The threat surface here is sprawling. CAA Club Group is Canada's largest not-for-profit automobile association, serving over 2.5 million members across Ontario, Manitoba, and nationally. That means the security team is defending infrastructure that spans roadside assistance dispatch systems, travel booking platforms, insurance underwriting through CAA Insurance Company and Echelon Insurance (a specialty insurer), life and disability policies via CCG Advisory Services, and a member savings ecosystem - each with its own data flows, third-party integrations, and regulatory obligations under PIPEDA and provincial insurance legislation.
The attack vectors map to the business verticals: fleet telemetry and location data from roadside operations, PII-heavy claims and policy data across property, casualty, life, and travel insurance lines, and payment infrastructure tied to member benefits. With 115+ years of operating history, legacy systems are a given alongside modernization efforts - so the security posture has to bridge both. The organization's advocacy around member safety signals that data stewardship isn't an afterthought; it's core to the mission.
Roles here likely touch identity and access management across multiple business units, application security for customer-facing portals, cloud infrastructure hardening, and incident response scaled to an organization with national reach. If you're looking for breadth of domain - insurance regulation, automotive services, travel logistics - within a single security program, this is one of the more technically diverse environments in the Canadian market.





