- Company Name
- Legislative Assembly of Ontario / Assemblée législative de l’Ontario
- Job Title
- Manager, Information Security
- Job Description
-
**Job Title**
Manager, Information Security
**Role Summary**
Leads the development, implementation, and governance of the organization’s information and cybersecurity strategy. Oversees policy creation, risk‑based metrics, incident response, and security operations while aligning security initiatives with business objectives and stakeholder requirements. Manages an internal team and a Managed Security Service Provider (MSSP) to deliver effective security services for the Legislative Assembly.
**Expectations**
- Minimum 7 years of hands‑on experience in information and cyber security, including strategy design, implementation, and monitoring.
- Proven ability to provide strategic guidance and develop enterprise‑wide security policies, standards, and training programs.
- Demonstrated expertise in KPI/metric development, performance reporting, and ROI tracking for security investments.
- Strong leadership skills to motivate and manage security professionals and external service providers.
- Ability to collaborate across IT, executive leadership, and legislative stakeholders to ensure alignment with risk posture and business goals.
**Key Responsibilities**
- Create and maintain the overall information and cybersecurity strategy, governance framework, and related policies, procedures, and standards.
- Develop and maintain operational metrics, dashboards, and scorecards; define actionable KPIs and track ROI of security initiatives.
- Lead incident response activities, ensuring compliance with the Assembly’s strategic plan and stakeholder requirements.
- Partner with the Director to align the security roadmap with business objectives and desired risk posture.
- Design and deliver comprehensive security awareness and training programs.
- Coordinate with IT and other internal teams to implement and operate the security operations service, including vulnerability management, threat intelligence, event management, and SOC functions.
- Manage and motivate an internal security team and MSSP, overseeing day‑to‑day SOC and SIEM operations.
- Implement a co‑managed SIEM solution, integrating internal and third‑party data sources across the enterprise.
**Required Skills**
- Deep technical and operational knowledge of cyber security disciplines: vulnerability management, access management, cloud security, risk management, security operations, and incident response.
- Familiarity with security frameworks such as NIST Cybersecurity Framework (CSF).
- Experience with SIEM technologies and SOC management.
- Strong analytical skills for metric and KPI development; proficiency in reporting and dashboard creation.
- Excellent communication and stakeholder management abilities.
- Leadership and team‑building capabilities, including experience managing external service providers.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field (or equivalent experience).
- Relevant professional certifications preferred (e.g., CISSP, CISM, CISA, CEH, or similar).