Talent.com
City of Brampton
Advisor, IT Security and RiskCity of Brampton • Brampton, Peel Region, Canada
Advisor, IT Security and Risk

Advisor, IT Security and Risk

City of Brampton • Brampton, Peel Region, Canada
11 days ago
Salary
CA$100,277.00 yearly
Job type
  • Full-time
Job description

Advisor, IT Security and Risk - Job Details

Job Title: Advisor, IT Security and Risk

Posting Start Date: 7/30/26

Job Opening Number: 107070
Job Requisition Number: 236
Number of Positions: 1
Job Type: Management and Administration
Department: CORPORATE SUPPORT SERVICES
Division: Information Technology
Hiring Salary Range: $100,277 - $112,812 per annum
Maximum of Salary Range: $125,346 per annum
Job Grade: 006
Job Status and Duration: Full Time (FT), Regular (R), vacancy
Hours of Work: 35 Hour work week
Location: West Tower
Posting Date: 07/30/2026
Closing Date: 08/14/2026

Area of Responsibilities

This role is responsible to provide advisory subject matter expertise, offer solutions, strategies and recommend ways to ensure all program policies and procedures related to Cyber Security and Information Risk Management within the Corporation are communicated and implemented to meet organizational effectiveness and corporate service standards.

As part of a small IT Security and Risk team, the role will be responsible for a broad range of information security work including: Supporting Information Security tooling, e.g. IDS/IPS, AntiVirus, Malware Detection Responses, URL Filtering, Threat Hunting, DLP, on Endpoints, Network Devices, and 0365/Azure Cloud. Managing operational support for Mail Gateway, AD PAM, Certificate Management/Provisioning, IAM Onboarding process. Providing security assessments on our in-house developed products as well as procured products; participating in enterprise and project risk management activities; researching, defining evaluation criteria and recommending information security controls and procedures; developing information security standards, policies and procedures; establishing information security metrics, gathering data and preparing reports; participating in the information security incident response process; and championing and communicating the future state of COB’s (City of Brampton) cyber security awareness program.

KEY RESPONSIBILITIES

  • OPERATION SUPPORT
  • Support projects and security tools by providing governance, and operational delivery of information security services.
  • Conduct security and threat risk assessments and security evaluations.
  • Conduct product reviews to identify potential vulnerabilities and risks.
  • Review IT operational processes, identifying potential security concerns and risks and developing mitigation measures.
  • Participate in enterprise and project risk management activities.
  • Proactively conduct IT security risk and vulnerability assessments for new and existing IT infrastructure elements (network/systems/applications/services).
  • Consult with the Corporation’s Technology Services teams to research, define evaluation criteria and recommend information security controls and procedures
  • Participate in the information security incident response process.
  • Inclusive of the above, the architecture focused role will:
  • Liaise with the Enterprise Information Architecture team as the source of trusted security expertise for various programs and projects
  • Develop, evolve and maintain security in balance with user, business, and system goals.
  • Assist with security reviews for conformance to solution architecture
  • Collaborate with development services in the development, review, and documentation of detailed security design and reusable security design patterns
  • STAFF GUIDANCE AND DIRECTION
  • Support staff, prioritize and organize daily work direction to meet operational effectiveness.
  • Coach, mentor and provide guidance as required to meet operational effectiveness.
  • Participate in recruitment and hiring process as required to meet operational effectiveness.
  • Provide input into performance review as required.
  • CUSTOMER SERVICE
  • Serve as a source of trusted information security expertise for various programs and projects.
  • Escalate complex issues to appropriate level.
  • Liaise with stakeholders in order to understand business needs and recommend solutions to meet operational effectiveness.
  • Build and maintain a relationship with internal and external stakeholders, departments and team members to achieve common goals and objectives.
  • COMMUNICATION AND REPORTING
  • Establish information security metrics, gather data and prepare reports.
  • Champion and communicate the future state of COB’s cyber security program.
  • Present and convey complex concepts and conditions to stakeholders; develop reports, proposals and make recommendations to management for effective decision-making.
  • Keep management informed of activities and initiatives; recommend solutions for effective decision-making.
  • CORPORATE CONTRIBUTION
  • Develop information security standards, policies and procedures.
  • Ensure proper documentation standards are adhered to, and standards are kept up to date.
  • Promote security awareness and good data protection practices to safeguard COB’s information assets.
  • Help shape strategic technical direction and standards for the organization.
  • Keep abreast of new technology trends, information security and cyber risks and standards development in order to recommend solutions that improve business processes, service solutions and best practices.
  • Maintain knowledge of collective agreements, City policies and practices, legislation, regulations and Standard Operating Procedures (SOPs).
  • BUDGET SUPPORT
  • Use of effective resource and expense management at all times to meet corporate policies and guidelines.
  • TEAMWORK AND COOPERATION
  • Participate on project initiatives as a subject matter expert.
  • Work well within diverse groups to achieve common goals and objectives that meet operational effectiveness and corporate service standards.
  • Participate as a member of cross-functional team.
  • Demonstrate corporate values at all times.

