Chief Information Security Officer, Information Technology

University of Ottawa

University of Ottawa

IT

Ottawa, ON, Canada · Kanata, Ottawa, ON, Canada

USD 146,405-183,006 / year

Posted on May 14, 2026

Follow us on LinkedIn

Posting Reason:

Replacement of a regular position

Job Type:

Employee

Anticipated Duration in Months (for contracts and temporary assignments):

N/A

Job Family:

IT Security

# of Open Positions:

1

Faculty/Service - Department:

Information Technology

Campus:

Main Campus

Union Affiliation:

N/A

Date Posted (YYYY/MM/DD):

2026/05/13

Applications must be received BEFORE (YYYY/MM/DD):

2026/06/15

Hours per week:

35

Salary Grade:

Non-Union Grade NM4

Salary Range:

$146,405.00 - $183,006.00About Information Technology:

Information Technology is a dynamic and collaborative environment. We are focused on prioritizing and optimizing technological investments that facilitate the best student experience, as well as the activities of faculty, researchers and staff. Our greatest strength are the people working with us. People like you, professionals eager to flex their intellectual muscle and achieve new heights in their career. Working here gives you access to a great IT environment, rich with a diverse range of platforms, products, and services. This is a place where innovative ideas are welcome.

In a nutshell: working here is challenging and rewarding. It’ll bring out the best of you. We want people that have the drive to advance IT in higher education. We have the technologies to keep your inner fires burning, and benefits that can help you sustain a better lifestyle. And all this minutes away from gyms, the Byward Market, downtown, and the Rideau Canal at lunch time for runners and skaters.

Position Purpose
Reporting to the Chief Information Officer, the incumbent is responsible for establishing and maintaining the institution vision, strategy, and program to ensure information assets and technologies are adequately protected. This role involves strategic leadership, risk management, stakeholder engagement, and fostering a strong security culture within the institution. The CISO recommend and oversee monitoring of computing practices to prevent and recover from security breaches; and direct the handling of security incidents when breaches occur.

The incumbent governs the cybersecurity strategy and ensures the institution (and its affiliated universities, institutes and other partners) adherence to adopted standards and best practices throughout IT operations and interoperation of all university stakeholders; faculties, services, professors, students, affiliated universities, and external partners. The Chief Information Security Officer primary mandate is to protect the confidentiality, integrity, and availability of enterprise IT assets and data University wide.

In this role, your responsibilities will include:

  • Strategic Leadership:
    • Develop and implement a comprehensive information security strategy that aligns with the institution's business goals and objectives.
    • Ensure security considerations are integrated into all aspects of the institution's operations.
    • Ensures that cybersecurity strategy is in compliance with relevant laws, regulations and policies.
  • Risk Management:
    • Identify, assess, and mitigate security risks at a strategic level.
    • Develop and implement IT risk management frameworks and ensure compliance with relevant regulations and standards.
  • Stakeholder Engagement:
    • Engage with key stakeholders, including senior executives, board members, external institutions, and other external partners, to communicate security risks and strategies.
    • Ensure that security is a top priority across the institution.
    • Liaises with provincial research network (ORION) and national cybersecurity agencies (CanSSOC, CCCS), higher education consortia (e.g., CUCCIO, CANARIE), and peer institutions to share best practices, align the organization cybersecurity strategy to the national strategy, and stay informed on emerging threats.
  • Innovation and Emerging Threats:
    • Continuously monitor the threat landscape and evaluate new risks.
    • Ensure the institution is prepared to respond to evolving security threats by creating strategic action plans to mitigate these risks.
  • Security Culture and Awareness:
    • Foster a strong security culture within the institution.
    • Develop and implement security awareness programs and train employees, external partners, students, and other collaborators on security best practices.
  • Collaboration and Coordination:
    • Collaborate with other institutions, faculties, services and teams to ensure security is integrated into all projects and initiatives.
    • Work closely with IT, legal counsel, privacy office, risk management office, and other teams to ensure security considerations are taken into account.


What you will bring:

  • University degree or college diploma in Computer Science, Computer Engineering, or a related IT discipline.
  • Certification in the field of information security is considered an asset, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.
  • Proven experience in planning, organizing, and developing IT security system technologies.
  • Experience in planning and executing security policies and standards development .
  • 10 years’ experience in areas related to IT security and IT security domain expertise, including two years in a significant leadership role.
  • Understanding risk-based approaches, regulatory and compliance issues.
  • Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet the objectives of excellence in a dynamic environment.
  • Excellent business and technological acumen, leadership style, and organizational skills suited to an environment where multiple projects are run concurrently.
  • Ability to lead and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals.
  • Asset: The person in this role needs to have knowledge of: International Organization for Standardization (ISO) 2700X, ITIL, COBIT/Risk IT and National Institute of Standards and Technology (NIST)., as well as : Knowledge and understanding of relevant legal and regulatory requirements, such as Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry/Data Security Standard.
  • Excellent communications and interpersonal skills.
  • Bilingual French and English (spoken and written).

#LI-Hybrid #LI-DP1

Key Competencies at uOttawa:
Here are the required competencies for all or our employees at uOttawa:

Planning: Organize in time a series of actions or events in order to realize an objective or a project. Plan and organize own work and priorities in regular daily activities.
Initiative: Demonstrate creativity and initiative to suggest improvements and encourage positive results. Is proactive and self-starting. Show availability and willingness to go above and beyond whenever it is possible.
Client Service Orientation: Help or serve others to meet their needs. This implies anticipating and identifying the needs of internal and external clients and finding solutions on how to meet them.
Teamwork and Cooperation: Cooperate and work well with other members of the team to reach common goal(s). Accept and give constructive feedback. Able to adjust own behaviour to reach the goals of the team.

The University of Ottawa embraces diversity and inclusion in the workplace. We are passionate about our people and committed to employment equity. We foster a culture of respect, teamwork and inclusion, where collaboration, innovation, and creativity fuel our quest for research and teaching excellence. While all qualified persons are invited to apply, we welcome applications from qualified Indigenous persons, racialized persons, persons with disabilities, women and LGBTQIA2S+ persons. The University is committed to creating and maintaining an accessible, barrier-free work environment. The University is also committed to working with applicants with disabilities requesting accommodation during the recruitment, assessment and selection processes. Applicants with disabilities may contact hrtalentmanagement@uottawa.ca to communicate the accommodation need. All qualified candidates are encouraged to apply; however, Canadians and permanent residents will be given priority.

Note: if this is a union position: The hiring process will be governed by the current collective agreement related to the union affiliation noted above; you can click here to find out more.

If this is a front-line position with responsibilities to interact with students, selected candidates must be rated at the Low Advanced proficiency level or higher for both oral comprehension and reading comprehension in their second official language. The rating is determined by a proficiency test designed by the Official Languages and Bilingualism Institute.

Prior to May 1, 2022, the University required all students, faculty, staff, and visitors (including contractors) to be fully vaccinated against Covid-19 as defined in Policy 129 – Covid-19 Vaccination. This policy was suspended effective May 1, 2022 but may be reinstated at any point in the future depending on public health guidelines and the recommendations of experts.