Job ID: COT-2023-18
Job Title: Senior Specialist Cyber Security
Division: Office of the Chief Information Security Officer
Reports To: Manager Cyber Security
Salary Range: $122,000 to $158,105
Work Location: 55 John Street, Toronto
Job Type: Full Time, Temporary, 36 months
Shift Information: Monday to Friday, 35 hours work week
To support the execution of the Chief Information Security Officer’s (CISO) mandate, cyber vision and strategy, providing strategic business advice, senior level guidance, technical and operational support and services on Business Application Resilience cyber programs and initiatives to all City divisions, agencies and corporations.
To define, develop and support Business Application Resilience cyber programs and initiatives and to engage with teams across the organization to build alignment on key projects and initiatives and develop execution roadmaps.
- Develops and implements detailed plans and recommends cyber security policies/procedures regarding program specific requirements.
- Provides subject matter expertise and strategic advice on cyber security issues affecting the organization, identifying potential exposures, and conducting reviews to ensure that undesirable effects are detected, mitigated and/or corrected, and providing pragmatic advice to clients to ensure that cyber risks are managed appropriately.
- Determines cyber security requirements of business strategies to provide appropriate advice, guidance, and technical solutions.
- Takes a proactive approach to identify gaps and opportunities for improvement to mitigate risk.
- Supports operational security activities including oversight of ongoing segment specific security processes (e.g., incident response, ad hoc queries, periodic access reviews, and vulnerability management).
- Post-secondary degree in Business or Technology or a related discipline.
- Extensive experience in business application protection.
- Extensive experience in Cyber Security.
- Experience with circulation and commenting software.
- Extensive experience with security evaluation/analysis within a technical organization
- Extensive experience with a combination of relevant technical disciplines in the field of Information
- Security and Information Risk Management.
- Extensive experience in conducting risk assessments, required controls definition, control procedure appropriateness, security capabilities identification.
- Extensive experience applying security frameworks (e.g. ISO 27001, COBIT), laws and standards (e.g. NIST, GDPR, etc.)
- Preferred Certifications (any in the list): CISSP, CISM, CRISC
- Ability to work in transformative programs.
- Ability to lead efficient communication between all project stakeholders, including internal teams and clients
- Ability to achieve business objectives through influencing and effectively working with key stakeholders.
- Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership and vendors.
- Excellent problem-solving skills with capability to identify solutions to unusual and complex problems.
- Keen attention to detail and strong organizational skills.
- Highly organized, proactive, self-motivated team player who takes initiative and is able to work independently.
- Ability to work in a fast-paced environment managing multiple priorities with proven time management skills.
- Strong analytical skills and ability to prioritise and multitask.
- Ability to prioritize and effectively manage competing priorities and projects.
- Ability to manage multiple initiatives while adhering to strict deadlines.
- Able to work extremely well under pressure while maintaining a high level of professionalism
- Self-motivated person with desire to go above and beyond tasks
- Transferable skills, like communication and decision-making, are equally important.
- Being able to think on your feet and show good judgment are especially valuable in this field. “Security pros should always be ready to react to cyber-related incidents quickly.
A normal work week is 35 hours, however, unforeseen situation may require extended hours of work with little or no prior notice. In case of a cyber incident or breach, rotation shift, continuous extended hours may be required with little or no prior notice.
*Subject to a police check, background check, psychological assessment and/or any other checks on a regular basis as the Office of the CISO handles highly sensitive and confidential information.
Equity, Diversity and Inclusion
The City is an equal opportunity employer, dedicated to creating a workplace culture of inclusiveness that reflects the diverse residents that we serve. Learn more about the City’s commitment to employment equity.
The City of Toronto is committed to creating an accessible and inclusive organization. We are committed to providing barrier-free and accessible employment practices in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Should you require Code-protected accommodation through any stage of the recruitment process, please make them known when contacted and we will work with you to meet your needs. Disability-related accommodation during the application process is available upon request. Learn more about the City’s Hiring Policies and Accommodation Process.
If this role is of interest to you, please submit your resume to firstname.lastname@example.org.