Head of Cybersecurity & Compliance
Village Farms International Inc. · Lake Mary, FL · 1 wk ago
Information TechnologyFull-time
What You'll Do
- Lead Cybersecurity Strategy & Governance
- Develop and execute the enterprise cybersecurity and compliance strategy, ensuring alignment with business objectives, growth initiatives, and evolving risk landscapes.
- Led the enterprise cyber risk management program by identifying, assessing, prioritizing, mitigating, and monitoring cybersecurity risks across the organization.
- Establish, maintain, and continuously improve the organization's information security program to safeguard the confidentiality, integrity, and availability of systems and data.
- Communicate cybersecurity risks, mitigation strategies, and program performance to executive leadership and the Board, providing meaningful governance reporting and strategic recommendations.
- Drive Security Operations & Compliance Excellence
- Oversee enterprise information security, IT compliance, and governance programs, ensuring effective security controls and regulatory compliance.
- Develop, implement, and enforce information security policies, standards, and procedures while driving adoption across business and technology teams.
- Lead security architecture and security-by-design initiatives, ensuring robust cloud, network, application, and data protection controls.
- Direct enterprise incident response activities, coordinating investigations and recovery efforts with IT, Legal, Privacy, Communications, and external partners.
- Strengthen Risk Management & Organizational Readiness
- Lead third-party risk management by evaluating vendor security, establishing contractual security requirements, monitoring compliance, and driving remediation activities.
- Oversee internal and external audits, regulatory examinations, and customer security assessments, ensuring timely resolution of findings and continuous improvement.
- Serve as the executive owner of Governance, Risk, and Compliance (GRC) platforms, optimizing automation, reporting, and workflow integration.
- Champion enterprise-wide security awareness and compliance training initiatives while staying ahead of emerging cyber threats, technologies, and regulatory developments to continuously strengthen the organization's security posture.
What You Bring
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field; a Master's degree or MBA is considered an asset.
- 10–15+ years of progressive leadership experience in cybersecurity, information security, risk management, IT audit, or a related discipline.
- Demonstrated expertise implementing and leading enterprise security, governance, and risk management frameworks within complex cloud, hybrid, or enterprise environments.
- Strong understanding of information security governance, cyber risk management, security architecture, incident response, third-party risk management, and regulatory compliance.
- Knowledge of global privacy and data protection regulations, including GDPR, CCPA, and related compliance requirements.
- Experience leading enterprise audits, regulatory assessments, and governance reporting for executive leadership and Boards.
- Professional certifications such as CISSP are strongly preferred.
- Additional certifications including CISM, CISA, CRISC, or equivalent are considered an asset.
- A collaborative leader who demonstrates sound judgment, strategic thinking, accountability, and a commitment to protecting the organization while enabling business success.