Principal Investigator, Cybersecurity

Durham CollegeOshawa, ON
Onsite

About The Position

Durham College (DC) is seeking experienced and motivated professionals for the role of Principal Investigator, Cybersecurity. This part-time, project-based contract position is within the Centre for Cybersecurity Innovation, overseen by the Office of Research Services, Innovation and Entrepreneurship. The role involves overseeing the development of real-world solutions for industry partners through applied research and knowledge transfer projects. Teams of expert faculty, students, and recent graduates will collaborate with industry partners to deliver innovative cybersecurity-based solutions. Projects may include producing and testing prototypes, evaluating new technologies, and developing new or improved products or processes for small- and medium-sized businesses (SMEs). All projects are funded by provincial or federal government grants. The Centre for Cybersecurity Innovation is located at the Oshawa Campus and provides SMEs access to facilities, equipment, technical expertise, and project services.

Requirements

  • An undergraduate degree in Cybersecurity, Information Technology, Business or a related field, preferably a masters degree.
  • Three to five years of relevant industry experience and demonstrated ability in fields and technologies relevant to project opportunities
  • 3+ years of experience in GRC, information security, or compliance roles.
  • In-depth knowledge of SOC 2 Type 2, ISO 27001, and NIST frameworks.
  • Experience with gap analysis, internal audits, and remediation planning.
  • Strong understanding of cloud security principles and cloud infrastructure (AWS, Azure, GCP, etc.).
  • Familiarity with GRC and audit management tools (e.g., Secureframe, Drata, Vanta, Sprinto).
  • Excellent written and verbal communication skills; ability to communicate complex compliance requirements to technical and non-technical audiences.
  • Strong organizational and project management abilities.
  • Experience developing and maintaining security policies and governance documentation.
  • Ability to work independently and collaboratively in a fast-paced environment.

Nice To Haves

  • ISO/IEC 27001 Lead Auditor/Implementer, CISA, CRISC, CGRC, or similar certifications.
  • Experience supporting SOC 2 Type 2, ISO 27001, or NIST certification and audit processes.
  • Knowledge of vulnerability management, SIEM, and cloud security assessment tools.
  • Experience in SaaS or cloud-native environments.

Responsibilities

  • Develop, review, and update security policies, procedures, and governance documentation to meet compliance standards.
  • Conduct comprehensive gap assessments against relevant frameworks, identify areas of non-compliance, and recommend actionable remediation steps.
  • Lead the implementation, maintenance, and continuous improvement of SOC 2 Type 2, ISO 27001, and NIST SP 800-53/800-171 compliance programs.
  • Design, implement, and document security controls across cloud and on-premises environments, ensuring alignment with framework requirements.
  • Develop and manage remediation plans, conduct internal audits and readiness assessments, and track progress toward compliance objectives.
  • Perform risk assessments, maintain risk registers, and support third-party/vendor risk management processes.
  • Assess and enhance the security of cloud infrastructure, ensuring compliance with SOC 2, ISO 27001, and NIST requirements.
  • Coordinate and support external audits, manage evidence collection, and serve as the primary liaison with auditors.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service