Vice President, Cyber Security
About QuadReal Property Group
QuadReal Property Group is a global real estate investment, development and operating company headquartered in Vancouver, British Columbia. Its assets under management are $98.5 billion. From its foundation in Canada as a full-service real estate operating company, QuadReal has expanded its capabilities globally for investments in equity and debt in both the public and private markets. QuadReal invests directly through operating platforms in which it holds an ownership interest and via programmatic partnerships.
QuadReal seeks to deliver strong investment returns while creating sustainable environments that bring value to the people and communities it serves. Now and for generations to come.
QuadReal: Excellence lives here.
The Vice President, Cybersecurity is responsible for leading QuadReal’s enterprise cybersecurity program, ensuring the organization’s systems, data, users, and operating platforms remain secure, resilient, and aligned to business priorities. Reporting to the Chief Technology Officer (CTO) and working closely with business leaders, this senior leader will oversee cyber operations, risk management, governance, security architecture oversight, and regulatory compliance while continuing to mature QuadReal’s cybersecurity capabilities and operational discipline.
The role is focused on strengthening cyber operations, improving visibility and accountability across the security program, reducing enterprise risk, and ensuring security practices support business growth, acquisitions, and operational continuity.
Responsibilities
Defines, negotiates, and delivers all IT services related to enterprise cybersecurity, including cyber operations, security governance, identity and access management, endpoint security, cloud security, network security, operational technology security, and third-party risk management
Leads the ongoing evolution of QuadReal’s cybersecurity strategy, operating model, roadmap, and controls framework aligned to enterprise priorities and risk tolerance
Oversees enterprise cyber operations including threat detection, incident response, vulnerability management, security monitoring, and remediation activities
Ensures security standards, policies, controls, and governance practices are consistently applied across enterprise systems, operating platforms, acquisitions, and third-party environments
Acts as the primary cybersecurity liaison between IT, business stakeholders, executive leadership, auditors, and external partners
Partners closely with Infrastructure, Enterprise Solutions, ED&A, AI & Digital Innovation, Legal, and Risk teams to ensure cybersecurity practices are embedded into operational and project delivery activities
Enhances third-party vendor and partner relationship ecosystem, including sourcing and negotiating security-related services, managing vendor performance, and ensuring vendors meet QuadReal’s security and compliance expectations
Oversees security risk assessments, audits, penetration testing, and compliance activities across the enterprise
Manages the resolution of escalated cybersecurity incidents and operational issues
Develops cybersecurity capital and operating budgets and ensures adherence to approved budgets
Establishes and maintains clear operational metrics, reporting, and governance cadence related to cybersecurity risk, controls, incidents, vulnerabilities, and remediation progress
Creates and fosters a security-conscious and customer-focused culture across all cybersecurity interactions
Acts as a mentor and coach to the Cybersecurity team and guides the development of both technical and leadership capabilities within the team
Promotes effective teamwork and manages the resolution of interpersonal issues
Ensures the Cybersecurity team, including extended delivery vendors and partners, have clearly defined roles, responsibilities, accountabilities, and documented performance expectations
Experience and Qualifications:
Bachelor’s degree in information technology, engineering, cybersecurity, or directly related specialized training and equivalent work experience
Minimum of 10 years of relevant cybersecurity experience across enterprise security operations, cyber risk management, governance, and security controls
Minimum of 5 years in management roles showing steady progression through leadership levels
Experience leading enterprise cybersecurity programs within complex, multi-platform environments
Strong understanding of cybersecurity operations, security governance, identity and access management, cloud security, endpoint security, network security, vulnerability management, and incident response
Demonstrated ability to build strong relationships and effectively communicate across all levels of an organization
Strong understanding of the real estate business and related operational and investment processes across multiple asset classes considered an asset
Knowledge of regulated environments and audits (PCI, SOC, PIPEDA, GDPR) considered an asset
Experience supporting acquisitions, operating company integrations, and third-party vendor environments considered an asset
Top Skills Necessary
Executive Leadership – 5+ years’ experience in a senior leadership role (Director, AVP, or VP level)
Team Leadership – Experience leading enterprise cybersecurity teams, including operational leadership, mentorship, organizational alignment, onboarding/offboarding, and performance management
Cybersecurity Operations Experience – Demonstrated experience leading enterprise cybersecurity operations including incident response, vulnerability management, identity and access management, endpoint security, cloud security, and operational resilience
Cybersecurity Program Leadership – Experience leading large-scale cybersecurity initiatives (e.g., IAM, DLP, SSO, MDM/EMM, SOC modernization, cloud security, zero trust initiatives), including governance, operationalization, and enterprise adoption
Risk & Governance – Strong understanding of enterprise risk management, regulatory compliance, audit readiness, security controls, and governance practices
Business & Stakeholder Engagement – Ability to translate cybersecurity risks and operational priorities into practical business discussions and executive decision-making
Based on the position, QuadReal offers a competitive total rewards package in addition to the base pay, which may include a performance-based incentive plan, comprehensive health & dental benefits, pension plan, and paid time off.
The actual salary offered will take into consideration a wide array of factors including, but not limited to, the individual’s skill, experience, education and training, the market compensation of the role, and the consideration to internal equity.
We value diverse experiences and perspectives. Even if your skills don’t align 100% with the listed qualifications or salary range, we encourage you to apply – you may be a great fit for this role or others in our community. Applicants may also be considered for alternative positions within the organization where their qualifications and experience align more closely with available opportunities.
We use artificial intelligence (AI) technology — alongside human review — to assist in screening and assessing applicants for this position. Our recruitment team remains involved in all decisions.
Note to Recruiters: QuadReal does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to QuadReal, directly or indirectly, will be considered QuadReal property. QuadReal will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for engaged services to submit resumes.
QuadReal Property Group will provide reasonable accommodation at any time throughout the hiring process for applicants with disabilities or for those needing job postings in an alternate format. If you require accommodation, please advise the Talent Acquisition team member you are working with and include the following: Job posting #, your name and your preferred method of contact.
This job posting is for an existing vacancy role within our organization.
#LI-JC1