Talent.com
University of British Columbia
Associate Director, Cybersecurity Governance, Risk & ComplianceUniversity of British Columbia • Vancouver, British Columbia, Canada
Associate Director, Cybersecurity Governance, Risk & Compliance

Associate Director, Cybersecurity Governance, Risk & Compliance

University of British Columbia • Vancouver, British Columbia, Canada
21 days ago
Salary
CA$205.00 daily
Job type
  • Full-time
Job description
Staff - Non Union

Job Category

M&P - Excluded M&P

Job Profile

XMP - Information Systems & Technology Level G

Job Title

Associate Director Cybersecurity Governance Risk & Compliance

Department

OCIO Chief Information Security Office

Compensation Range

$13137.75 - $20502.83 CAD Monthly

The Compensation Range is the span between the minimum and maximum base salary for a position. The midpoint of the range is approximately halfway between the minimum and the maximum and represents an employee that possesses full job knowledge qualifications and experience for the the normal course employees will be hired transferred or promoted between the minimum and midpoint of the salary range for a job.

Posting End Date

July 26 2026

Note: Applications will be accepted until 11:59 PM on the Posting End Date.

This position is subject to the satisfactory completion of required background checks

Job End Date

Ongoing

This position is subject to the satisfactory completion of required background checks.

At UBC we believe that attracting and sustaining a diverse workforce is key to the successful pursuit of excellence in research innovation and learning for all faculty staff and students. Our commitment to employment equity helps achieve inclusion and fairness brings rich diversity to UBC as a workplace and creates the necessary conditions for a rewarding career.


At UBC we believe that attracting and sustaining a diverse workforce is key to the successful pursuit of excellence in research innovation and learning for all faculty staff and students. Our commitment to employment equity helps achieve inclusion and fairness brings rich diversity to UBC as a workplace and creates the necessary conditions for a rewarding career.


JOB SUMMARY


The Associate Director Cybersecurity Governance Risk and Compliance oversees the portfolio of services delivered as part of the Compliance and Risk Assessment team of the UBC Privacy & Information Security Management (PrISM) initiative. The function reports directly to the Chief Information Security Officer (CISO) and to the Executive Director Safety and Risk Services and ensures cybersecurity risks are understood and communicated to institutional leadership in collaboration with the leaders within the CIO & CISOs portfolio and those of the Enterprise Risk Management team. The role establishes and sustains second-line risk management processes and leads the Risk and Compliance team in optimizing risk assessment practices and improving institutional visibility of cybersecurity and privacy related risks as well as training and compliance.

The Associate Director is responsible for overseeing the activities related to assessing and reporting on compliance with Policy SC 14 and the associated Rules identifying risks and gaps prioritizing the risks and maintaining an institutional IT risk register for communicating these risks to the appropriate governance bodies. The register will support the CIO and CISO in establishing the annual activities for the CISO team and the broader UBC IT and distributed IT units. The Associate Director will support the Enterprise Risk Management team in reporting on key risks to the Executive and the Board.

The Associate Director is responsible for assessing the priority of the risks and recommending ownership for cybersecurity and privacy related risks including external risks related to third party suppliers and emerging risks such as digital resilience and AI assisted attacks.

The compliance reports and the risk register will provide the CIO and Executive Leadership with a structured view of risk exposures across the University to inform future initiatives priorities and subsequent investments.

The Associate Director and their team provides compliance advisory services pertaining to the standards set out in Policy SC 14 and associated Rules as well as supporting the Office of University Counsel by managing the Privacy Impact Assessment process under the guidance of the Legal Counsel responsible for Privacy while supporting the institutions capacity to innovate responsibly. The function provides independent risk insight and advisory services related to the impact of technology.

The Privacy and Information Security Management Risk and Compliance team delivers risk and compliance services in established areas such as Privacy Impact Assessments Security Threat Risk Assessments Information Security Compliance awareness and training. While progressively expanding their knowledge of or integrating with (as appropriate and subject to the decision of the CIO and advice of Enterprise Risk and Assurance) additional priority domains including artificial intelligence and supply chain risk. Through coordinated intake assessment and advisory services the function improves process efficiency while strengthening the institutions understanding of technology-related risk.

