Location Address:100 Queens Quay East, 9th Floor, Toronto
Number of Openings:1
Pay:$106,911.00 - $205,213.00
Job Posting Description:Director, Cybersecurity
This position is onsite #LI-OnsiteAre you passionate about growing and developing cybersecurity teams and programs? Reporting to the CIO, you will oversee the LCBO's cybersecurity program and ensure that we maintain a robust cybersecurity posture, aligned with business objectives and regulatory requirements. You will be the primary liaison between LCBO and the MSSP as well as managing high-severity incidents, overseeing vendor relationships, and leading strategic initiatives to protect systems, data, and assets.
About the RoleStrategic Leadership and Governance- Develop and execute the organization's cybersecurity strategy and roadmap.
- Provide strategic direction to ensure cybersecurity aligns with organizational goals.
- Oversee cybersecurity governance, compliance, and risk management frameworks.
- Act as the organization's key advisor on cybersecurity to the CIO, leadership team, and other stakeholders.
- Develop and present updates to executive leadership and the Board on the state of cybersecurity.
- Lead the cybersecurity council meetings to provide updates to leadership from all business units
- Monitor changes to regulatory and compliance requirements, ensuring the organization's cybersecurity strategy evolves to meet new standards and obligations.
- Collaborate with LCBO CISO
Cybersecurity Program Oversight and Strategic Operations- Serve as Incident Commander for high-severity incidents, ensuring timely resolution and executive reporting.
- Oversee strategic direction of cybersecurity operations, ensuring proper monitoring, detection, and response processes are in place.
- Establish and track key cybersecurity metrics to measure the program's effectiveness, ensuring alignment with organizational goals and identifying opportunities for continuous improvement.
- Lead the governance and performance management of the Managed Security Service Provider (Managed Security Service Provider) to ensure SLAs and KPIs are met.
- Advance the organization's cybersecurity maturity by promoting innovative security strategies, frameworks, and automation to proactively address evolving threats and business needs.
- Ensure the effectiveness of security tools, processes, and technologies across the enterprise.
- Develop and enforce policies, standards, and processes to enhance security posture.
- Oversee enterprise-wide cybersecurity risk assessments and ensure mitigation strategies are aligned with organizational risk tolerance and business objectives.
- Continuously assess emerging cybersecurity technologies and threats to identify opportunities for innovation and ensure the organization remains resilient against evolving risks.
- Manage the cybersecurity budget, ensuring effective allocation of resources to achieve strategic priorities and enhance security capabilities.
- Act as the primary cybersecurity representative during the RFP process, ensuring that security requirements are accurately defined and included in procurement documents.
Leadership Development and Organizational Integration- Lead, mentor, and develop the cybersecurity team, including senior managers, architects, and analysts.
- Foster a culture of continuous improvement and knowledge sharing.
- Provide strategic oversight into the development and delivery of security awareness and training programs to promote a security-first culture across the organization.
- Collaborate with other IT and business leaders to integrate security into operations.
- Promote cross-functional collaboration to ensure security priorities are integrated into IT and business operations without hindering innovation.
- Champion security awareness programs across the organization to embed a security-first mindset at all levels.
- Develop and implement talent development and succession planning strategies to grow future cybersecurity leaders.
Third-Party Risk and Compliance Management- Oversee relationships with third parties, ensuring SLAs and compliance objectives are met.
- Develop and oversee a comprehensive third-party risk management program to mitigate risks posed by vendors, suppliers, and partners.
- Ensure findings from audits and assessments are addressed promptly, and drive improvements to maintain compliance and enhance security posture."
- Lead security reviews, assessments, and audits, ensuring alignment with regulatory frameworks (e.g., NIST, ISO 27001).
- Provide strategic oversight for the implementation of initiatives that improve the organization's cybersecurity posture across cloud, network, and applications.
- Establish metrics and reporting mechanisms to track vendor compliance with SLAs and ensure alignment with security objectives
- Stay current with the latest regulatory requirements and ensure we are compliant across all security domains.
About You- Bachelor's degree in Computer Science, IT, cybersecurity or equivalent work experience
- CISSP or CRISC or CISA or CISM Certification or equivalent experience
- 7+ years of progressive experience in cybersecurity, including at least 3 years in a leadership or strategic oversight role.
- Knowledge of cloud security (Azure, AWS) and Vulnerability Management
- Expertise in frameworks like NIST CSF, ISO 27001, and CIS Controls; strong knowledge of cloud security (Azure, AWS), vulnerability management, and modern security architectures Knowledge of incident response processes.
- Understanding of compliance standards such as PCI-DSS, GDPR, or Canadian-specific cybersecurity regulations.
- Identify inefficiencies in processes and recommend automation or optimization.
- Experience aligning MSSP operations with long-term cybersecurity goals.
- Experience mentoring teams and aligning cybersecurity initiatives with organizational goals.
- Experience managing incidents, conducting risk assessments, and overseeing audit and compliance efforts to mitigate risks.
- Experienced in managing third-party vendors, negotiating contracts, and ensuring SLA compliance.
We offer a comprehensive suite of benefits including:
- Health/Dental Benefits
- Access to an Employee & Family Assistance Program
- a Defined Benefit Pension
- Discounts on products and services via Workperks.
Work Hours:36.25
Union / Non-Union:Non-Union
Job Posting End Date:July 22, 2026