Director, Information Security

Brock UniversitySt. Catharines, ON
CA$140,000 - CA$160,000Hybrid

About The Position

Reporting to the Associate Vice-President, Information Technology Services, the Director, Information Security provides enterprise leadership and strategic direction for the University’s information security program, spanning security governance, policy and standards, risk management, security architecture, identity and access governance, security awareness, incident response, and cyber resilience. The incumbent serves as the University’s senior authority on information security and technology risk, setting security strategies, governance frameworks, policies, standards, and roadmaps that protect Brock’s digital assets, systems, and information resources and support regulatory and compliance requirements. The Information Security portfolio governs security for the University; it sets requirements, assesses risk, assures the effectiveness of controls, and directs the response to security incidents, while day-to-day security controls are operated by ITS delivery teams under those standards. The Director, Information Security partners closely with ITS leadership, the University’s privacy function, the research portfolio, and institutional stakeholders to strengthen Brock’s security posture while enabling teaching, learning, and research.

Requirements

  • Degree in a related discipline or the equivalent combination of education and experience;
  • Leadership experience in information security, cybersecurity, technology risk management, or enterprise technology environments, including oversight of enterprise cybersecurity programs, security operations, identity and access management (IAM), risk management, compliance, security governance, and vendor/cloud security;
  • Experience leading security incident response, digital forensics, investigations, business continuity, and disaster recovery programs;
  • Extensive knowledge of enterprise information security, cybersecurity governance, technology risk management, compliance, and regulatory frameworks, including NIST, ISO 27001, CIS Controls, PCI-DSS, FIPPA, federal research security requirements, and related standards;
  • Comprehensive understanding of cybersecurity operations, including security operations centres (SOC), incident response, threat management, digital forensics, vulnerability management, security monitoring, and SIEM technologies;
  • Advanced knowledge of security architecture and technologies, including cloud security, identity and access management (IAM), endpoint security, data protection, firewalls, intrusion detection and prevention systems, centralized logging, vulnerability management, and emerging infrastructure technologies;
  • Strong understanding of enterprise infrastructure, networking, operating systems, and cloud environments, including Microsoft and Linux server platforms;
  • Advanced knowledge of cyber risk assessment methodologies, security governance practices, compliance requirements, and risk mitigation strategies, with the ability to assess emerging threats and develop appropriate organizational responses;
  • Ability to develop and execute long-term cybersecurity strategies, operating models, roadmaps, and organizational change initiatives aligned with institutional objectives;
  • Promotes and embodies inclusivity and respect within the workplace and the broader community;
  • Strong customer service skills, with the ability to maintain effective relationships with internal and external partners;
  • Exceptional communication, presentation, and facilitation skills, with the ability to translate complex technical concepts into clear recommendations, reports, assessments, and briefings;
  • Strong analytical, problem-solving, organizational, and decision-making skills.

Nice To Haves

  • Experience in the higher education and/or public sector;
  • Master's degree in Cybersecurity, Information Technology, Information Systems, Business Administration (MBA), or a related discipline;
  • Professional cybersecurity certifications such as CISSP, CISM, CRISC, CCSP, GIAC, CGEIT;
  • Project Management Professional (PMP), ITIL, COBIT, or related governance, risk, or service management certifications.

Responsibilities

  • Provide senior leadership, strategic direction, and oversight for the University’s information security, cybersecurity, and technology risk programs;
  • Establish and advance the University’s information security vision, governance framework, and strategic roadmap to support institutional priorities and strengthen organizational resilience;
  • Lead the development and governance of enterprise security policies, standards, procedures, and control frameworks to protect University information assets and services, ensuring alignment with institutional objectives, regulatory requirements, and industry frameworks;
  • Direct the evolution of enterprise security architecture, secure-by-design principles, and technology standards to support a modern and resilient security posture;
  • Establish performance measures and reporting mechanisms that enable effective oversight and decision-making;
  • Provide strategic oversight of identity and access management, including standards and requirements for authentication, authorization, privileged access, and identity lifecycle management;
  • Advise academic, administrative, and technology leaders on emerging threats, cybersecurity risks, privacy considerations, and security-related strategic initiatives;
  • Oversee security risk assessment activities across applications, infrastructure, cloud services, research environments, third-party solutions, and business processes;
  • Establish and govern vulnerability management, threat monitoring, penetration testing, and security assessment programs to proactively identify and address risks;
  • Ensure security requirements are embedded throughout technology planning, procurement, solution design, implementation, and operational support processes;
  • Provide leadership and command authority for enterprise cybersecurity incident response, leading institutional response to cybersecurity incidents, data breaches, ransomware events, malware outbreaks, phishing campaigns, and other security threats;
  • Ensure effective monitoring, detection, investigation, containment, recovery, and reporting of cybersecurity incidents across the institution;
  • Champion enterprise-wide security awareness, education, and training programs that strengthen cybersecurity knowledge and accountability across the University community;
  • Provide leadership, coaching and mentorship to a Program Manager, Information Security, and an Information Security Analyst;
  • Support the University's research security obligations in partnership with the Office of Research, enabling researchers by embedding security across research activities while preserving a flexible operating environment.

Benefits

  • Health & Dental Benefits: Comprehensive extended health, dental, and vision coverage.
  • Pension Plan: Enrollment eligibility in the Brock University Pension Plan.
  • Vacation: Up to 3 weeks per year, in addition to university holidays.
  • Professional Development: Eligibility for the Brock Tuition Waiver Program.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service