Competition NumberREQ 7210TitleManager, Cyber SecurityDivisionInformation TechnologySalaryPayband 11, $104,000 to $122,385 annuallyHours per week37.5Location51 Dockside DriveWork ModalityHybridStatusContractAdminVacancyReplacementEffective dateImmediately to 1 yearInternal closing dateOpen until filledEquity StatementGeorge Brown Polytechnic is committed to creating and sustaining an equitable and inclusive learning and working environment. We encourage and actively seek applications from Indigenous, Black, racialized people, visible minorities, 2SLGBTQIA+ persons, all genders, and persons with disabilities.Position DescriptionReporting to the Executive Director, Cyber Security and IT Infrastructure Services, the Cyber Security Manager supports the continued maturity of the Cyber Security program at GeorgeBrown Polytechnic (GBP). The role serves as a key liaison between the Executive Director’s strategic and process-driven initiatives and the Cyber Security team’s operational and technical work.The Cyber Security Manager partners with ITS and external service providers to develop and maintain a cybersecurity service delivery roadmap and leads the design and implementation of appropriate security controls, processes, and protocols. The role oversees day-to-day cybersecurity operations, including the ongoing review and enhancement of security controls, and provides recommendations to strengthen GBP’s security posture in alignment with the Polytechnic’s risk appetite.Working closely with internal IT teams and external vendors/service providers, the Cyber Security Manager prioritizes security initiatives, coordinates responses to security incidents, and ensures compliance with GBP’s cybersecurity governance framework.Key ResponsibilitiesLeads the ongoing enhancement and maturity of the Polytechnic’s Cyber Security program, aligning initiatives with institutional priorities and risk management objectives.Leads the maturity of the Cyber Security risk management program in alignment with the Enterprise Risk Management (ERM) function.Develops and implements preventive, detective, and corrective controls to mitigate identified Cyber Security risks.Owns and manages the relationship with the Managed Security Service Provider (MSSP), including oversight of service delivery and roadmap alignment.Leads the development and implementation of Cyber Security policies, standards, procedures,
and guidelines.Facilitates cross-functional workgroups with ITS, system owners, data custodians, and governance stakeholders to ensure engagement, accountability, and effective management of technology and information security.Ensures enforcement of IT security policies across the Polytechnic, including ITS, and develops metrics and reporting mechanisms to support compliance monitoring.Reports to senior management on Cyber Security posture, compliance status, emerging risks, and mitigation strategies.Oversees key security management programs, including patch management, configuration management, data inventory, and vulnerability management.Collaborates with ITS and other Polytechnic staff to identify and implement approved security tools and technologies that monitor the environment and detect potential breaches, vulnerabilities, or misuse of technology and information assets.Develops and implements processes for incident response, breach investigation, and the management of security-related complaints or concerns from internal and external stakeholders.Serves as the central point of contact and escalation for cybersecurity-related issues across the Polytechnic.Leads the development and delivery of the Security Education, Training, and Awareness (SETA) program, including strategic planning, implementation, monitoring, and continuous improvement of awareness initiatives.Provides Cyber Security advisory services to ITS and Polytechnic departments/divisions, offering guidance on information security best practices and frameworks, including ISO 27001, CIS, and NIST.Represents the Polytechnic in relevant security-related industry workgroups and committees to stay informed of emerging threats, trends, and best practices.Other duties as assigned.Educational and Experience RequirementsFour-year degree from a recognized post-secondary institute in Information Security, Cyber Security, Information Technology, or equivalent work experience.Certifications in one or more of the following are required: CISSP, CCSP, CISM, Security+, or Microsoft certification in the areas of security design, implementation,
or administration.Minimum five (5) years of demonstrated experience in incident investigation, containment, and timely resolution.Experience in incident handling and effective communication on Cyber Security/IT/information security breaches within a large institutional setting, ideally within an academic, unionized environment.Experience in developing, implementing, and maintaining Cyber Security policies, procedures, standards, and guidelines.Demonstrated success in planning, procuring, implementing, testing, and monitoring enterprise information security solutions.Experience working with and managing servers, endpoints, configuration management (baselining), cloud infrastructure, endpoint and network security assessments, systems administration, network operations, and stakeholder support.Leading asset inventory, configuration management, change control, and inventory of critical applications, data, and business processes.Awareness of networking concepts and data centre operations (on-prem and cloud).Demonstrated experience in educating and heightening awareness of Cyber Security.Skills and AttributesExcellent interpersonal and communication skills and the ability to work effectively with, engage, and influence a wide range of stakeholders/constituents in a large, multi-site, diverse community.Proven ability to mediate and resolve conflicts and find solutions in a collaborative workplace.Well-developed analytical, problem-solving, and evaluation skills, with experience leading complex Cyber Security projects and teams.Broad leadership skills in managing a diverse team of experienced Cyber Security and IT professionals.Demonstrated commitment to uphold the Polytechnic’s priorities on diversity and equity.Interview process may consist of a practical skills component.NotesThe Polytechnic requires proof of degrees, credentials, or equivalencies from accredited regional or federal post-secondary institutions and/or their international equivalents. Credentials may require validation at the time of interviews or offer.George Brown Polytechnic is committed to accommodating applicants with disabilities throughout the hiring process, in accordance with the Accessibility for Ontarians with Disabilities Act (AODA). Candidates who require accommodation in the hiring process may contact
[email protected] confidentially.#J-18808-Ljbffr
📌 Manager, Cyber Security - C$104,000 - C$122,385 A Year (Winnipeg)
🏢 George Brown Polytechnic
📍 Winnipeg