AVP, Information Security
Vancouver, British Columbia, Canada
Benevity
Benevity's corporate purpose software offers the only integrated suite of community investment, employee, customer and nonprofit engagement solutions.Meet Benevity
Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!
We’re looking for an experienced and strategic Associate Vice President (AVP) of Information Security to lead and grow our security program. Reporting to the Chief Information and Security Officer (CISO), the AVP will oversee key areas including Security Operations, Product and Application Security, Governance, Risk & Compliance (GRC), Fraud Operations, and Security Training & Awareness.
In this high-impact role, you'll manage a team of security professionals and collaborate closely with Product, Engineering, Legal, Client Success, Finance, and other teams to ensure security is integrated across everything we do. As a key ambassador for trust at Benevity, you’ll help safeguard our clients, users, and data while reinforcing our commitment to privacy, protection, and operational excellence.
What you’ll do:
- Define and lead Benevity’s security strategy, ensuring alignment with business objectives, client needs, and regulatory requirements
- Oversee daily security operations, including incident response, threat detection, and vulnerability management
- Embed security best practices into the software development lifecycle in close partnership with Engineering and Product teams
- Lead fraud prevention and detection efforts to safeguard the integrity of the non-profit ecosystem and ensure secure, traceable fund movements
- Manage a comprehensive GRC program covering enterprise risk, privacy, financial reporting, charitable disbursements, AML, sanctions, and regulatory compliance
- Ensure compliance with industry standards and frameworks such as SOC 2, ISO 27001, and GDPR
- Foster a security-first culture through impactful training and awareness programs across the organization
- Act as a trusted advisor to clients and internal stakeholders, ensuring transparent communication about security practices and performance
- Lead, support, and develop a high-performing, inclusive security team focused on growth and continuous learning
- Collaborate across departments to embed security and fraud prevention into product development, operations, and client engagement
- Deliver regular updates on security posture to the CISO, executive leadership, and Board of Directors
What you’ll bring:
- Proven experience (10+ years) in Information Security leadership roles, with direct accountability for security operations, product security, compliance, and fraud management.
- Experience leading and scaling security programs in a SaaS, fintech, or regulated environment.
- Deep understanding of security frameworks, standards, and regulations (e.g., SOC 2, ISO 27001, NIST, GDPR, AML, CCPA).
- Strong technical acumen across cybersecurity domains, with the ability to balance strategic oversight and technical depth.
- Demonstrated success in building high-performing teams and fostering inclusive, collaborative environments.
- Exceptional communication skills, with the ability to translate complex security topics into clear, actionable insights for technical and non-technical audiences.
- A strong commitment to cultivating trust with clients, customers, and partners.
- Bachelor’s degree in Computer Science, Information Security, or a related field; relevant certifications (CISSP, CISM, CISA, etc.) are an asset.
Discover your purpose at work
We’re not employees, we’re Benevity-ites. From all locations, backgrounds and walks of life, who deserve more …
Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose.
If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become …
It’s time to join Benevity. We’re so excited to meet you.
Where we work
At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there’s no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.
Join a company where DEIB isn’t a buzzword
Diversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams.
We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine.
That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.
Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to accommodations@benevity.com.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security CCPA CISA CISM CISO CISSP Compliance Computer Science Finance FinTech GDPR Governance Incident response ISO 27001 NIST Privacy Product security SaaS SDLC Security strategy SOC SOC 2 Strategy Threat detection Vulnerability management
Perks/benefits: Career development Flex hours Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.