Back to jobs

Associate Director, Cybersecurity

Hybrid / CanadaFull timeDirector
Apply

About the role

About Us

SickKids Foundation, with over 50 years of philanthropic impact is Canada's largest charitable funder of child health research, learning and care, raising over $200 million last year. As a national charity, SickKids Foundation invests in national and international initiatives to benefit children in Canada and around the world. As the fundraising partner to The Hospital for Sick Children (SickKids), we are aligned in supporting Precision Child Health (PCH), the future of tailoring medicine to each child's unique traits so SickKids can diagnose faster, treat smarter, and predict better.

We are driven by our core values of integrity, collaboration, excellence, innovation, and inclusion, with goals of delivering a superior donor experience, investing in our people and culture, driving innovative and sustainable fundraising, and disrupting the market through data and technology.

SickKids Foundation is committed to an inclusive culture by embedding equity, diversity and inclusion in our policies, practices, and behaviours. We aim to build awareness and skills in this area, both internally and with our partners. Our commitment extends to creating a safe, positive work environment. For details on our Equity, Diversity & Inclusion commitment, please click here.

We’re committed to attracting and retaining passionate individuals to help create a healthier future. That’s why SickKids Foundation is looking for a new Associate Director, Cybersecurity.

Description Of The Position

The Associate Director, Cybersecurity is a senior leadership role responsible for driving hands-on security operations, managing enterprise cyber risk, and maturing the organization's security posture. The incumbent will lead day-to-day security monitoring and incident response activities, oversee the risk register, champion security awareness, and ensure the organization is aligned with industry frameworks including MITRE ATT&CK and the NIST Cybersecurity Framework. The role reports to the Director, Infrastructure, Automation & Cybersecurity and is expected to actively leverage AI-enabled tools and automation to improve detection, response, and operational efficiency across the security program.

Key Responsibilities

Security Operations (Hands-On)

  • Monitor, triage, and respond to security events, alerts, and incidents across SIEM, EDR, email security, and WAF platforms.
  • Lead Level 2/3 incident analysis and drive root-cause investigations to resolution.
  • Maintain and tune detection rules, alert thresholds, and playbooks to reduce false-positive rates.
  • Administer and optimise security tooling including Imperva (WAF / Database Security), Abnormal AI (Email Security), and Sophos (EDR / Endpoint Protection).
  • Collaborate with vendors to ensure tools are current, licensed, and properly integrated.

Frameworks & Threat Intelligence

  • Apply MITRE ATT&CK techniques and tactics to map threat actor behaviour and improve detection coverage.
  • Align security controls and risk assessments to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
  • Integrate threat intelligence feeds into operational tooling to proactively identify emerging risks.

IT Risk Management

  • Maintain the IT/Cyber Risk Register — identify, assess, score, and track remediation of risks in partnership with IT, legal, and business stakeholders.
  • Conduct periodic risk reviews and present risk status updates to leadership and governance committees.

Security Awareness & Education

  • Design, build, and execute enterprise-wide Cybersecurity Awareness Campaigns across multiple channels (intranet, email, digital signage, lunch-and-learns).

Phishing Simulation / Tabletop Exercises

  • Coordinate and execute regular phishing simulation exercises using approved simulation platforms. Analyse simulation results, identify high-risk user segments, and administer remedial training.
  • Coordinate the annual Cybersecurity Tabletop Exercise — develop scenarios, coordinate participants (IT, legal, HR, communications, executive leadership), and facilitate sessions.
  • Document lessons learned, produce after-action reports, and track improvement items to closure.

Cybersecurity Architecture & Policy

  • Provide input on security architecture reviews for new projects, cloud deployments, and third-party integrations.
  • Maintain, review, and update Cybersecurity Policies, Standards, and Procedures on a defined review cycle.

Cybersecurity Tool Management

  • Evaluate tool effectiveness, identify capability gaps, and make recommendations for tooling enhancements.
  • Collaborate with vendors to ensure tools are current, licensed, and properly integrated.

Automation & AI-Enabled Security (New)

  • Actively incorporate artificial intelligence and advanced automation into security operations, including threat detection, alert triage, analysis, and reporting, to enable faster and more consistent outcomes.
  • Identify and reduce manual, repetitive security tasks through automation, orchestration, and standardized workflows rather than increased headcount.
  • Maintain current, practical expertise in AI-enabled security tooling and demonstrate personal proficiency in using these tools to accelerate analysis and decision-making.
  • Ensure AI is applied responsibly, securely, and in alignment with enterprise governance, privacy, and ethical standards.
  • Continuously evaluate emerging AI-enabled security capabilities and recommend adoption where they improve detection, response time, or operational efficiency.

Qualifications

  • 8+ years of progressive cybersecurity experience, with at least 5 years in a senior or lead role.
  • Hands-on experience in a Security Operations Centre (SOC) environment — monitoring, triage, and incident response.
  • Demonstrated working knowledge of MITRE ATT&CK framework and NIST CSF.
  • Proven experience owning or contributing to an IT/Cyber Risk Register.
  • Experience delivering security awareness programs and phishing simulations.
  • Familiarity with security tools: Imperva, Abnormal AI, and Sophos (or comparable equivalents).
  • Good understanding of cybersecurity architecture principles, network security, and cloud security.
  • Excellent communication and stakeholder management skills — ability to translate technical risk into business language.
  • Experience using automation and AI-enabled security tools to improve operational effectiveness.

Preferred

  • Nice to have CISSP, CISM, GIAC or equivalent.
  • Familiarity with additional frameworks: ISO 27001, SOC 2, CIS Controls.
  • Experience with SOAR platforms and automation of security workflows.
  • Post-secondary education in Computer Science, Information Security, or a related discipline.

