Job descriptionPosition Purpose
Reporting to the Chief Information Officer, the incumbent is responsible for establishing and maintaining the institution’s vision, strategy, and program to ensure information assets and technologies are adequately protected. The role involves strategic leadership, risk management, stakeholder engagement, and fostering a strong security culture within the institution. The CISO recommends and oversees monitoring of computing practices to prevent and recover from security breaches and directs the handling of security incidents when breaches occur. Responsibilities
Strategic Leadership:
Develop and implement a comprehensive information security strategy that aligns with the institution's business goals and objectives; ensure security considerations are integrated into all aspects of operations and comply with relevant laws, regulations and policies. Risk Management:
Identify, assess and mitigate security risks at a strategic level; develop and implement IT risk management frameworks and ensure compliance with relevant regulations and standards. Stakeholder Engagement:
Engage with senior executives, board members, external institutions and partners to communicate security risks and strategies; liaise with provincial research network (ORION), national cybersecurity agencies (CanSSOC, CCCS), higher education consortia (CUCCIO, CANARIE), and peer institutions to share best practices and align the organization’s strategy to national priorities. Innovation and Emerging Threats:
Continuously monitor the threat landscape and evaluate new risks; prepare strategic action plans to respond to evolving threats. Security Culture and Awareness:
Foster a strong security culture; develop and implement security awareness programs and train employees, partners, students and collaborators on best practices. Collaboration and Coordination:
Coordinate with other institutions, faculties, services and teams to ensure security is integrated into all projects and initiatives; work closely with IT, legal counsel, privacy office, risk management office and other teams to incorporate security considerations. Qualifications
University degree or college diploma in Computer Science, Computer Engineering, or a related IT discipline. Certification in information security (e.g., CISSP, CISM, CISA) is an asset. Proven experience in planning, organizing, and developing IT security systems and technologies. Experience in developing and executing security policies and standards. 10 years of experience in IT security, including at least two years in a significant leadership role. Understanding of risk‑based approaches, regulatory and compliance issues. Track record in developing information security policies and procedures and successfully executing programs that meet excellence objectives. Business and technical acumen, leadership style, and organizational skills suitable for managing multiple concurrent projects. Capability to lead cross‑functional, interdisciplinary teams to achieve tactical and strategic goals. Knowledge of ISO 2700X, ITIL, COBIT/Risk IT, NIST, and relevant legal/regulatory requirements (SOX, HIPAA, PCI DSS). Excellent communication and interpersonal skills. Bilingual in French and English (spoken and written). EEO Statement
Prior to May 1, 2022, the University required all students, faculty, staff, and visitors (including contractors) to be fully vaccinated against Covid‑19 as defined in Policy 129 – Covid‑19 Vaccination. This policy was suspended effective May 1, 2022 but may be reinstated at any time. The University is an Equal Opportunity and Diversity Employer.
#J-18808-Ljbffr