Director, Cybersecurity

Liquor Control Board of Ontario

$106K — $205K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, cybersecurity, or equivalent experience
  • CISSP, CRISC, CISA, or CISM Certification or equivalent experience
  • 7+ years of progressive cybersecurity experience, including 3+ years in a leadership role
  • Knowledge of cloud security (Azure, AWS) and vulnerability management
  • Expertise in NIST CSF, ISO 27001, and CIS Controls frameworks
  • Understanding of compliance standards such as PCI-DSS and GDPR
  • Experience in managing third-party vendor relationships and SLAs.

Responsibilities

  • Develop and execute the cybersecurity strategy and roadmap for the organization.
  • Oversee governance and compliance frameworks ensuring alignment with business goals.
  • Act as the key cybersecurity advisor to the CIO and executive leadership.
  • Serve as Incident Commander for high-severity incidents, ensuring timely resolution.
  • Lead the cybersecurity team and foster a culture of continuous improvement.
  • Manage the cybersecurity budget and allocate resources to strategic priorities.
  • Oversee third-party risk management programs to mitigate vendor-related risks.

Benefits

  • Health/Dental Benefits
  • Access to an Employee & Family Assistance Program
  • Defined Benefit Pension
  • Discounts on products and services via Workperks.
Full Job Description
Location Address:
100 Queens Quay East, 9th Floor, Toronto

Number of Openings:
1

Pay:

$106,911.00 - $205,213.00

Job Posting Description:

Director, Cybersecurity

This position is onsite #LI-Onsite

Are you passionate about growing and developing cybersecurity teams and programs? Reporting to the CIO, you will oversee the LCBO's cybersecurity program and ensure that we maintain a robust cybersecurity posture, aligned with business objectives and regulatory requirements. You will be the primary liaison between LCBO and the MSSP as well as managing high-severity incidents, overseeing vendor relationships, and leading strategic initiatives to protect systems, data, and assets.

About the Role

Strategic Leadership and Governance
  • Develop and execute the organization's cybersecurity strategy and roadmap.
  • Provide strategic direction to ensure cybersecurity aligns with organizational goals.
  • Oversee cybersecurity governance, compliance, and risk management frameworks.
  • Act as the organization's key advisor on cybersecurity to the CIO, leadership team, and other stakeholders.
  • Develop and present updates to executive leadership and the Board on the state of cybersecurity.
  • Lead the cybersecurity council meetings to provide updates to leadership from all business units
  • Monitor changes to regulatory and compliance requirements, ensuring the organization's cybersecurity strategy evolves to meet new standards and obligations.
  • Collaborate with LCBO CISO


Cybersecurity Program Oversight and Strategic Operations
  • Serve as Incident Commander for high-severity incidents, ensuring timely resolution and executive reporting.
  • Oversee strategic direction of cybersecurity operations, ensuring proper monitoring, detection, and response processes are in place.
  • Establish and track key cybersecurity metrics to measure the program's effectiveness, ensuring alignment with organizational goals and identifying opportunities for continuous improvement.
  • Lead the governance and performance management of the Managed Security Service Provider (Managed Security Service Provider) to ensure SLAs and KPIs are met.
  • Advance the organization's cybersecurity maturity by promoting innovative security strategies, frameworks, and automation to proactively address evolving threats and business needs.
  • Ensure the effectiveness of security tools, processes, and technologies across the enterprise.
  • Develop and enforce policies, standards, and processes to enhance security posture.
  • Oversee enterprise-wide cybersecurity risk assessments and ensure mitigation strategies are aligned with organizational risk tolerance and business objectives.
  • Continuously assess emerging cybersecurity technologies and threats to identify opportunities for innovation and ensure the organization remains resilient against evolving risks.
  • Manage the cybersecurity budget, ensuring effective allocation of resources to achieve strategic priorities and enhance security capabilities.
  • Act as the primary cybersecurity representative during the RFP process, ensuring that security requirements are accurately defined and included in procurement documents.


Leadership Development and Organizational Integration
  • Lead, mentor, and develop the cybersecurity team, including senior managers, architects, and analysts.
  • Foster a culture of continuous improvement and knowledge sharing.
  • Provide strategic oversight into the development and delivery of security awareness and training programs to promote a security-first culture across the organization.
  • Collaborate with other IT and business leaders to integrate security into operations.
  • Promote cross-functional collaboration to ensure security priorities are integrated into IT and business operations without hindering innovation.
  • Champion security awareness programs across the organization to embed a security-first mindset at all levels.
  • Develop and implement talent development and succession planning strategies to grow future cybersecurity leaders.


Third-Party Risk and Compliance Management
  • Oversee relationships with third parties, ensuring SLAs and compliance objectives are met.
  • Develop and oversee a comprehensive third-party risk management program to mitigate risks posed by vendors, suppliers, and partners.
  • Ensure findings from audits and assessments are addressed promptly, and drive improvements to maintain compliance and enhance security posture."
  • Lead security reviews, assessments, and audits, ensuring alignment with regulatory frameworks (e.g., NIST, ISO 27001).
  • Provide strategic oversight for the implementation of initiatives that improve the organization's cybersecurity posture across cloud, network, and applications.
  • Establish metrics and reporting mechanisms to track vendor compliance with SLAs and ensure alignment with security objectives
  • Stay current with the latest regulatory requirements and ensure we are compliant across all security domains.


About You
  • Bachelor's degree in Computer Science, IT, cybersecurity or equivalent work experience
  • CISSP or CRISC or CISA or CISM Certification or equivalent experience
  • 7+ years of progressive experience in cybersecurity, including at least 3 years in a leadership or strategic oversight role.
  • Knowledge of cloud security (Azure, AWS) and Vulnerability Management
  • Expertise in frameworks like NIST CSF, ISO 27001, and CIS Controls; strong knowledge of cloud security (Azure, AWS), vulnerability management, and modern security architectures Knowledge of incident response processes.
  • Understanding of compliance standards such as PCI-DSS, GDPR, or Canadian-specific cybersecurity regulations.
  • Identify inefficiencies in processes and recommend automation or optimization.
  • Experience aligning MSSP operations with long-term cybersecurity goals.
  • Experience mentoring teams and aligning cybersecurity initiatives with organizational goals.
  • Experience managing incidents, conducting risk assessments, and overseeing audit and compliance efforts to mitigate risks.
  • Experienced in managing third-party vendors, negotiating contracts, and ensuring SLA compliance.


We offer a comprehensive suite of benefits including:
  • Health/Dental Benefits
  • Access to an Employee & Family Assistance Program
  • a Defined Benefit Pension
  • Discounts on products and services via Workperks.


Work Hours:
36.25

Union / Non-Union:
Non-Union

Job Posting End Date:
July 22, 2026

Similar Jobs

More Jobs at Liquor Control Board of Ontario

More Information Technology Jobs

Find similar Director, Cybersecurity jobs: