Security Advisor, Governance, Risk and Compliance

Toronto Community Housing Corporation

$107K — $128K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Undergraduate degree in Information Technology, Computer Science, Engineering, Business, or related field.
  • One or more security certifications in good standing (e.g., CEH, CISSP, CompTIA CySA+).
  • 5+ years of progressive information security experience in an enterprise environment.
  • Minimum 2 years in an information security position within a medium to large organization.
  • Experience conducting cyber risk assessments and producing risk reports for management audiences.
  • Excellent written and verbal communication skills for diverse audiences.
  • Ability to build effective relationships and drive positive change.

Responsibilities

  • Lead governance of the vulnerability management (VM) framework and lifecycle.
  • Oversee asset scanning across IT, cloud, and applications.
  • Analyze and prioritize vulnerabilities based on business impact.
  • Coordinate with remediation teams to track and validate patching efforts.
  • Produce executive-level metrics and reports on cyber risk exposure.
  • Engage in incident response processes related to information security.
  • Participate in enhancing TCHC's cybersecurity posture through continuous improvement.

Benefits

  • Full-time permanent position with job security.
  • Hybrid work environment offers flexible working arrangements.
  • Engagement with stakeholders at all levels within the organization.
  • Opportunity to impact organizational cybersecurity strategy and posture.
  • Professional development opportunities in the field of information security.
Full Job Description
Job #:

10836

Division:

Information Technology Services

Affiliation:

Non-Union: Management & Exempt

Vacancy Type:

Full-time Permanent

Grade:

07

Contract Length:

Salary/Hourly Range:

107,358 - 128,830

Work Details (Days/hours):

Monday to Friday, 36.5 hours/week

Hiring range/wage:

107,358 - 118,094

Existing/New Job:

Existing

Vacancy Status:

Existing Vacancy

# of Vacancies:

1

Posted Date:

7/17/26

Deadline to Apply:

7/31/26

Hybrid Eligible:

Yes

Reporting to the Senior Manager, Governance, Risk and Compliance (GRC), the Security Advisor is responsible for establishing and governing a risk-based vulnerability management lifecycle covering identification, assessment, prioritization, remediation tracking, validation, reporting, and continuous improvement. The position translates technical vulnerabilities into business risk, ensures SLA/SLO adherence, manages exception and risk acceptance processes, and delivers executive-level reporting on cyber risk exposure.

Key areas of focus include:
  • Participate in security assessments on our in-house developed products as well as procured products.
  • Participate in the planning and design of enterprise security architecture, where appropriate.
  • Ensure vulnerability scans are scheduled and cover all in-scope assets.
  • Review vulnerability findings to confirm accuracy and remove false positives.
  • Apply risk-based prioritization to vulnerabilities using severity, exploitability, and business impact.
  • Track vulnerabilities through the full lifecycle from identification to closure and coordinate with IT, cloud, and application teams to clarify findings and confirm remediation actions.
  • Validate that vulnerabilities have been resolved by reviewing evidence and confirming re-scan results.
  • Identify recurring vulnerabilities or systemic issues such as patching gaps or misconfigurations.
  • Participate in the information security incident response process and support communication of TCHC's cybersecurity program.
  • Knowledge of legislation (MFIPPA), regulations, policies, procedures, interpretations and apply applicable orders of the Information and Privacy Commissioner of Ontario.

The incumbent will work with a high degree of autonomy, engaging with stakeholders at all levels within TCHC and contributing to the continuous improvement of TCHC's cyber security posture.

What you'll do
  • Enterprise VM Governance & Leadership
  • Establish and govern VM framework, standards, procedures and lifecycle
  • Align VM program to IT and Cyber strategy
  • Monitor SLA, escalation and risk acceptance governance
  • Provide advisory to IT and business teams
  • Vulnerability Identification & Assessment
  • Oversee scanning across IT, OT, cloud and applications
  • Ensure asset coverage and scan completeness
  • Analyze vulnerabilities and assess business impact
  • Support Pen testing exercises
  • Risk Prioritization & Remediation Oversight
  • Develop prioritization models (CVSS + business context)
  • Coordinate with remediation teams
  • Track SLA adherence and escalate issues
  • Validate remediation through rescans
  • Improve scanning quality and reduce false positives
  • Conduct root cause analysis
  • Maintain vulnerability register and exceptions
  • Report KPIs (MTTR, SLA, backlog)
  • Produce executive dashboards including reporting, Metrics & KPIs
  • Ensure alignment to NIST, ISO and policies
  • Maintain procedures and documentation
  • Participates in after-hours and on-call schedule

What you'll need
  • Undergraduate degree (or equivalent experience) in Information Technology, Computer Science, Engineering, Business, or a related field. Information security-specific coursework is an asset.
  • One or more security certifications in good standing, including but not limited to: CEH (Certified Ethical Hacker), EC-Council ECSA, GIAC/SANS certifications, CompTIA CySA+, CISSP, CCSK, or industry equivalents.
  • 5+ years of progressive information security experience in an enterprise environment including security program development, risk and vulnerability analyses, system design, and security architecture.
  • Minimum 2 years in an information security position within a medium to large organization.
  • Demonstrated experience conducting cyber risk assessments, maintaining risk registers, and producing risk reports for management audiences.
  • Exposure to security operations activities including SIEM, EDR, vulnerability management, or incident response support.
  • Demonstrable experience conducting security reviews, implementing information security recommendations, analyzing technical controls, and applying security control standards.
  • Experience working within regulatory or legislative compliance environments (MFIPPA, PIPEDA, or equivalent privacy legislation is an asset).
  • Experience working on solutions that support verticals such as government, finance, human resources, and information management is preferred.
  • Excellent written and verbal communication skills; ability to produce high-quality policies, reports, and proposals for both technical and non-technical audiences.
  • Ability to build effective working relationships with internal and external stakeholders and to affect change in a positive and constructive manner.

Nice to have:
  • Experience with vulnerability management platforms (e.g., Tenable, CrowdStrike, Zscaler, or similar).
  • Familiarity with cloud security principles and hybrid infrastructure risk considerations.
  • Experience with threat intelligence platforms and threat hunting methodologies.
  • Experience with threat intelligence platforms and contextualized risk prioritization methodologies.
  • Exposure to security investigation or digital forensics activities in an enterprise environment.
  • Additional security industry certifications or vendor-specific security product certifications would be considered an asset

What's next

Once you apply, we'll review your resume and contact you if we believe your skills and experience will make you successful in the role. If you are selected to move forward, the process will include one or more interviews and/or assessments and reference checks.

INDS

Similar Jobs

More Jobs at Toronto Community Housing Corporation

More Information Technology Jobs

Find similar Security Advisor, Governance, Risk and Compliance jobs: