Lead, Cybersecurity

Michael Garron Hospital / Toronto East Health Network

$113K *
Hospitals & Medical Centers
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 5 years of hands-on experience in IT security with a focus on security operations, governance, and compliance.
  • Proven experience in a supervisory or senior support role leading technical teams.
  • In-depth knowledge of security principles and frameworks (NIST, ISO 27001).
  • Familiarity with regulatory and industry compliance (HIPAA, PHIPA, PIPEDA).
  • Experience with various security platforms, including vulnerability scanners and threat response systems.
  • Ability to influence cross-functional teams without direct authority.
  • Strong analytical and communication skills with a talent for simplifying complex security concepts.

Responsibilities

  • Supervise and guide daily workloads of the cybersecurity analyst team as a mentor.
  • Manage complex security incidents and act as the primary escalation point for team members.
  • Oversee operational assignments to balance workloads in line with security response SLAs.
  • Foster an inclusive and collaborative team culture that prioritizes professional growth.
  • Lead the implementation of the hospital's overarching cybersecurity strategy.
  • Ensure IT security policies align with best practices and security frameworks.
  • Collaborate with various stakeholders to enhance the hospital's privacy and security posture.

Benefits

  • Permanent full-time position with a standard 37.5 hours workweek.
  • Opportunity for mentorship and leadership development in a senior role.
  • Access to professional growth and team collaboration initiatives.
  • Contributions toward a transparent culture of patient and staff safety.
  • Compliance with Occupational Health and Safety practices.
  • Support for psychological health and safety in the workplace.
Full Job Description
Requisition #:

SNO2606

Job Category:

Information Technology

Department:

Information Technology

Job Type:

Permanent Full Time

Standard Work Hours:

37.5 hours/week

Start Rate Amount ($/hour):

54.2993

Open Positions:

1

Job Number:

J0826-0380

OVERVIEW

The Cybersecurity Lead is a senior operational leadership role responsible for guiding the development, maintenance, and maturity of the hospital's cybersecurity strategy and day to day security operations. Reporting directly to the Chief Information Security Officer (CISO), the Lead serves as the primary escalation point, mentor, and senior advisor to the cybersecurity team. This role centers on operational coordination, framework alignment, governance, and compliance. The Lead bridges the gap between tactical analyst operations and executive strategy, ensuring the analyst team is supported, initiatives are aligned with healthcare regulations (PHIPA, PHI), and the hospital's risk posture is continuously managed.

Primary Responsibilities

Senior Operational Support & Mentorship: Supervise, coordinate, and guide the daily workloads of the cybersecurity team. Serve as the primary escalation point for complex security events, incident triage, and difficult technical requests. Foster an inclusive, highly collaborative, and open team culture.
  • Team Guidance: Supervise, coordinate, and guide the daily workloads of the cybersecurity analyst team, acting as a direct mentor and senior resource.
  • Escalation Management: Serve as the primary escalation point for analysts on complex security events, incident triage, and difficult technical requests.
  • Resource Coordination: Oversee operational assignments to ensure balanced workloads and adherence to security response SLAs.
  • Culture Building: Foster an inclusive, highly collaborative, and psychologically safe team culture that prioritizes professional growth and peer support.

Strategic Alignment & Governance: Lead the implementation of the hospital's overarching cybersecurity strategy. Ensure policies, processes, and controls align with industry best practices (NIST CSF, ISO 27001). Collaborate with stakeholders, vendors, and regional Local Delivery Groups (LDGs) to mature the hospital's privacy and security posture.
  • Strategy Execution: Lead the implementation and maintenance of the hospital's overarching cybersecurity strategy and cost-effective security operations.
  • Framework Alignment: Ensure all IT security policies, processes, controls, and technology solutions align with industry best practices and security frameworks (e.g., NIST CSF, ISO 27001).
  • Partnership Management: Collaborate with stakeholders, vendors, and external security teams (such as regional Local Delivery Groups and managed security service providers) to mature the hospital's privacy and security posture.
  • Influential Leadership: Lead cross-functional initiatives across the hospital, driving consensus and influencing outcomes across various departments without requiring direct authority.

Risk Management & Compliance: Provide high-level security and privacy risk analysis. Ensure absolute adherence to health sector regulatory requirements (PHIPA, PIPEDA, HIPAA). Review threat and risk assessments (TRAs) and advise on secure-by-design principles for organizational projects.
  • Advisory Role: Provide high-level security and privacy knowledge, risk analysis, and mitigation strategies for organizational projects.
  • Regulatory Compliance: Ensure absolute adherence to health sector regulatory requirements, including PHIPA, PIPEDA, and HIPAA.
  • Assessment Oversight: Review threat and risk assessments (TRAs) and privacy impact assessments, advising the team and broader IT department on secure by design principles.

Security Intelligence & Reporting: Oversee the reporting of security and vulnerability data, translating raw metrics into risk-prioritized briefings for the CISO and hospital leadership. Guide the optimization of security dashboards.
  • Metric Translation: Oversee the reporting of security and vulnerability data, ensuring raw log metrics are translated into clear, non-technical, and risk-prioritized briefings for the CISO and hospital leadership.
  • Dashboard Optimization: Guide the optimization of security dashboards to ensure clear visibility into the hospital's defense metrics.

Decision-Making Authority
  • Resource Management: Authorizes staff deployment and assignments based on daily operational needs.
  • Performance Management: Responsible for assessing staff performance and initiating formal discussions with HR/Labour Relations regarding discipline or performance improvement plans.
  • Operational Budgeting: Selects and recommends financial management decisions regarding security tools and team resources within standard hospital precedents.

EDUCATION

Education: IT-related university degree or college diploma.

Certifications:
  • IT Security Certification (e.g., CISSP, CISM, GIAC, or equivalent), ITIL Certification, and project/product management are highly preferred.
  • Formal training or certifications in leadership, team supervision, or project management is highly preferred.

QUALIFICATIONS

  • Minimum 5 years of hands-on experience in the IT security field, with demonstrated experience in security operations, governance, and compliance.
  • Proven supervisory or senior support experience; track record of leading technical teams and mentoringjunior staff.
  • In depth knowledge of security principles, tools, and standards (NIST, ISO 27001).
  • In depth knowledge of regulatory and industry frameworks (HIPAA, PHIPA, PIPEDA, etc.).
  • Broad operational familiarity with security platforms (vulnerability scanners, access control, identity management, and threat response).
  • Proven ability to lead cross-functional initiatives and influence without authority.
  • Strong analytical, communication, and project management skills; ability to explain complex security risks in non-technical language.

Competencies:
• Ability to translate security risks and technical issues into non-technical language for hospital leadership.
• A team player with the ability to develop and maintain partnerships with diverse, multidisciplinary stakeholders.

- Good work and attendance record required.
- All employees of Michael Garron Hospital (MGH), a division of Toronto East Health Network
(TEHN) [formerly Toronto East General Hospital (TEGH)] agree to work within the legislated practices of the Occupational Health and Safety Act of Ontario.
- All employees of MGH are responsible to contribute to a transparent culture of patient and staff safety by adhering to and abiding by patient and staffsafety policies and procedures set by MGH.
- All employees are accountable for protecting the psychological health and safety of themselves and their co-workers through adherence to MGH's policies and practices.

Are you interested in this job?

Similar Jobs

More Jobs at Michael Garron Hospital / Toronto East Health Network

More Hospitals & Medical Centers Jobs

Find similar Lead, Cybersecurity jobs: