Associate Director, Cybersecurity

SickKids FoundationToronto, ON
CA$99,297 - CA$142,739Hybrid

About The Position

SickKids Foundation is seeking an Associate Director, Cybersecurity. This senior leadership role is responsible for driving hands-on security operations, managing enterprise cyber risk, and maturing the organization's security posture. The incumbent will lead day-to-day security monitoring and incident response activities, oversee the risk register, champion security awareness, and ensure the organization is aligned with industry frameworks including MITRE ATT&CK and the NIST Cybersecurity Framework. The role reports to the Director, Infrastructure, Automation & Cybersecurity and is expected to actively leverage AI-enabled tools and automation to improve detection, response, and operational efficiency across the security program.

Requirements

  • 8+ years of progressive cybersecurity experience, with at least 5 years in a senior or lead role.
  • Hands-on experience in a Security Operations Centre (SOC) environment — monitoring, triage, and incident response.
  • Demonstrated working knowledge of MITRE ATT&CK framework and NIST CSF.
  • Proven experience owning or contributing to an IT/Cyber Risk Register.
  • Experience delivering security awareness programs and phishing simulations.
  • Familiarity with security tools: Imperva, Abnormal AI, and Sophos (or comparable equivalents).
  • Good understanding of cybersecurity architecture principles, network security, and cloud security.
  • Excellent communication and stakeholder management skills — ability to translate technical risk into business language.
  • Experience using automation and AI-enabled security tools to improve operational effectiveness.

Nice To Haves

  • CISSP, CISM, GIAC or equivalent.
  • Familiarity with additional frameworks: ISO 27001, SOC 2, CIS Controls.
  • Experience with SOAR platforms and automation of security workflows.
  • Post-secondary education in Computer Science, Information Security, or a related discipline.

Responsibilities

  • Monitor, triage, and respond to security events, alerts, and incidents across SIEM, EDR, email security, and WAF platforms.
  • Lead Level 2/3 incident analysis and drive root-cause investigations to resolution.
  • Maintain and tune detection rules, alert thresholds, and playbooks to reduce false-positive rates.
  • Administer and optimise security tooling including Imperva (WAF / Database Security), Abnormal AI (Email Security), and Sophos (EDR / Endpoint Protection).
  • Collaborate with vendors to ensure tools are current, licensed, and properly integrated.
  • Apply MITRE ATT&CK techniques and tactics to map threat actor behaviour and improve detection coverage.
  • Align security controls and risk assessments to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
  • Integrate threat intelligence feeds into operational tooling to proactively identify emerging risks.
  • Maintain the IT/Cyber Risk Register — identify, assess, score, and track remediation of risks in partnership with IT, legal, and business stakeholders.
  • Conduct periodic risk reviews and present risk status updates to leadership and governance committees.
  • Design, build, and execute enterprise-wide Cybersecurity Awareness Campaigns across multiple channels (intranet, email, digital signage, lunch-and-learns).
  • Coordinate and execute regular phishing simulation exercises using approved simulation platforms. Analyse simulation results, identify high-risk user segments, and administer remedial training.
  • Coordinate the annual Cybersecurity Tabletop Exercise — develop scenarios, coordinate participants (IT, legal, HR, communications, executive leadership), and facilitate sessions.
  • Document lessons learned, produce after-action reports, and track improvement items to closure.
  • Provide input on security architecture reviews for new projects, cloud deployments, and third-party integrations.
  • Maintain, review, and update Cybersecurity Policies, Standards, and Procedures on a defined review cycle.
  • Evaluate tool effectiveness, identify capability gaps, and make recommendations for tooling enhancements.
  • Actively incorporate artificial intelligence and advanced automation into security operations, including threat detection, alert triage, analysis, and reporting, to enable faster and more consistent outcomes.
  • Identify and reduce manual, repetitive security tasks through automation, orchestration, and standardized workflows rather than increased headcount.
  • Maintain current, practical expertise in AI-enabled security tooling and demonstrate personal proficiency in using these tools to accelerate analysis and decision-making.
  • Ensure AI is applied responsibly, securely, and in alignment with enterprise governance, privacy, and ethical standards.
  • Continuously evaluate emerging AI-enabled security capabilities and recommend adoption where they improve detection, response time, or operational efficiency.

Benefits

  • Comprehensive benefit package
  • Flex benefit plan
  • Tuition reimbursement
  • Flexible work arrangements
  • Pension plan
  • Birth parent/parental top up
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service