Information Security Program Manager

Date Posted: 12/13/2023
Req ID:35383
Faculty/Division: Faculty of Applied Science & Engineering
Department: Faculty Information Technology Office
Campus: St. George (Downtown Toronto)

 

ABOUT US

The Faculty of Applied Science & Engineering is a world-renowned community of researchers and students dedicated to solving some of the world's most pressing challenges through collaborative and multidisciplinary research and experiential education. Through rigorous technical training, and unparalleled extracurricular and professional experience opportunities, we prepare the next generation of engineering leaders and changemakers to unlock the future's boundless potential.

 

The Faculty's Information Technology Office provides the vision and leadership for the development and implementation of technological information systems, processes, and associated technology to support Faculty of Applied Science and Engineering academic mission and administrative operations. The Faculty Information Technology Office is comprised of a team of highly motivated IT professionals who work collaboratively with colleagues in administrative units and academic departments across the Faculty to provide timely, quality service and innovative technological solutions.

 

YOUR OPPORTUNITY

Faculty of Applied Science and Engineering is distributed and complex, serving the needs of teaching, research and administration in academic units and institutes. Divisional and departmental IT teams are responsible for ensuring that technology is delivered and stewarded with security and risk focus and in alignment with institutional guidelines and direction.

 

Reporting to the Director, Information Technology and with input, as required, from a dotted line reporting relationship to the Chief Information Security Officer (CISO) of the University, the Information Security Program Manager provides strategic leadership and tactical planning, evaluation, design, development, implementation, and overall management and support of the Faculty’s Information Security and Risk Management Program.

 

The Manager is responsible for working with Information Technology staff and resources at the Faculty of Applied Science and Engineering and across the University to efficiently and effectively address the management, control, and protection of Digital Assets in support of Faculty’s education and research mission. The Manager is also responsible for conducting and facilitating risk and privacy assessments, overseeing maintenance of the data asset inventory, leading incident response and investigations, and ensuring on-going cybersecurity outreach. Work is done in the context of existing policy, guidelines and applicable legislation in a fluid, consultative environment.

 

The Manager works with academic departments and units across the Faculty with the aim of minimizing the risk of compromise to all Faculty’s IT services and resources, analyzing gaps and vulnerabilities, effectively solving security and privacy risk issues, integrating new systems with current systems, and initiating projects to augment and improve service delivery.

 

The Manager oversees the monitoring of cyber threats and works to ensure systems, servers and computing solutions administered by the Faculty and academic units are secure, available, and that appropriate disaster recovery and business continuity plans are in place and regularly tested.

 

The Manager collaborates with departmental and faculty-wide groups (ISTEP, Engineering Computing Facility, Engineering Career Center, Office of the Registrar, Recruitment, etc. …) to ensure that all projects containing confidential and restricted information follow the information security standards and best practices for Identity and Access Management, Information Disclosure, Information Integrity, Business Continuity and Protection of Privacy.

As the key senior project team member for major security initiatives and solutions, the Manager provides expertise at all stages of each project, from design to delivery, ensuring current, high-quality innovative and advanced solutions are being applied in accordance with service best practices, and evaluating appropriateness for final use to effectively achieve and optimize the security of services to the Faculty.

 

The Manager establishes and manages strong relationships with all levels of the FASE community including executive leadership, project teams, clients, stakeholders, and academic departments across the Faculty and the University of Toronto to promote cybersecurity awareness. Work is done in collaboration with institutional partners including other academic Divisions, IT&S, FIPP office and others.

As a member of the FASE management team, the incumbent tables proposals to augment and/or improve services delivered and participates in reviewing proposals from others. The incumbent’s in-depth technical expertise and teamwork approach to organizational issues are called upon not only in day-to-day developments but also in tactical and strategic planning efforts.

 

The Manager oversees a team of technically savvy individuals in the infrastructure unit and manages IT enterprise projects with a strong business-oriented focus. The Manager allocates project related human resources and work force planning, directing staff efforts and assigning project priorities. The Manager is responsible for financial and contract management and prepares and manages project budgets. The Manager is also responsible for the initiation and successful negotiation of a wide variety of contracts covering hardware, software, consulting and professional services, and is responsible for the management of budget expenditures and recoveries and for completing projects in a timely, accurate and cost-effective manner.

While the Manager’s primary responsibilities are centered around Information Security and IT Risk Management, the Manager will also deploy similar mechanisms and approaches to champion and progress models, templates and documentation for IT availability, business continuity, disaster recovery planning and audits.

 

The Information Security Program Manager serves on University committees, and has frequent contact with academic departments, instructors, and the research enterprise, to advise on security and privacy considerations, global threat landscape, nation state actors and cybercrime.

 

QUALIFICATIONS

EDUCATION:

University degree in Computer Science, Engineering, or an equivalent combination of education and experience. A Graduate Degree and certifications in information security and management, such as CISSP, CISM, CISA, PMP, CRISC or other relevant certifications, are an asset.