The function provides advisory risk analysis investigation and compliance services spanning major technology transformation initiatives emerging technology domains and key operational areas as agreed thorough agreement between Enterprise Risk and Assurance and the CIO.

Working closely with Enterprise Risk and Assurance the CIO portfolio Cybersecurity Enterprise Data Governance Architecture University Counsel and key service units the function supports the consistent application of risk-informed practices across UBC operations. These activities help embed proportionate risk and compliance practices aligned with institutional priorities and informed by the evolving technology risk register.

ORGANIZATIONAL STATUS


The Associate Director has a dual reporting relationship to the Chief Information Security Officer (CISO) and to the Executive Director Safety and Risk role works closely with Enterprise Risk and Assurance to integrate technology risk insights into the Institutional Risk Register and enterprise risk governance processes and with the CIO portfolio to ensure technology risk insights support institutional technology strategy and decision-making.

The Associate Director collaborates extensively with Cybersecurity teams the CIOs portfolio in areas such as Enterprise Architecture Enterprise Data Governance Enterprise Digital Transformation and other areas within Legal Counsel Records Management Access and Privacy Procurement and other teams and governance functions across the University. The role interacts with senior leadership project sponsors operational teams and governance committees to ensure technology risk considerations are clearly understood and effectively addressed.


WORK PERFORMED

Technology Risk Governance


  • Leads the teams responsible for identifying interpreting and communicating privacy and information security related risks across the University.
  • Develops and maintains the practices and processes to identify and address significant privacy and information security risks relating to UBC electronic information and systems.
  • Leads the development of a risk register aligned with Enterprise Risk Management processes. Translate operational technology risk information into clear institutional insights for the CIO and executive leadership and governance bodies as appropriate.
  • Provide strategic risk advice to leadership regarding institutional exposure to technology risks including cybersecurity system resilience thirdparty dependencies and emerging technologies as they relate to privacy and information security

Technology Risk Assessment and Advisory

  • Oversees the enterprise Privacy Impact and Security Threat Risk Assessment services ensuring the processes and practices are continually streamlined and improved.
  • Provides privacy and cybersecurity risk advisory services and methodologies to complex digital initiatives technology-enabled transformation programs and major institutional technology investments. Supports Enterprise Risk and Assurance in leading thematic technology risk reviews.
  • Provide advisory services under the direction of the CIO and Enterprise Risk and Assurance in assessing risks associated with emerging technologies including artificial intelligence advanced analytics and digital platforms as they relate to privacy and information security.
  • Leads the activities related to the development of institutional responses to technology related risk where mitigation requires a coordinated response beyond the scope of Information technology (e.g. supply chain).

Compliance and Governance

  • Direct the Information Security Compliance Support Program and related riskbased compliance initiatives.
  • Ensure technology risk and compliance activities remain aligned with institutional policy frameworks risk appetite and evolving regulatory expectations.
  • Leads the development of governance processes and practices at the local level with Faculties and Amin Units to ensure IT risk assessment and management processes remain efficient consistent and supportive operational and project delivery across the university.
  • Participate in the development of UBC-wide rules pertaining to the Use Management and Security of UBC Electronic Information and Systems.

Leadership and Organizational Development


  • Lead and mentor a multidisciplinary team delivering technology risk and compliance services. Foster collaboration across governance risk and technology communities to strengthen institutional decision-making.

CONSEQUENCE OF ERROR


This role is critical to ensuring that the University understands the gaps and resulting exposure associated with the management of information technology. Failure to effectively identify interpret or communicate technology-related risks will result in privacy or cybersecurity breaches expose the University to significant operational disruption cybersecurity incidents regulatory non-compliance financial loss or reputational damage. Sound judgment and strong governance leadership are required to ensure risks are appropriately understood and addressed.

SUPERVISION RECEIVED


Works independently under the direction of the Executive Director Safety and Risk Services (SRS) and the Chief Information Security Officer with close interaction with the Associate Vice President & Chief Information Officer and Chief Enterprise Risk and Assurance Officer.

SUPERVISION GIVEN


The Director will direct mentor and supervise a multidisciplinary team of privacy and information security analysts/advisors. May occasionally supervise and direct contract workers or students.


