Date Posted: 08/31/2026
Req ID:50031
Faculty/Division: Faculty of Arts & Science
Department: Citizen Lab
Campus: St. George (Downtown Toronto)
Existing Vacancy: Yes
Description:
About Us:
The Faculty of Arts & Science is the heart of Canada’s leading university and one of the most comprehensive and diverse academic divisions in the world. The strength of Arts & Science derives from our combined teaching and research excellence in the humanities, sciences and social sciences across 29 departments, seven colleges and 46 interdisciplinary centres, institutes and programs.
We can only realize our mission with the dedication and excellence of engaged staff and faculty. The diversity of opportunities and perspectives within the Faculty reflect the local and global landscape and the need for curiosity, innovative thinking and collaboration. At Arts & Science, we take pride in our legacy of innovation and discovery that has changed the way we think about the world.
The Citizen Lab is an interdisciplinary laboratory based at the Munk School of Global Affairs & Public Policy, University of Toronto, focusing on research, development, and high-level strategic policy and legal engagement at the intersection of information and communication technologies, human rights, and global security. The Lab uses a “mixed methods” approach to research combining practices from political science, law, computer science, and area studies. Our research includes investigating digital espionage against civil society, documenting Internet filtering and other technologies and practices that impact freedom of expression online, analyzing privacy, security, and information controls of popular applications, and examining transparency and accountability mechanisms relevant to the relationship between corporations and state agencies regarding personal data and other surveillance activities.
Your opportunity:
Reporting to the Director of Administration, Citizen Lab and working under the general direction of the Information Security Program Manager, Citizen Lab in coordination with the University of Toronto’s Chief Information Security & Digital Trust Officer (CISDTO), the Systems and Security Technical Lead is responsible for working with Information Technology staff and resources at Citizen Lab and the wider University to minimize risk of the compromising of information, data, servers, and server-based applications. The System and Security Technical lead provides technical leadership and supervision to assigned staff, including work assignment, coaching, performance management and staff development activities. Work is done in the context of existing policy, guidelines and applicable legislation in a fluid, consultative environment.
The Systems and Security Technical Lead assumes responsibility for the strategic and tactical planning and provision of systems security, confidentiality, privacy and risk management in the areas of systems administration, server and service design, implementation, operation and support. The Systems and Security Technical Lead is responsible for developing, updating, implementing, promoting and training the community on the Citizen Lab’s Information Security and Risk Management Program. The Systems and Security Technical Lead is instrumental in ensuring reliable and robust access controls, service availability, and activity/incident reporting. The Systems and Security Technical Lead applies known security standards as well as establishes new security standards and best practices related to the use and operation of information technology solutions, systems, servers, network services solutions and proposes strategies by which those standards and best practices are implemented, tested and confirmed on a regular basis.
Working closely with Information Security Program Manager, the Systems and Security Technical Lead works to support threat detection, containment, eradication, and forensic investigations of IT systems and services where access control mechanisms have been compromised or circumvented. This role is responsible for conducting detective audits of Citizen Lab Systems Administrators and other privileged accounts across all Citizen Lab systems and servers, proactively monitoring security threats, and ensuring that the Lab's systems, servers, and computing environments remain secure, resilient, and protected against unauthorized access. Attention to detail, procedural discipline, and a strong understanding of security standards are essential for this role, as errors may have a severe impact, including loss, corruption or unauthorized disclosure of mission-critical and highly-confidential research data and the threat or compromise to the physical and mental well-being of those affiliated with the Lab, up to and including loss of liberty of life.
The Systems and Security Technical Lead acts as a project manager for IT projects that fall within areas related to Information Security or projects, which include confidential and restricted information following the security standards and best practices for Identity and Access Management, Information Disclosure, Information Integrity, Business Continuity and Protection of Privacy.
The Systems and Security Technical Lead reviews the performance of security controls, and effectiveness of projects to achieve the security goals of Citizen Lab, in the context of the University. The Systems and Security Technical Lead is also responsible for the initiation, specification and assessment of a wide variety of contracts covering information security related hardware, software, support and services. The Systems and Security Technical Lead tables proposals to augment and/or improve services delivered and participates in reviewing proposals from others, using in-depth technical expertise and a teamwork approach to organizational issues in daily day-to-day developments and in tactical and strategic planning efforts.