Total Compensation Package

Expected Hiring Salary Range:

$99,297- $124,121; with the ability to progress to a maximum of $142,739 with demonstrated experience and proficiency. To ensure fair and equitable pay at SickKids Foundation, placement on the salary range will be based on your years of experience, skills, and qualifications relevant to the Associate Director, Cybersecurity.

To help you lead in the fight for kids’ health and to support your health, wellness, and career growth, in addition to competitive compensation, we offer a comprehensive benefit package (includes a flex benefit plan), tuition reimbursement, flexible work arrangements, pension plan and birth parent/parental top up – to name a few!

Position Status

:

Permanent Full-Time.

Hours

: Hybrid work model: minimum two days per week in-office (Tuesday and Wednesday).

Available To:

Internal and External Candidates.

Available

: Immediately; this posting is for an existing vacancy.

Applications will be reviewed on an ongoing basis. We encourage interested candidates to apply early.

How to apply

: Please apply on-line by visiting our website: https://www.sickkidsfoundation.com/careersandvolunteers

Please note that automated tools, including artificial intelligence, may be used to support the pre-screening of applications as part of our recruitment process.

SickKids Foundation is committed to its people and the talents, capabilities, and perspectives they bring to our mission. We live that commitment by being open and accessible to all, by valuing and respecting every individual, and by equally supporting every employee. As an organization proud to have joined the BlackNorth Initiative’s CEO pledge, we uphold our commitment by inviting and encouraging individuals from diverse lived experiences from Black, Indigenous, communities of colour, people with disabilities, 2SLGBTQIA+ community and all candidates who may contribute to the further diversification of the Foundation’s community.

Candidates who require accommodation during the recruitment process should contact the People & Culture team at: [email protected]

Search the jobs. Check the details. Make your move.

Compare recent openings by location, work format, pay, and experience level in one place.

Explore jobs
Smiling man pointing at a “Job offer!” notification on his phone

Excellent

Rated 4.8 out of 5 based on 617 reviewsTrustpilot

by Megan F.

Job seeker

The filters made it easier to see roles that actually matched the way I want to work. I could compare options without opening dozens of tabs.

by Daniel B.

Developer

I liked being able to narrow the search to remote roles and check the requirements before taking the next step.

by Rachel A.

People operations

The listings are easy to scan. Work format, location, and experience level are right where I expect them.

by Marcus H.

Data analyst

Salary and location filters helped me focus on roles that were worth a closer look.

by Aisha K.

QA engineer

I found the job details clear and useful. It was simple to see which skills mattered for each role.

by Olivia G.

Support specialist

The search felt straightforward, and I could quickly switch between different kinds of jobs.

by Kevin T.

Account manager

It is easy to revisit roles that fit my experience. I would like to see even more openings in my area.

by Sophia R.

Product designer

I could check work format and salary before reading the full description. That made my search feel much clearer.

by Hannah S.

Project coordinator

The job pages put the important details together, so I knew what to expect before deciding to continue.

by Victor A.

DevOps engineer

The remote filter is useful and the listings are quick to scan. A few more country options would make it even better.

by Brandon L.

Job seeker

After a break from work, a simple search and clear filters helped me start looking again without feeling overwhelmed.

by Jessica M.

Marketing coordinator

The search is straightforward. I can move from a short result to the full role description in one click.

by Christopher H.

Operations manager

I like seeing salary, location, and experience level next to each role. It saves time when comparing openings.

by Ethan M.

Sales representative

The layout is clean and the job cards are easy to read. I am looking forward to a larger selection of listings.

by David R.

Support specialist

I found the different work formats easy to browse and could quickly open roles that matched my schedule.

Frequently asked questions

Answers about finding your next role

What can I search for?

Search by job title or keyword, then browse remote, hybrid, and onsite openings in one list.

Where can I find remote jobs?

Browse remote openings on Remote Amigo. Search by job title or keyword, then choose Remote in the work format filter. Check each listing for location or country requirements.

How do I narrow the results?

Choose a country, work format, minimum annual salary, and experience level. You can change or clear the filters at any time.

What will I see on a job page?

Each listing shows the role, company, location, work format, salary when available, skills when provided, and a job description.

Do I need an account to browse jobs?

No. You can search and read the available listings without signing in.

Does this site submit job applications for me?

No. You can search and review listings here. The Apply button starts the job preference quiz; it does not submit an application to an employer.

Where do the jobs come from?

Listings are imported from public job feeds and job sites. Job details may change at the original source, so confirm the latest information before applying.

How recent are the listings?

Search results include listings with a publication date in the last 30 days. If a source provides no publication date, the import date is used; the actual posting may be older.

Can I search for remote jobs only?

Yes. Select Remote in the job type filter to show remote listings. You can switch to Hybrid or Onsite whenever you want.

What is the difference between remote, hybrid, and onsite?

Remote roles are intended to be done away from an office. Hybrid roles combine remote and office work. Onsite roles are based at a workplace. Always read the listing for its exact location requirements.

Can I filter jobs by country?

Yes. Choose a country in the search form to narrow the listings. A remote role may still have country restrictions, so check its description before applying.

Why do some jobs have no salary listed?

Some listings do not include pay information. We show a salary when it is available and leave it out when it is not provided.

Is the salary filter a monthly or annual amount?

The minimum salary field uses US dollars per year. It filters listings that have comparable salary information.

Can I change or clear my search filters?

Yes. Change the keyword, country, job type, salary, or level in the search form. You can clear individual fields and run a broader search again.