SELECTION CRITERIA

Education

  • Post-secondary degree or diploma in Information Technology, Computer Science, Engineering, Business or related degree is required.
  • Professional security and privacy certifications (one of more of the following is preferred):Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA)
  • Information security specific coursework is an asset.

Experience

  • 7+ years of broad and progressive information security experience in an enterprise environment including: security tooling support, program development, security risk and vulnerability analyses, system design and architecture required.
  • Minimum of 3 years in a senior information security position in a medium to large organization.
  • 3-5 years supervisory experience is an asset; Ability to guide and motivate staff

Other Skills and Assets

  • Practical knowledge of Municipal, Regional, Provincial and Federal Governments and applicable Legislations is an asset
  • Demonstrable experience with conducting security reviews, implementing information security recommendations, analyzing technical controls and applying security control standards required.
  • Experience in public cloud environment (MS Azure and AWS is highly preferred) and analyzing existing cloud structures and creating new and enhanced security methods.
  • Knowledge of and experience working with the following IT security solutions: Cloud Access Security Broker, Endpoint Detection and Response, Next Generation Firewall, Privileged Access Management, Identity Access Management, Security Information and Event Management (SIEM), Multi Factor Authentication, Vulnerability Management, Penetration Testing, etc.)
  • Understanding of and experience with general certificate management processes, public key infrastructure (PKI) and commercial Certificate Authority providers
  • Demonstrable experience presenting analyses and presentations to both internal and external audiences.
  • Strong understanding of various information security controls, their strengths and weaknesses, and how best to apply them successfully to mitigate threats.
  • Broad understanding of Microsoft and Oracle technology stacks across operating system, server, middleware, storage (database), and development.
  • Exceptional knowledge of application, network, and operating system security, security architectures and the application of privacy and security controls (i.e. authentication, authorization, auditing, encryption).
  • Strong understanding of Cloud computing concepts, virtualization and software architecture patterns. Microsoft Azure knowledge and experience is highly preferred.Ability to understand and translate strategic, tactical and operational business requirements into effective architectures and designs through the use of new or enhanced technology products and services to support business objectives.
  • Ability to function with a high level of autonomy in setting objectives based on direction from management.
  • Collaboration with team in managing expectations and tracking progress.
  • Ability to develop detailed documentation tailored to specific audiences and purposes.
  • Exceptional communication skills. Has the ability to interact equally well with experts from multiple disciplines; both technical and non-technical. Listens effectively and articulates complex technology alternatives in ways appropriate for the audience.
  • Strong Presentation skills; Facilitate and convey concepts in a clear and concise manner
  • Strong Customer Service and People Management skills; Interface with internal and external stakeholders and resolve issues to meet corporate service standards
  • Strong Organizational skills; Detail oriented, well organized and able to prioritize complex tasks and meet critical deadlines
  • Strong Analytical skills for complex problem solving

Additional Information

Interview: Our recruitment process may be completed with video conference technology.

As part of the corporation’s Modernizing Job Evaluation project, this position will undergo an evaluation which may result in a change to the rate of compensation. Any changes affecting this position will be communicated as information becomes available.

As part of the application process, applicants will be invited to complete a self identification survey. The survey is voluntary. Participation in the survey will have no impact on hiring decisions. All information collected is confidential and will not be shared with the hiring manager. The surveys will be anonymized and will be kept separate from applicant or employee files, such that the individuals who completed the surveys will not be identifiable. The results of the survey will assist in the analysis of disaggregated metrics for organizational planning purposes and our commitment to advance and foster diversity, equity, and inclusion. The City may use anonymized data to produce aggregate reports for internal or external use.

The City of Brampton uses email to communicate with applicants for open job competitions. It is the applicant's responsibility to include an updated email address that is checked daily and accepts emails from unknown users. Time sensitive correspondence is sent via email (i.e. testing bookings, interview dates) and it is imperative that applicants check their email regularly. If we do not hear back from applicants, we will assume that you are no longer interested in the employment opportunity and your application will be removed from the competition.

If you would like to request content in an alternate format, please contact the Accessibility office by submitting a new Alternate Format Request .

The City is an equal opportunity employer. We are committed to inclusive, barrier-free recruitment and selection processes and work environments. If you require any accommodations at any point during the application and hiring process, please contact TalentAcquisition@brampton.ca or 905.874.2150 with your accommodation needs, quoting the job opening ID#, job title. Any information received relating to accommodation will be addressed confidentially.

