Requisition #: SNO2606
Job Category: Information Technology
Department: Information Technology
Job Type: Permanent Full Time
Standard Work Hours: 37.5 hours/week
Start Rate Amount ($/hour): 54.2993
Open Positions: 1
Job Number: J0826-0380
OVERVIEWThe Cybersecurity Lead is a senior operational leadership role responsible for guiding the development, maintenance, and maturity of the hospital's cybersecurity strategy and day to day security operations. Reporting directly to the Chief Information Security Officer (CISO), the Lead serves as the primary escalation point, mentor, and senior advisor to the cybersecurity team. This role centers on operational coordination, framework alignment, governance, and compliance. The Lead bridges the gap between tactical analyst operations and executive strategy, ensuring the analyst team is supported, initiatives are aligned with healthcare regulations (PHIPA, PHI), and the hospital's risk posture is continuously managed.
Primary ResponsibilitiesSenior Operational Support & Mentorship: Supervise, coordinate, and guide the daily workloads of the cybersecurity team. Serve as the primary escalation point for complex security events, incident triage, and difficult technical requests. Foster an inclusive, highly collaborative, and open team culture.
- Team Guidance: Supervise, coordinate, and guide the daily workloads of the cybersecurity analyst team, acting as a direct mentor and senior resource.
- Escalation Management: Serve as the primary escalation point for analysts on complex security events, incident triage, and difficult technical requests.
- Resource Coordination: Oversee operational assignments to ensure balanced workloads and adherence to security response SLAs.
- Culture Building: Foster an inclusive, highly collaborative, and psychologically safe team culture that prioritizes professional growth and peer support.
Strategic Alignment & Governance: Lead the implementation of the hospital's overarching cybersecurity strategy. Ensure policies, processes, and controls align with industry best practices (NIST CSF, ISO 27001). Collaborate with stakeholders, vendors, and regional Local Delivery Groups (LDGs) to mature the hospital's privacy and security posture.
- Strategy Execution: Lead the implementation and maintenance of the hospital's overarching cybersecurity strategy and cost-effective security operations.
- Framework Alignment: Ensure all IT security policies, processes, controls, and technology solutions align with industry best practices and security frameworks (e.g., NIST CSF, ISO 27001).
- Partnership Management: Collaborate with stakeholders, vendors, and external security teams (such as regional Local Delivery Groups and managed security service providers) to mature the hospital's privacy and security posture.
- Influential Leadership: Lead cross-functional initiatives across the hospital, driving consensus and influencing outcomes across various departments without requiring direct authority.
Risk Management & Compliance: Provide high-level security and privacy risk analysis. Ensure absolute adherence to health sector regulatory requirements (PHIPA, PIPEDA, HIPAA). Review threat and risk assessments (TRAs) and advise on secure-by-design principles for organizational projects.
- Advisory Role: Provide high-level security and privacy knowledge, risk analysis, and mitigation strategies for organizational projects.
- Regulatory Compliance: Ensure absolute adherence to health sector regulatory requirements, including PHIPA, PIPEDA, and HIPAA.
- Assessment Oversight: Review threat and risk assessments (TRAs) and privacy impact assessments, advising the team and broader IT department on secure by design principles.
Security Intelligence & Reporting: Oversee the reporting of security and vulnerability data, translating raw metrics into risk-prioritized briefings for the CISO and hospital leadership. Guide the optimization of security dashboards.
- Metric Translation: Oversee the reporting of security and vulnerability data, ensuring raw log metrics are translated into clear, non-technical, and risk-prioritized briefings for the CISO and hospital leadership.
- Dashboard Optimization: Guide the optimization of security dashboards to ensure clear visibility into the hospital's defense metrics.
Decision-Making Authority - Resource Management: Authorizes staff deployment and assignments based on daily operational needs.
- Performance Management: Responsible for assessing staff performance and initiating formal discussions with HR/Labour Relations regarding discipline or performance improvement plans.
- Operational Budgeting: Selects and recommends financial management decisions regarding security tools and team resources within standard hospital precedents.
EDUCATIONEducation: IT-related university degree or college diploma.Certifications: - IT Security Certification (e.g., CISSP, CISM, GIAC, or equivalent), ITIL Certification, and project/product management are highly preferred.
- Formal training or certifications in leadership, team supervision, or project management is highly preferred.
QUALIFICATIONS - Minimum 5 years of hands-on experience in the IT security field, with demonstrated experience in security operations, governance, and compliance.
- Proven supervisory or senior support experience; track record of leading technical teams and mentoringjunior staff.
- In depth knowledge of security principles, tools, and standards (NIST, ISO 27001).
- In depth knowledge of regulatory and industry frameworks (HIPAA, PHIPA, PIPEDA, etc.).
- Broad operational familiarity with security platforms (vulnerability scanners, access control, identity management, and threat response).
- Proven ability to lead cross-functional initiatives and influence without authority.
- Strong analytical, communication, and project management skills; ability to explain complex security risks in non-technical language.
Competencies:
• Ability to translate security risks and technical issues into non-technical language for hospital leadership.
• A team player with the ability to develop and maintain partnerships with diverse, multidisciplinary stakeholders.
- Good work and attendance record required.
- All employees of Michael Garron Hospital (MGH), a division of Toronto East Health Network
(TEHN) [formerly Toronto East General Hospital (TEGH)] agree to work within the legislated practices of the Occupational Health and Safety Act of Ontario.
- All employees of MGH are responsible to contribute to a transparent culture of patient and staff safety by adhering to and abiding by patient and staffsafety policies and procedures set by MGH.
- All employees are accountable for protecting the psychological health and safety of themselves and their co-workers through adherence to MGH's policies and practices.
Are you interested in this job?