Cyber Security Architect
Cynet Systems
Toronto, ON
$74 an hour (estimated)
Full-time
Job Description :
- Contributing to a tailored cyber security framework that is based primarily on NIST Cybersecurity Framework (CSF) v2, with considerations from other industry frameworks and standards such as SANS / CIS Controls v8, COBIT, ISO, etc.
- Developing standards for priority cyber security, privacy protection and online safety controls applicable to K-12, including documented guidance.
- Providing hands-on subject matter expertise and guidance to support adoption of framework, standards and policy(ies).
- Ensuring alignment with modern security operation (SecOps) practices leveraging automation, artificial intelligence, and machine learning.
- Collaborating with other parts of the government (e.g., Cyber Security Division) to consider linkages with Client and BPS cyber security priorities and standards, and alignment with other workstreams of the cyber protection strategy such as cyber security and privacy assessments to identify linkages and interconnections and facilitate alignment.
- Presenting to various stakeholders to seek feedback, as needed.
- Delivering on other duties as assigned.
- Providing progress and project status reports on all deliverables assigned.
- This work involves working in close partnership with various government departments and the K-12 education sector.
- The manager may assign school board-related work for other initiatives, as needed.
Experience and Skill Set Requirements :
- Cyber Security and Privacy 60%
- 5+ years’ experience mapping and adapting cyber security frameworks such as NIST Cybersecurity Framework (CSF) v2, COBIT, CIS Controls v8 and ISO 27001 for adoption by an organization comparable in size and complexity to a school board.
- 5+ years’ experience integrating and implementing cyber security frameworks, and cyber security controls into an organization’s enterprise risk management practice, governance and overall organization including associated change management practices.
- 5+ years’ experience performing security analysis, developing and implementing cyber security and online privacy policies, standards and guidelines, preferably for the public sector or broader public sector.
- Demonstrated experience applying privacy frameworks such as the NIST Privacy Framework v1.1 and ISO / IEC 27701 is highly desirable.
- Demonstrated experience performing cyber / online safety analysis, developing and implementing cyber safety policies, standards and guidelines is highly desirable.
- Experience with the adoption of capability maturity models such as Capability Maturity Model Integration (CMMI) and Cybersecurity Maturity Model Certification (CMMC) is desirable.
- Excellent knowledge of applicable legislation such as Municipal Freedom of Information and Protection of Privacy Act (MFIPPA).
Knowledge of the Education Act is desirable.
Excellent knowledge and exposure to Internet of Things (IoT) or Operational Technology (OT) security issues is desirable.
Communication Skills and Experience 20% :
- 10+ years’ experience in effectively presenting to senior management and management teams and external stakeholders.
- 10+ years’ experience in preparing written materials (e.g., security and privacy reports, status reports, recommendations, briefing notes) for practitioners and management levels.
Industry Certifications / Relevant Degrees 15% :
- Security certification is mandatory (Certified Information Systems Security. Professional (CISSP) or Certified Information Security Manager (CISM)).
- Privacy certification (Certified Information Privacy Professional (CIPP)) is desirable
- Other certifications CISA, CASP+.
Public Sector Experience 5% :
- 5+ years’ hands-on experience working with large public sector environments, preferably with K-12 school boards.
- The security standards (GO-ITS 25.X) can be found on the information technology standards website :
Industry Certifications / Relevant Degrees 15% :
- Security certification is mandatory (Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM)).
3 days ago