 

EXPERIENCE:

Information Security

  • At least eight (8) years of experience working in the IT industry, with a focus on information security.
  • Proven experience in planning, organizing, and developing IT security and facility security system technologies. Expert level understanding of Information Security technologies and concepts, including information security and defense solutions.
  • Experience developing and adopting information security standards and guidelines.
  • Extensive experience using network and security analysis tools, with a focus on intrusion detection and prevention – host and network, active and passive.
  • Experience managing information security incident response and investigations; demonstrated aptitude for security/or major incident management; ability to quickly analyze and interpret forensic information and evidence.
  • Excellent understanding of defense in depth strategies and implementation across the entire ecosystem (endpoints, servers, appliances, cloud, and network architecture, etc.) with strong ability to assess risks and controls of computing systems and operations.
  • Experience auditing systems for compliance (PCI-DSS, PA-DSS, etc.).

Digital Infrastructure

  • Strong understanding of IT Architecture concepts and security methodologies, with expertise in management of IT infrastructure, supporting business critical applications.
  • Substantial exposure to data processing, hardware platforms, enterprise software applications, and outsourced systems, including financial, human resources and email.
  • Experience with systems design and development from business requirements analysis through to day-to-day management.
  • Strong understanding of change and configuration management processes.
  • Experience with deployment of policies, management of resource, and security controls within cloud-based platforms (Azure, Microsoft Entra ID, etc. …).

People Management

  • At least five (5) years of experience in a team lead or senior/supervisory role.
  • Experience leading and mentoring high performing teams, with a track record of driving results through process evaluation, design, and development.
  • Experience working with a broad range of stakeholders and IT SMEs. Experience leading change and driving results through process evaluation, design, and development.

SKILLS:

  • Strong and proven managerial, relationship management and leadership skills.
  • Strong communication skills, both verbal and written.
  • Excellent project management and problem-solving skills.
  • Ability to master new technology quickly.
  • Experience negotiating purchase agreements and contracts.
  • Excellent instruction and presentation skills.
  • Able to describe a variety of complex technical concepts or policies to users and senior leadership at all technical experience levels and to deliver security awareness and education content to faculty, staff, and graduate students.

OTHER:

  • Broad knowledge of industry innovations and state-of-the-art technology in both computing and networking arenas, and in-depth knowledge of information security.
  • Familiarity with database administration and operation a plus.
  • Expedience and ability to provide support outside of normal working hours, as needed.
  • Ability to work under pressure of high volume and expectations, while meeting multiple deadlines for multiple projects.
  • Strong service orientation coupled with ability to recognize and assess the operational significance of a problem, control/mitigate the risk and set priorities accordingly.
  • Demonstrated ability to exercise sound judgment, tact, and diplomacy at all times.
  • Ability to effectively navigate a professional and political climate including assessing the requirement to escalate an issue to more senior levels of management or resources or bodies outside the Faculty.
  • Ability to maintain a high level of confidentiality.
  • A proven commitment to equity, diversity, and inclusivity.

 

This role is currently eligible for a hybrid work arrangement, pursuant to University policies and guidelines, including but not limited to the University of Toronto’s Alternative Work Arrangements Guideline.

 

Closing Date: 05/14/2024,11:59PM ET
Employee Group: Salaried 
Appointment Type: Budget - Continuing 
Schedule: Full-Time
Pay Scale Group & Hiring Zone: PM 5 -- Hiring Zone: $116,047 - $135,389 -- Broadband Salary Range: $116,047 - $193,412
Job Category: Information Technology (IT)

All qualified candidates are encouraged to apply; however, Canadians and permanent residents will be given priority.

Diversity Statement

The University of Toronto embraces Diversity and is building a culture of belonging that increases our capacity to effectively address and serve the interests of our global community. We strongly encourage applications from Indigenous Peoples, Black and racialized persons, women, persons with disabilities, and people of diverse sexual and gender identities. We value applicants who have demonstrated a commitment to equity, diversity and inclusion and recognize that diverse perspectives, experiences, and expertise are essential to strengthening our academic mission.

As part of your application, you will be asked to complete a brief Diversity Survey. This survey is voluntary. Any information directly related to you is confidential and cannot be accessed by search committees or human resources staff. Results will be aggregated for institutional planning purposes. For more information, please see http://uoft.me/UP.

Accessibility Statement

The University strives to be an equitable and inclusive community, and proactively seeks to increase diversity among its community members. Our values regarding equity and diversity are linked with our unwavering commitment to excellence in the pursuit of our academic mission.

The University is committed to the principles of the Accessibility for Ontarians with Disabilities Act (AODA). As such, we strive to make our recruitment, assessment and selection processes as accessible as possible and provide accommodations as required for applicants with disabilities.

If you require any accommodations at any point during the application and hiring process, please contact uoft.careers@utoronto.ca.


Job Segment: Program Manager, Information Security, Cloud, Facilities, Engineer, Management, Technology, Operations, Engineering