Description The
Information Technologies is currently seeking a Full-time Regular
Lead, Cybersecurity Operations.
The Security Operations team is responsible for the planning and implementation of security measures designed to protect the staff, capital assets, and proprietary information of the University by providing strategic direction, tactical management, emergency planning, and advisory services. The IT Security team provides leadership and technical guidance to both IT and Client departments on the identification and mitigation of risk. In addition, this team is the primary responder to any issue that may lead to disruptions within the organization as such they are responsible for creating and implementing processes and solutions for the detecting, investigating and mitigation of security incidents that could impact the University.
The position reports to the Manager, Cybersecurity Operations. The position works 35 hours per week, with normal business hours being 8:30 - 4:30, Monday to Friday. The position is subject to high stress and requires balancing multiple priorities with tight deadlines. There may be a requirement for after-hours work, depending on the nature of the projects, operations, and initiatives currently underway.
Summary of Key Responsibilities (job functions include but are not limited to):
Requirements Gathering
- Work with customers, IT Partners, Project Managers, and representatives from various faculties/departments on campus to understand cyber security requirements or issues
- Researching and defining cyber security operating procedures
Project Management/Leadership
- Work with the leadership team to build annual goals and objectives for themselves and their staff
- Full managerial discretion for direct reports including recruitment, onboarding, professional development, coaching, up to and including discipline and termination
- Lead as an escalation point and organize the team through challenging cybersecurity events with the goal of root cause determination and build a remediation plan to resolve issues
- Work with the architecture or project teams to build tasks, and track the work required for the security items on projects to ensure timely completion of deliverables from their team
- Ensure all systems are aligned with the IT's standards and roadmaps
- Actively participate in assigned projects delivering consulting, installation and support services
- Contribute to the success of project deployment in cyber security operations
- Organize and lead vulnerability management and incident response processes
- Operational upgrades coordination and implementation for security operational products
- Lifecycle management of hardware and software assets
- Oversight of managed security services providers
- Provides briefings to leadership on major new technologies, issues, and changes that impact cyber risks
- Planning for future technology shifts and upgrades
- Support security architecture practices related to cyber security operational technology including but not limited to vulnerability management, incident response, IDS/IPS, SIEM, network topology, network security, Operating system security, identity and access management, etc
- Managing licensing related to functional area of responsibility
- Work independently with guidance to plan projects, solve problems and prioritize competing tasks for themselves and direct reports
- Ability to identify and generate executive summaries on key performance indicators for Security Operations activities
- Participate in on-site network and security audits related to PCI, SOX, etc. for effective vulnerability, security event and incident management
Documentation
- Responsible for ensuring all documentation is detailed, accurate, timely, and meets the requirements of the project stakeholders and operational excellence. These documents may include, but are not limited to:
- Consolidated design, showing both logical and physical layout
- Security vulnerability management SOPs
- Standard operating procedures for daily activities
- Security security application setup and configuration
- Service catalog request items
- Security Incident handling and tracking
- Release documentation
- Support documentation, FAQs, known issues, errors
- Requests for Change
- CMDB add/change/remove data
- Develop and train others on technical documentation, standards and guidelines
Technical Leadership
- Administer and provide technical support for primarily vulnerability management and incident response, could also manage SIEM, PAM, other security tools for forensics, etc
- Design and develop new technologies that align with vendor roadmaps or future trends in the industry that apply to the server infrastructure environment
- Lead the cyber security process using their own technical expertise and challenge the team members on their technical recommendations where needed and appropriate
- Lead technology roadmap sessions and work with IT Architecture to develop new standards to drive innovation in the cyber security service realm
- Take on responsibility for self-study and learning to remain well-versed in a wide range of security technologies and systems
- Build and ensure staff follow technical documentation, standards and guidelines
- Provide cyber security guidance and escalation to direct reports and operational teams
- Taking corrective action to ensure confidentiality, integrity and availability of services to minimize downtime to the operations environment
- Drawing on experience and knowledge of Enterprise IT environment to propose a temporary work-arounds with aim of mitigating impact to production system if security issues arise
- Build the procedures to effectively remediate and manage vulnerabilities and security incidents with the intent of minimizing the business impact and restoring operational capabilities as soon as possible in conjunction with the operations team
- Develop administrative, technical and physical controls ensuring the confidentiality, integrity and availability of the operations environment
- Work with the architecture or project teams to build tasks, and track the work required for the security items on projects to ensure timely completion of deliverables from their team
- Operational upgrades coordination and implementation
- Lifecycle management of hardware and software assets for all security products
Qualifications / Requirements:- University degree or professional certification such as CISSP, CISM, CISA, GIAC, CEH, etc required
- Minimum of 5-7 years of recent related experience equivalent to the above
- Minimum 2 years of supervisory experience required
- Knowledge of published security and privacy standards (ISO, NIST, PCI, PIPA)
- Field experience with cyber security incident management processes
- Knowledge of cyber security technologies including SIEM, IDS/IPS, Vulnerability management, etc
- Knowledge of network technologies such as DNS, DHCP, TCP/IP, routing, firewalls
- Knowledge of operating systems technologies
- In depth knowledge of cyber security processes, tools and frameworks
- In depth knowledge of incident response and investigative procedures
- In depth knowledge of security tools including Threat Detection, vulnerability management, IPS/IDS, Certificate Services, End Point Protection, Web application firewalls and SIEM technologies
- Knowledge of Identity Access Management
- Broad knowledge of enterprise systems, operating systems, and hardware platforms
- Broad knowledge of storage technologies, local storage, Arrays, SAN's, IP-Storage, NAS, File Systems
- Broad Knowledge of Cloud and on-premise infrastructure as well as application infrastructure
- Expected to have a working knowledge of a wide range of cyber security, server, storage, applications, and network systems
- Physical and Virtual server knowledge and skillset
- Ability to raise, facilitate, escalate and resolve security events
- Ability to communicate clearly and concisely to diverse audiences, in both oral and written form
- Capable of working on concurrent projects and managing conflicting priorities
- Ability to translate technical jargon into business-friendly language
- Working knowledge of Microsoft security products
- ITIL Foundations certification is an asset
Application Deadline: August 26, 2026
This position is classified in the
Management & Professional Career Band, Level P4 of the Management and Professional Staff Career Framework.
For a listing of all management and staff opportunities at the University of Calgary, view our
Management and Staff Careers website .