Director, Information Security

Brock University

St. Catharines

On-site

CAD 140,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & dental benefits
Pension plan
Vacation: up to 3 weeks
Professional development

Job summary

Brock University in St. Catharines, Canada, seeks a Director, Information Security to provide enterprise leadership for the University’s information security program, governance, risk management, and technology resilience.

The role reports to the Associate Vice-President, ITS and partners with privacy, research, and stakeholders to balance security with teaching, learning, and innovation. You will lead security architecture, IAM, incident response, and vendor security, set policies and roadmaps,

Qualifications

  • Experience leading enterprise security programs and governance.
  • Knowledge of NIST, ISO 27001, CIS Controls, PCI-DSS and related standards.
  • Ability to translate complex security concepts to stakeholders.

Responsibilities

  • Provide senior leadership and strategic direction for information security and technology risk.
  • Develop governance frameworks, policies, and roadmaps for security across Brock University.
  • Oversee IAM standards, incident response, threat monitoring, and risk assessments.
  • Collaborate with ITS, privacy, research, and academic leaders to balance security with innovation.

Skills

Security leadership
Information security
Technology risk
IAM
Policy governance
Risk management
Incident response
Disaster recovery
Vulnerability management
Security architecture
Cloud security
Regulatory compliance
Communication skills

Education

Degree in related discipline
Master's degree (preferred)

Job description

This job advertisement is to fill an existing vacancy in the Administrative Professional (Employee Group)

About the Role:

Reporting to the Associate Vice-President, Information Technology Services, the Director, Information Security provides enterprise leadership and strategic direction for the University’s information security program, spanning security governance, policy and standards, risk management, security architecture, identity and access governance, security awareness, incident response, and cyber resilience. The incumbent serves as the University’s senior authority on information security and technology risk, setting security strategies, governance frameworks, policies, standards, and roadmaps that protect Brock’s digital assets, systems, and information resources and support regulatory and compliance requirements. The Information Security portfolio governs security for the University; it sets requirements, assesses risk, assures the effectiveness of controls, and directs the response to security incidents, while day-to-day security controls are operated by ITS delivery teams under those standards. The Director, Information Security partners closely with ITS leadership, the University’s privacy function, the research portfolio, and institutional stakeholders to strengthen Brock’s security posture while enabling teaching, learning, and research.

The Director, Information Security will:
  • Provide senior leadership, strategic direction, and oversight for the University’s information security, cybersecurity, and technology risk programs;
  • Establish and advance the University’s information security vision, governance framework, and strategic roadmap to support institutional priorities and strengthen organizational resilience;
  • Lead the development and governance of enterprise security policies, standards, procedures, and control frameworks to protect University information assets and services, ensuring alignment with institutional objectives, regulatory requirements, and industry frameworks;
  • Direct the evolution of enterprise security architecture, secure-by-design principles, and technology standards to support a modern and resilient security posture;
  • Establish performance measures and reporting mechanisms that enable effective oversight and decision-making;
  • Provide strategic oversight of identity and access management, including standards and requirements for authentication, authorization, privileged access, and identity lifecycle management;
  • Advise academic, administrative, and technology leaders on emerging threats, cybersecurity risks, privacy considerations, and security-related strategic initiatives;
  • Oversee security risk assessment activities across applications, infrastructure, cloud services, research environments, third-party solutions, and business processes;
  • Establish and govern vulnerability management, threat monitoring, penetration testing, and security assessment programs to proactively identify and address risks;
  • Ensure security requirements are embedded throughout technology planning, procurement, solution design, implementation, and operational support processes;
  • Provide leadership and command authority for enterprise cybersecurity incident response, leading institutional response to cybersecurity incidents, data breaches, ransomware events, malware outbreaks, phishing campaigns, and other security threats;
  • Ensure effective monitoring, detection, investigation, containment, recovery, and reporting of cybersecurity incidents across the institution;
  • Champion enterprise-wide security awareness, education, and training programs that strengthen cybersecurity knowledge and accountability across the University community;
  • Provide leadership, coaching and mentorship to a Program Manager, Information Security, and an Information Security Analyst;
  • Support the University's research security obligations in partnership with the Office of Research, enabling researchers by embedding security across research activities while preserving a flexible operating environment.
Key Skills and Experience:
  • Degree in a related discipline or the equivalent combination of education and experience;
  • Leadership experience in information security, cybersecurity, technology risk management, or enterprise technology environments, including oversight of enterprise cybersecurity programs, security operations, identity and access management (IAM), risk management, compliance, security governance, and vendor/cloud security;
  • Experience leading security incident response, digital forensics, investigations, business continuity, and disaster recovery programs;
  • Extensive knowledge of enterprise information security, cybersecurity governance, technology risk management, compliance, and regulatory frameworks, including NIST, ISO 27001, CIS Controls, PCI-DSS, FIPPA, federal research security requirements, and related standards;
  • Comprehensive understanding of cybersecurity operations, including security operations centres (SOC), incident response, threat management, digital forensics, vulnerability management, security monitoring, and SIEM technologies;
  • Advanced knowledge of security architecture and technologies, including cloud security, identity and access management (IAM), endpoint security, data protection, firewalls, intrusion detection and prevention systems, centralized logging, vulnerability management, and emerging infrastructure technologies;
  • Strong understanding of enterprise infrastructure, networking, operating systems, and cloud environments, including Microsoft and Linux server platforms;
  • Advanced knowledge of cyber risk assessment methodologies, security governance practices, compliance requirements, and risk mitigation strategies, with the ability to assess emerging threats and develop appropriate organizational responses;
  • Ability to develop and execute long-term cybersecurity strategies, operating models, roadmaps, and organizational change initiatives aligned with institutional objectives;
  • Promotes and embodies inclusivity and respect within the workplace and the broader community;
  • Strong customer service skills, with the ability to maintain effective relationships with internal and external partners;
  • Exceptional communication, presentation, and facilitation skills, with the ability to translate complex technical concepts into clear recommendations, reports, assessments, and briefings;
  • Strong analytical, problem-solving, organizational, and decision-making skills.
Preferred or Asset Skills:
  • Experience in the higher education and/or public sector;
  • Master's degree in Cybersecurity, Information Technology, Information Systems, Business Administration (MBA), or a related discipline;
  • Professional cybersecurity certifications such as CISSP, CISM, CRISC, CCSP, GIAC, CGEIT;
  • Project Management Professional (PMP), ITIL, COBIT, or related governance, risk, or service management certifications.
Salary and Total Rewards:
  • Job Grade Q, Salary Scale ($111,580-178,528);
  • Target Hiring Range: $140,000-$160,000*
  • This is a permanent position that includes:
  • Health & Dental Benefits: Comprehensive extended health, dental, and vision coverage.
  • Pension Plan:Enrollment eligibility in the Brock University Pension Plan.
  • Vacation: Up to 3 weeks per year, in addition to university holidays.
  • Professional Development: Eligibility for the Brock Tuition Waiver Program.