MINIMUM QUALIFICATIONS


Masters degree in a relevant discipline. Minimum of eleven years of related experience including at least five years of managerial experience plus four years of specialized experience in the design and implementation of major computer systems or the equivalent combination of education and experience.


- Willingness to respect diverse perspectives including perspectives in conflict with ones own
- Demonstrates a commitment to enhancing ones own awareness knowledge and skills related to equity diversity and inclusion

PREFERRED QUALIFICATIONS

Masters degree in a relevant discipline. Minimum 10 years of progressive leadership experience in technology risk cybersecurity governance enterprise risk management or related fields.


Experience developing or operating risk management frameworks aligned with recognized standards such as NIST ISO 27001/27002 COBIT or similar.


The following professional designations and experience are desired:

- IIA Certification in Risk Management Assurance (CRMA)

- Certified in the Governance of Enterprise Information Technology (CGEIT)
- ISACA Certified in Risk and Information Systems Control (CRISC)
- ISACA Certified Information Systems Auditor (CISA)
- Project Management Professional (PMP) Minimum of 9 years experience or the equivalent combination of education and experience.

- Minimum of 10 years of management experience
- Experience in a higher education institution
- Extensive experience of risk management information governance and information security frameworks such as COBIT and ISO 27002
- Self-motivated with a strong commitment to providing high quality services together with a thorough understanding and awareness of information governance and security best practices and the ability to translate them into meaningful and value added University-wide and local solutions
- Demonstrates knowledge of Freedom of Information and Protection of Privacy Act (FIPPA) as it relates to implementing reasonable security arrangements over personal information under the Universitys control or in its custody
- Holds in depth knowledge of the Universitys information security policies
- High level of interpersonal skills used to lead enthuse motivate influence and educate others to drive change across the University
- Excellent verbal and written communication skills and the ability to communicate effectively at all levels.
- Ability to identify problems and develop solutions through the involvement of appropriate stakeholders.
- Able to work under pressure and manage priorities appropriately
- Positive attitude towards learning and development demonstrated by a record of continuing professional development


Required Experience:

Director


Employment Type : Full-Time
Experience: years
Vacancy: 1
Monthly Salary Salary: 13137 - 20502
Create a job alert for this search

Associate Director, Cybersecurity Governance, Risk & Compliance • Vancouver, British Columbia, Canada

Similar jobs

Director of FinTech Analytics & Risk

JobberVancouver, Metro Vancouver Regional District, CA
Full-time

Join Jobber as a Director where you will elevate the integration of FinTech analytics and risk management.This key position makes a significant impact on financial product strategies.Reporting to t... Show more

 • Promoted

Senior Associate

Wylie-Crump LimitedVancouver, Metro Vancouver Regional District, CA
Full-time

Wylie-Crump is a specialized commercial insurance brokerage focused on construction, renewable energy, and complex risk management.We operate as a trusted advisor and outsourced risk manager to ent... Show more

 • Promoted

Senior Cybersecurity Analyst — Architecture & Threat Response

Surrey Police ServiceSurrey, Metro Vancouver Regional District, CA
Full-time

A law enforcement agency in Canada is seeking a Cybersecurity Analyst 3 to manage information security architecture and governance.This role involves developing security standards, conducting compl... Show more

 • Promoted

Associate Director, Professional Conduct - C$108,600 - C$128,900 A Year

Chartered Professional Accountants of British ColumbiaWest End, Canada
Full-time

Seeking an Associate Director to manage investigations into professional conduct complaints, support departmental initiatives, and ensure professional standards are met to protect the public. Show more

 • Promoted • New!

Risk Manager

Transportation Investment CorporationVancouver, Metro Vancouver Regional District, CA
Full-time

The salary range for this position is $83,000 to $114,000.The Risk Manager is responsible for overseeing risk management for TI Corp both corporately and for major infrastructure projects being del... Show more

 • Promoted

Associate Director Brand Partnerships

FeverVancouver, Metro Vancouver Regional District, CA
Full-time

We’re excited you are checking out this job offer.How do we achieve our mission? Fever has developed a proprietary technology that inspires a global community of over 125M people through personaliz... Show more

 • Promoted

Director, Enterprise Risk - $170,000 - $180,000 A Year - Remote

WELL HealthNorth Vancouver, Canada
Remote
Full-time

Seeking a Director of Enterprise Risk to manage and operationalize risk programs within a growing healthcare technology organization.Responsibilities include risk assessment, mitigation, reporting,... Show more

 • Promoted • New!

