Senior Manager, Information Security

About The Role As the Senior Manager, Information Security, you aren't just checking compliance boxes. You are the architect of FreshBooks' security compliance program, risk register, and governance processes.

In this planner-and-operator leadership role, you will hold real authority to shape our multi-year security roadmap and drive cross-functional execution across Engineering, IT, Product, and Legal.

You will serve as a trusted, analytical advisor on risk management, ensuring we scale securely by protecting our customers' data while strengthening the robust compliance frameworks that protect our users' trust. You view information security as a true business partner, employing your experience and creativity to enable FreshBooks' innovation in the most scalable, safest ways possible. This is an impactful role offering direct exposure to the Senior Leadership Team and Board as you safeguard our global operations.

Beyond the considerable impact of this role and the opportunity to truly shape one of our most fundamental programs, you believe in small business owners. You are motivated by FreshBooks' mission to make running a small service-based business easy, and have a strong desire to alleviate one of the stressors these business owners face.

Work location : This role can be worked remotely from within Canada.

Posting duration: To account for the Canada Day holiday 🇨🇦, we will accept applications until July 10 and will connect with successful applicants the following week. Thank you for your interest!

What You'll Do

  • Drive Strategy and Roadmap: Own FreshBooks’ multi-year security strategy and roadmap, running it with strict program discipline to prioritize initiatives based on business impact.
  • Lead Compliance and Risk: Oversee the PCI DSS and SOC 2 compliance programs to maintain clean attestations, while operating the enterprise risk register to guide remediation versus acceptance decisions.
  • Govern AI and Emerging Tech: Lead and formalize our cross-functional AI Governance Council, defining the review framework for cutting-edge AI use cases and reporting on compliance KPIs.
  • Optimize and Scale the Service Queue: Turn raw ticket data into strategic insights by designing a highly efficient operating model with strict SLAs, reading queue trends to proactively steer our security strategy.
  • Influence at the Board Level: Own the security metrics program from end-to-end, translating complex operational data into high-leverage, business-framed dashboards for our Senior Leadership Team and the Board.
  • Lead and Develop Talent: Manage, coach, and build the Information Security team while designing staffing plans that balance internal headcount with external specialists during peak audit cycles.
  • Steer Security Committees: Staff and lead the Security Steering Committee to drive critical organizational decisions regarding prioritization, resourcing, and policy approvals.
What You'll Bring
  • Craft Experience: 8+ years of experience in information security, with a strong focus on compliance, GRC, or security program management.
  • People Leadership: 3+ years of direct people management experience with a proven track record of developing talent and building cohesive teams.
  • Deep Compliance Audit Expertise: Hands-on experience successfully navigating and owning PCI DSS and SOC 2 Type II audit cycles.
  • Risk and Roadmap Management: Proven ability to operate an enterprise risk register and translate those risks into a prioritized Engineering and IT roadmap.
  • Program Discipline: Strong project and program management skills with a meticulous focus on driving accountability across Engineering, IT, Product, and Legal teams.
  • Resource and Vendor Management: Experience managing external specialists and consultants for point-in-time assessments or audit peak periods.
You'll Stand Out If You Have
  • Emerging Tech Fluency: Experience or a strong foundational grasp of managing AI governance frameworks and emerging technology risks.
  • Security Program Execution: Experience designing and executing incident response tabletop exercises alongside security awareness programs.
  • Professional Credentials: An active security certification (such as CISSP, CISM, CRISC, or equivalent) or an undergraduate degree in Computer Science, Cybersecurity, Business, or a related field.
Compensation At FreshBooks, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. The total compensation for this role ranges from CA$160,000 - CA$200,000 per year, which may include participation in our incentive programs. Additionally, this positi
Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...