#J-18808-Ljbffr
Create a job alert for this search

Advisor, IT Security and Risk • Brampton, Peel Region, Canada

Similar jobs

On-Site IT Director Role at OTI Lumionics

OTI Lumionicsmississauga, peel region, Canada
Full-time

Become OTI Lumionics' IT Director, spearheading on-site operations and strategic IT governance.Focus on enhancing infrastructure and cybersecurity for advanced material applications.As a pivotal me... Show more

 • Promoted

Director Of Information Security Strategy (Hybrid) - C$84,000 - C$115,000 A Year

Healthcare Solutions ProviderBrampton, Canada
Full-time +1

A healthcare solutions provider in Brampton is seeking a Manager of Information Security to lead their information security initiatives.This permanent full-time position involves strategic developm... Show more

 • Promoted

Security Systems Field Technical Lead

ConvergintMississauga, Peel region, Canada
Full-time

Convergint is currently looking for a Security Field Technical Lead to join our amazing culture in our Toronto location.As a Security Field Technical Lead, you will be responsible for the installat... Show more

 • Promoted

Strategic Information Security Architect

ColliersMississauga, Peel Region, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

CAA Club Group IT Security Coordinator

CAA Club GroupVaughan, York region, Canada
Full-time

Become an IT Security Coordinator at CAA Club Group, providing vital technical support to enhance member safety.This role emphasizes troubleshooting across various platforms.At CAA Club Group, the ... Show more

 • Promoted

Remote IT Security Consultant - Leading Security Initiatives

ExperisMississauga, Peel Region, CA
Remote
Full-time

A leading technology staffing firm is seeking experienced IT Security Consultants to enhance cybersecurity initiatives across Canada.In this remote role, you will lead security implementations, con... Show more

 • Promoted

Mid-Senior Risk & IT Analytics Consultant

TechDoQuestMississauga
Full-time

A leading technology firm is seeking a mid-senior level IT Analyst based in Mississauga to lead risk management initiatives.The role involves comprehensive risk assessments and communication with c... Show more

 • Promoted

Senior It Director, Strategy, Security & Ops - $120,000 - $160,000 A Year

Leading Educational InstitutionMississauga, Canada
Full-time

Oversees IT strategy, security, and operations for an educational institution, requiring strong leadership and project management skills. Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMississauga, Peel Region, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2PMississauga, Peel region, Canada
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Manager, Assurance & Advisory, Risk Advisory - C$100,000 - C$132,000 A Year

Loblaw Companies LimitedPeel, Canada
Full-time

Lead assurance and advisory projects, driving strategy, quality, and delivery.Manage stakeholder relationships, mentor team members, and provide business insights and recommendations. Show more

 • Promoted

Senior IT Systems & Security Engineer

Litens Automotive GroupVaughan, York region, Canada
Full-time

A leading automotive manufacturing company located in York Region, Vaughan is seeking a Senior Systems Administrator and Security Engineer.This role requires a comprehensive skill set including net... Show more

 • Promoted

It Security Leader: Strategy, Policy & Risk | Hybrid - C$84,000 - C$105,000 A Year

Health Solutions ProviderPeel, Canada
Full-time

Manager of IT Security to lead information security strategy, policy, and risk management.Focus on compliance and stakeholder collaboration in a hybrid work model. Show more

 • Promoted

Senior IT and security Administrator – Malware Protection Specialist

act digitalMississauga, Peel region, Canada
Full-time

Senior IT and security Administrator – Malware Protection Specialist.ALTER SOLUTIONS is a consulting and technology expertise company founded in 2006.Our mission is to support our clients with thei... Show more

 • Promoted

Remote Director of IT Security Role

DirectiveMississauga, Peel region, Canada
Remote
Full-time

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Show more

 • Promoted

Tech Risk Auditor - It Controls & Assurance - C$60,000 - C$90,000 A Year

Canadian professional services networkOakville, Canada
Full-time

A leading Canadian professional services network is looking for an IS/IT Auditor in Oakville.The successful candidate will perform assessments of IT General Controls for financial audits, collabora... Show more

 • Promoted

Director, Enterprise Risk Management – It Security & Cyber Risk

Sagen MI Canada Inc.Oakville, Canada
Full-time

Director, Enterprise Risk Management – IT Security & Cyber RiskJob DescriptionSagen is Canada's leading private mortgage insurance company making home ownership more accessible to first tim... Show more

 • Promoted

Senior IT Audit Leader - Risk, Controls & Advisory

Clarity RecruitmentVaughan, York Region, CA
Full-time

A recruitment firm specializing in Finance & Accounting seeks an experienced IT Audit Manager in Vaughan, Canada.You will lead the planning and execution of complex IT audits, develop risk-based re... Show more

 • Promoted

Manager It Security - $84,000 - $115,000 A Year

DynacarePeel, Canada
Full-time

Manages the information security program, focusing on strategy, policy, risk management, and team leadership to ensure data integrity and system security. Show more

 • Promoted

Security Governance, Risk and Compliance Specialist

Tecsys Inc.Mississauga, Peel Region, CA
Full-time +1

Security Governance, Risk and Compliance Specialist.Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee ... Show more