Director of IT Security for Directive Consulting

DirectiveVancouver, Metro Vancouver Regional District, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

Security Compliance Lead: Risk, Audit & Frameworks

Fortinet, Inc.Burnaby, Metro Vancouver Regional District, CA
Full-time

A leading cybersecurity firm is seeking a Security Compliance Analyst to ensure information systems comply with security standards.Key responsibilities include conducting audits, developing complia... Show more

 • Promoted

Director Risk Services Commercial Solutions - C$125,000 - C$150,000 A Year

Northbridge FinancialRichmond, Canada
Full-time

Directs risk services, implementing strategies, managing teams, and ensuring operational efficiency in the Western Region. Show more

 • Promoted

Securities/Corporate Associate

ZSA CanadaVancouver, Metro Vancouver Regional District, Canada
Full-time

Get notified about new Corporate Lawyer jobs in.Corporate Lawyer Jobs in United States.Counsel Director, Legal and Business Affairs.Associate Director, Legal Counsel, GBM Legal.Associate Director, ... Show more

 • Promoted

Impactful Associate Director, Professional Conduct

RegulatoryJobs Executive RecruitmentVancouver, British Columbia, Canada
Full-time

A leading regulatory body in British Columbia is seeking an Associate Director, Professional Conduct.This role involves managing investigations, supporting departmental projects, and ensuring compl... Show more

 • Promoted

Director of Risk Management and Strategy Integration

Beem Credit UnionBurnaby
Full-time

Lead innovative risk management practices at Beem Credit Union as the Director responsible for Risk and Strategy Integration.This hybrid role is pivotal in shaping risk intelligence within the orga... Show more

 • Promoted

Sr. Associate / Director of M&A

Embrace Software IncVancouver, Metro Vancouver Regional District, Canada
Permanent

Industrial, Healthcare, Financial Services, and Education.We own and operate dozens of vertical‑market software companies serving customers across North America, including Fortune 500 enterprises, ... Show more

 • Promoted

Principal Consultant Cybersecurity Zero Trust Advisory

Palo Alto NetworksVancouver, Metro Vancouver Regional District, Canada
Full-time

Join Palo Alto Networks as a Principal Consultant in Zero Trust Advisory.Your expertise will guide clients through comprehensive cybersecurity transformations with a focus on Zero Trust architectur... Show more

 • Promoted

Cybersecurity Audit & OT Risk Advisor

BC HydroVancouver, Metro Vancouver Regional District, CA
Full-time

A major utility company is seeking an experienced IT Advisor to enhance their cybersecurity posture in Vancouver.You will perform impact assessments, lead vendor risk evaluations, and communicate s... Show more

 • Promoted

Remote Change Lead — Cybersecurity Transformation

ARAGA SOLUTIONSVancouver, Metro Vancouver Regional District, CA
Remote
Full-time

A technology solutions provider is seeking a Change Manager to develop and implement a change management strategy focused on cybersecurity modernization.The role involves stakeholder engagement, st... Show more

 • Promoted

Director, Risk Services – Hybrid Leadership (Commercial) - C$125,000 - C$150,000 A Year

Northbridge Financial CorporationRichmond, Canada
Full-time

Director of Risk Services needed to oversee strategic direction and manage operational functions in Vancouver. Show more

 • Promoted

EY Associate Director, Deal Strategy Coach

EYVancouver, British Columbia, Canada
Full-time

Become a strategic deal coaching expert as an Associate Director at EY.Lead collaboration across service lines to drive transformational deal success.As part of EY’s Strategic Deals Team, you will ... Show more

 • Promoted

Associate Director, Cost Management - $147,000 - $197,000 A Year

LinesightWest End, Canada
Full-time

Lead teams, manage client relationships, and oversee strategic projects in cost management within the data center sector.Requires extensive experience in construction and cost management. Show more