Essential Qualifications:
EDUCATION:
University degree in a relevant field, (e.g. Computer Science, Engineering), or equivalent combination of education and experience.
EXPERIENCE:
- Six (6) years working in an Information Technology environment, including at least two years working with Information Security as a significant focus of activity.
- Requires broad and in-depth knowledge of industry innovations and state-of-the-art technology in both computing and networking arenas.
- IT Security certifications held or in progress is an asset. High-performance computing systems management and networking is highly desirable.
- Expert understanding of client and server application deployment and support. Strong understanding of client and server activity tracking.
- Strong understanding of IT Architecture, IT Operations and security methodologies (e.g., zero knowledge architecture, defense in depth, ITIL).
- Experience auditing systems for regulatory compliance.
- Experience drafting, interpreting, applying and adapting information security standards and guidelines, assessing risk management and determining controls.
- Experience in administering enterprise-level Linux-based server applications.
- Strong scripting skills required including Shell and interpreted languages.
- Experience with automation/orchestration/scripting tools (e.g., bash, Python, Ansible, MDM).
- Experience with web application management, security and monitoring (e.g., WordPress).
- Experience with cloud collaboration SaaS platform management and administration (e.g., Google Workspace, enterprise secure messaging, client-side/zero knowledge encrypted storage and SaaS apps).
- Experience configuring databases and database-backed applications (e.g., PostgreSQL, MySQL). Extensive experience using network and security analysis tools.
- Extensive experience with intrusion detection and prevention – host and network, active and passive. Experience in selecting, configuring and deploying service mis-use detection and prevention technologies (e.g, Anti-Spam, XDR/EDR,Anti-DDOS, etc.).
- Experience running penetration testing and vulnerability scanning (Metasploit, Nessus, etc.).
- Experience with deploying, configuring and securing virtualized environments, and services running in it.
SKILLS:
- Expert level understanding of the Linux operating systems at both server and client level.
- Comprehensive knowledge of TCP/IP networking and client-server architecture and protocols.
- Strong understanding of network configuration, hardware and next-gen firewall/IPS technologies (Cisco ASA, Juniper, Fortinet, Palo Alto)
- Expert level understanding of the following access control technologies, LDAP, Kerberos, OAuth/OpenID, Shibboleth/SAML.
- Expert knowledge of Virtual Private Networks (VPNs).
- Expert knowledge of symmetric, asymmetric and post-quantum encryption technologies at network, file and file-system levels.
- Strong understanding of cryptographic certificates and the operation of certificate authorities.
- Excellent communication, instruction and presentation skills.
- Able to describe a variety of complex technical concepts or policies to users and senior leadership at all technical experience levels and to deliver security awareness and education content to faculty, staff and students.
OTHER:
- Ability to work under pressure of high volume and expectations, while meeting multiple deadlines for multiple projects;
- strong service orientation coupled with ability to recognize and assess the operational significance of a problem, control/mitigate the risk and set priorities accordingly.
- Strong ability to assess risks and controls of computing systems and operations.
- Demonstrated broad knowledge of information technology, network technologies, databases and application development.
- Strong ability and willingness to work effectively as a team leader and team member; must be able to collaborate and cooperate with team members, project sponsors, other stakeholders.
- Ability to lead team members of varying levels and skills. Must be able to deal calmly and effectively with a variety of people.
- Demonstrated ability to exercise sound judgment, tact and diplomacy.
- Ability to effectively navigate a professional and political climate including assessing the requirement to escalate an issue to more senior levels of management or resources; ability to maintain a high level of confidentiality.
- Ability and willingness to learn new systems, technologies and project management methods and tools.
Closing Date: 09/14/2026,11:59PM ET
Employee Group: Salaried
Personnel Subarea:PM
Appointment Type: Grant - Continuing
Schedule: Full-Time
Pay Scale Group & Hiring Zone: PM 3 -- Hiring Zone: $93,592 - $109,190 -- Broadband Salary Range: $93,592 - $155,985
Job Category: Information Technology (IT)