.
  • Define security principles, control expectations, and risk guardrails across cloud, SaaS, data flows, identity, privileged access, and production environments.
  • Provide security-by-design guidance for new systems, internet-facing services, AI capabilities, shared platforms, and sensitive data integrations.
  • Support risk assessments, threat modeling, control reviews, and documented security decisions for significant initiatives.

Vulnerability Management & Security Testing

  • Own the vulnerability management strategy and governance process across applications, infrastructure, cloud services, and shared platforms.
  • Define risk-based severity, prioritization, remediation expectations, escalation, and exception handling.
  • Identify recurring vulnerability patterns and drive lasting control improvements and measurable risk reduction.
  • Provide oversight of high-severity vulnerabilities, external exposure, and emerging threats.

Security Strategy, Risk & Oversight

  • Develop and maintain security strategy and priorities aligned with business objectives, regulatory...