*The final salary is based on experience, internal equity, and budget considerations within the target hiring range.

We are committed to offering flexible work arrangements where possible as outlined in our Flexible Work Arrangement Policy. As a student-centered organization, all employees are required to work on campus as needed.

Brock University is committed to creating a respectful and equitable workplace. We strive to foster a culture of diversity and inclusion in our work and learning environments. We welcome applications from all qualified individuals and actively encourage applications from women, people with disabilities, members of the 2SLGBTQIA+ community, Indigenous Peoples, people who identify as Black, African and/or Caribbean, as racialized and/or as from ethnic and cultural minority groups, and other underrepresented demographic groups at Brock and in the Niagara region. Brock also recognizes intersectionality and the interconnected identities, histories, and experiences of these aforementioned groups.

We are committed to inclusive and barrier-free recruitment, and we accommodate the needs of applicants throughout all stages of the recruitment process, as outlined in our Employment Accommodation Policy and consistent with the requirements of the Ontario Human Rights Code. Please contact talent@brocku.ca if you require a disability related accommodation so we can ensure your participation needs are met.

Brock University does not use AI Technology at any stage of the recruitment process.

We appreciate all applications received. Candidates that are selected for an interview will be contacted.

Learn more about Brock University by visiting www.brocku.ca.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Enterprise Technology & Products
Director, Enterprise Technology & Products

Socket.dev • St. Catharines

On-site
CAD 130,000 - 160,000
Health & Dental Benefits
Pension Plan
Vacation
+1
Director, Enterprise Technology & Products
Director, Enterprise Technology & Products

Brock University • St. Catharines

On-site
CAD 130,000 - 160,000
Health & Dental Benefits
Pension Plan
Vacation: Up to 3 weeks per year
Senior Analyst, IT Security
Senior Analyst, IT Security

Socket.dev • Ottawa

Hybrid
CAD 97,000 - 121,000
Director, Identity and Access Management
Director, Identity and Access Management

University of Toronto • Toronto

On-site
CAD 145,000 - 169,000
Manager, IT Infrastructure and Security
Manager, IT Infrastructure and Security

University of Toronto • Toronto

On-site
CAD 120,000 - 201,000
Senior Analyst, IT Security
Senior Analyst, IT Security

University of Ottawa • Ottawa

On-site
CAD 97,000 - 121,000
Cyber Security Architect
Cyber Security Architect

Centennial College • Toronto

On-site
CAD 120,000 - 180,000
Manager, Safety & Security
Manager, Safety & Security

Yorkville University • Toronto

On-site
CAD 90,000 - 105,000
Director Information Security
Director Information Security

Hire DigITalent Inc. • Toronto

On-site
CAD 180,000 - 240,000
Security Analyst
Security Analyst

York University • Toronto

On-site
CAD 85,000 - 110,000