Associate Director, Cybersecurity


Job Location:

Toronto - Canada

Monthly Salary: Not Disclosed
Posted on: 13 hours ago
Vacancies: 1 Vacancy

Job Summary

ABOUT US

SickKids Foundation with over 50 years of philanthropic impact is Canadas largest charitable funder of child health research learning and care raising over $200 million last year. As a national charity SickKids Foundation invests in national and international initiatives to benefit children in Canada and around the world. As the fundraising partner to The Hospital for Sick Children (SickKids) we are aligned in supporting Precision Child Health (PCH) the future of tailoring medicine to each childs unique traits so SickKids can diagnose faster treat smarter and predict better.

We are driven by our core values of integrity collaboration excellence innovation and inclusion with goals of delivering a superior donor experience investing in our people and culture driving innovative and sustainable fundraising and disrupting the market through data and technology.

SickKids Foundation is committed to an inclusive culture by embedding equity diversity and inclusion in our policies practices and behaviours. We aim to build awareness and skills in this area both internally and with our partners. Our commitment extends to creating a safe positive work environment. For details on our Equity Diversity & Inclusion commitment please click here.

Were committed to attracting and retaining passionate individuals to help create a healthier future. Thats why SickKids Foundation is looking for a new Associate Director Cybersecurity.

Description of the Position

The Associate Director Cybersecurity is a senior leadership role responsible for driving hands-on security operations managing enterprise cyber risk and maturing the organizations security posture. The incumbent will lead day-to-day security monitoring and incident response activities oversee the risk register champion security awareness and ensure the organization is aligned with industry frameworks including MITRE ATT&CK and the NIST Cybersecurity Framework. The role reports to the Director Infrastructure Automation & Cybersecurity and is expected to actively leverage AI-enabled tools and automation to improve detection response and operational efficiency across the security program.

Key Responsibilities:

Security Operations (Hands-On)

  • Monitor triage and respond to security events alerts and incidents across SIEM EDR email security and WAF platforms.
  • Lead Level 2/3 incident analysis and drive root-cause investigations to resolution.
  • Maintain and tune detection rules alert thresholds and playbooks to reduce false-positive rates.
  • Administer and optimise security tooling including Imperva (WAF / Database Security) Abnormal AI (Email Security) and Sophos (EDR / Endpoint Protection).
  • Collaborate with vendors to ensure tools are current licensed and properly integrated.

Frameworks & Threat Intelligence

  • Apply MITRE ATT&CK techniques and tactics to map threat actor behaviour and improve detection coverage.
  • Align security controls and risk assessments to the NIST Cybersecurity Framework (Identify Protect Detect Respond Recover).
  • Integrate threat intelligence feeds into operational tooling to proactively identify emerging risks.

IT Risk Management

  • Maintain the IT/Cyber Risk Register identify assess score and track remediation of risks in partnership with IT legal and business stakeholders.
  • Conduct periodic risk reviews and present risk status updates to leadership and governance committees.

Security Awareness & Education

  • Design build and execute enterprise-wide Cybersecurity Awareness Campaigns across multiple channels (intranet email digital signage lunch-and-learns).

Phishing Simulation / Tabletop Exercises

  • Coordinate and execute regular phishing simulation exercises using approved simulation platforms. Analyse simulation results identify high-risk user segments and administer remedial training.
  • Coordinate the annual Cybersecurity Tabletop Exercise develop scenarios coordinate participants (IT legal HR communications executive leadership) and facilitate sessions.
  • Document lessons learned produce after-action reports and track improvement items to closure.

Cybersecurity Architecture & Policy

  • Provide input on security architecture reviews for new projects cloud deployments and third-party integrations.
  • Maintain review and update Cybersecurity Policies Standards and Procedures on a defined review cycle.

Cybersecurity Tool Management

  • Evaluate tool effectiveness identify capability gaps and make recommendations for tooling enhancements.
  • Collaborate with vendors to ensure tools are current licensed and properly integrated.

Automation & AI-Enabled Security (New)

  • Actively incorporate artificial intelligence and advanced automation into security operations including threat detection alert triage analysis and reporting to enable faster and more consistent outcomes.
  • Identify and reduce manual repetitive security tasks through automation orchestration and standardized workflows rather than increased headcount.
  • Maintain current practical expertise in AI-enabled security tooling and demonstrate personal proficiency in using these tools to accelerate analysis and decision-making.
  • Ensure AI is applied responsibly securely and in alignment with enterprise governance privacy and ethical standards.
  • Continuously evaluate emerging AI-enabled security capabilities and recommend adoption where they improve detection response time or operational efficiency.

Qualifications

  • 8 years of progressive cybersecurity experience with at least 5 years in a senior or lead role.
  • Hands-on experience in a Security Operations Centre (SOC) environment monitoring triage and incident response.
  • Demonstrated working knowledge of MITRE ATT&CK framework and NIST CSF.
  • Proven experience owning or contributing to an IT/Cyber Risk Register.
  • Experience delivering security awareness programs and phishing simulations.
  • Familiarity with security tools: Imperva Abnormal AI and Sophos (or comparable equivalents).
  • Good understanding of cybersecurity architecture principles network security and cloud security.
  • Excellent communication and stakeholder management skills ability to translate technical risk into business language.
  • Experience using automation and AI-enabled security tools to improve operational effectiveness.

Preferred

  • Nice to have CISSP CISM GIAC or equivalent.
  • Familiarity with additional frameworks: ISO 27001 SOC 2 CIS Controls.
  • Experience with SOAR platforms and automation of security workflows.
  • Post-secondary education in Computer Science Information Security or a related discipline.

Total Compensation Package

Expected Hiring Salary Range: $99297- $124121; with the ability to progress to a maximum of $142739 with demonstrated experience and proficiency. To ensure fair and equitable pay at SickKids Foundation placement on the salary range will be based on your years of experience skills and qualifications relevant to the Associate Director Cybersecurity.

To help you lead in the fight for kids health and to support your health wellness and career growth in addition to competitive compensation we offer a comprehensive benefit package (includes a flex benefit plan) tuition reimbursement flexible work arrangements pension plan and birth parent/parental top up to name a few!

Position Status: Permanent Full-Time.

Hours: Hybrid work model: minimum two days per week in-office (Tuesday and Wednesday).

Available To: Internal and External Candidates.

Available: Immediately; this posting is for an existing vacancy.

Applications will be reviewed on an ongoing basis. We encourage interested candidates to apply early.

How to apply: Please apply on-line by visiting our website: note that automated tools including artificial intelligence may be used to support the pre-screening of applications as part of our recruitment process.

SickKids Foundation is committed to its people and the talents capabilities and perspectives they bring to our mission. We live that commitment by being open and accessible to all by valuing and respecting every individual and by equally supporting every employee. As an organization proud to have joined the BlackNorth Initiatives CEO pledge we uphold our commitment by inviting and encouraging individuals from diverse lived experiences from Black Indigenous communities of colour people with disabilities 2SLGBTQIA community and all candidates who may contribute to the further diversification of the Foundations community.

Candidates who require accommodation during the recruitment process should contact the People & Culture team at:

#LI-LD1


Required Experience:

Director

ABOUT USSickKids Foundation with over 50 years of philanthropic impact is Canadas largest charitable funder of child health research learning and care raising over $200 million last year. As a national charity SickKids Foundation invests in national and international initiatives to benefit children ...