Vancouver’s security leadership divides almost evenly between two worlds. Three of the people below protect public institutions: two universities and the provincial housing agency, organizations with open networks, constrained budgets, and obligations to people who did not choose to be their users. Three more secure venture-backed software companies where the security program is a revenue lever, unblocking enterprise deals and passing investor diligence. The seventh advises across both. What unites them is a city small enough that its security community overlaps constantly, through ISACA Vancouver, the local CISO forums, and the universities that train the next intake.
Sunny Jassal – CISO, British Columbia Institute of Technology
Sunny Jassal has held three different senior technology roles at BCIT in under eight years. He joined as Director of Cyber Security in 2018, spent eighteen months as AVP Technology and Chief Information Officer reporting to the president, and has been CISO since April 2024, reporting to the VP of Finance and Administration and to the board’s risk committee. His twenty years include eleven at Doctors of BC, where he rose from IT systems specialist to Director of Information Technology for the provincial medical association, and earlier work as a PRIME-BC trainer and 911 operations staffer with the RCMP. He is president of the ISACA Vancouver chapter, one of North America’s largest, guest lectures at UBC’s Sauder School of Business, and previously sat on EC-Council’s advisory board supporting Canada’s first CISO Forum. He holds an MBA alongside CCISO, CISM, CDPSE, and SSCP.
Jastej Aujla – CISO, Simon Fraser University
Jastej Aujla came to higher education from the transit network. CISO of Simon Fraser University since June 2022, he brings more than twenty years in cyber security, risk management, and compliance. He spent nearly a decade at TransLink, the regional transportation authority, progressing from IT security advisor through manager and senior manager to Director of IT Security, Risk, Compliance and Resiliency, an operational environment where availability is not negotiable. Before Canada he worked as a security consultant at Paladion Networks and a security analyst at NII Consulting in India, conducting penetration testing and network analysis for national and international banks. His declared specialties run to CEH, CISA, ISO 27001, ISMS implementation, OWASP-based penetration testing, and threat modeling.
Daniel Owen – CISO, BC Housing
Daniel Owen has been CISO of BC Housing since March 2013, more than thirteen years defending the provincial agency responsible for social and affordable housing, and the data of the people who depend on it. He arrived from London Drugs, where he spent thirteen years as Corporate Data Security Officer, giving him a rare pairing of long-tenure retail security and long-tenure public sector security. His earlier work was in systems consulting and engineering at ITI International Technology Integration and Datacom Systems. Two roles across twenty-six years is an uncommon shape for a security career, and it means the BC Housing program has had one consistent owner through the entire modern threat era.
Mary Carmichael – Field CISO, Western Canada, Bell Cyber
Mary Carmichael does not come from a purely technical background, and she treats that as the point. A CPA alongside her CISA, CISM, and CRISC, she became Field CISO for Western Canada at Bell Cyber in May 2026, advising executives, CISOs, and boards on where organizations are exposed, which investments matter, and how to manage third-party, cloud, and AI risk. She previously spent seven years as Principal Director of Technology Risk and Transformation at Momentum Technology, and before that ran the project management office at Metro Vancouver with a $10 million annual budget, delivering an ERP and HCM program for more than 1,600 users. Her research work is current: as an AI and cybersecurity industry research fellow at Toronto Metropolitan University’s Rogers Cybersecure Catalyst, she is developing practical approaches to third-party AI risk and procurement governance. She contributes to ISACA globally as lead developer of version 5 of its IT Audit Framework and as a member of the CRISC certification committee, and has been recognised by SC Media, Security Magazine, and ISACA’s Global Chapter Leadership Award.
Catherine Mendonsa – VP and CISO, Mark Anthony Group
Catherine Mendonsa has built security program in some of the most heavily regulated environments in Canada. VP and CISO of Mark Anthony Group since January 2025, she brings more than twenty-five years spanning legal services, law enforcement, energy regulation, oil and gas, bulk electric systems, and municipal government. She was CISO and Director of Information Systems Security and Enterprise Architecture at Finning, the Caterpillar dealer, and before that spent four and a half years as Senior Director of Information Security at law firm Fasken. Her energy sector work includes risk management leadership at TC Energy, cyber security project management at transmission operator AltaLink, information governance and security at Cenovus, and five years leading enterprise security architecture at the Energy Resources Conservation Board. The foundation was nearly twelve years as IT Security Coordinator for the Calgary Police Service. She holds a 2025 WiCYS Lifetime Achievement Award and was named to Top 10 CISOs Canada in 2022.
Fabrice Renaud – CISO, Hiive
Fabrice Renaud has spent a decade building security programmes at Vancouver software companies. CISO of Hiive since March 2025, he arrived from GeoComply, where he served four years as CISO for the geolocation compliance firm, and before that spent nearly fourteen years at Galvanize, now part of Diligent. His progression there is unusual: he joined as a project manager in 2007, spent seven years in R&D program management, then moved into security as Director of Information Security and Compliance before taking on global IT as well. His compliance record includes SOC 2 Type 2 and FedRAMP Moderate. Earlier still he worked in localization at Electronic Arts and as a freelance translator, a background that shows in a career built on making technical requirements legible to the people who have to meet them.
Alexey Zhigaltsov – CISO, owl.co
Alexey Zhigaltsov built the platform before he was asked to secure it. One of the first hires at owl.co when the InsurTech company was at zero revenue, he served three and a half years as Chief Technology Officer, growing engineering from one person to eighteen and acting as technical co-founder voice through seed, Series A, and Series B rounds raising more than $30 million. He became CISO in August 2021 and stood up the security and GRC program from nothing, achieving SOC 2 Type II and HIPAA compliance for a platform handling regulated health and personal data for major insurance carriers. He now leads security for the company’s LLM-powered features, working with engineering and ML teams on input validation, output filtering, and prompt injection defenses, and owning the bias testing programme and AI security review process. He describes security at owl.co as a revenue lever, personally leading the enterprise security reviews that unblock carrier deals.
What This Group Says About Vancouver
Vancouver’s security bench is small, connected, and unusually institution-heavy for a city known for its startups. Several of these leaders built something from zero: a security program at a pre-revenue InsurTech, a cyber function at a technical institute, an AI risk practice that did not exist as a discipline three years ago. Others have stayed put for a decade or more, which is how a housing agency or a transit authority gets a security programme with continuity rather than a series of restarts. The two patterns coexist here more comfortably than in most cities, and the local chapters and forums are where they meet.
Vancouver is one stop in an ongoing series profiling the security leaders shaping their cities, provinces, and sectors; explore more Canadian features spanning education, industry, media, and emerging technology below.
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

