Lead Analyst, IT Security Risk and Compliance

University of Ottawa

University of Ottawa

IT, Legal

Ottawa, ON, Canada · Kanata, Ottawa, ON, Canada

USD 107,503-134,379 / year

Posted on May 28, 2026

Follow us on LinkedIn

Posting Reason:

Temporary replacement of a regular position

Job Type:

Employee

Anticipated Duration in Months (for contracts and temporary assignments):

24

Job Family:

IT Security

# of Open Positions:

1

Faculty/Service - Department:

Information Security

Campus:

Main Campus

Union Affiliation:

N/A

Date Posted (YYYY/MM/DD):

2026/05/27

Applications must be received BEFORE (YYYY/MM/DD):

2026/06/08

Hours per week:

35

Salary Grade:

Non-Union Grade NM1

Salary Range:

$107,503.00 - $134,379.00About Information Technology:

Information Technology is a dynamic and collaborative environment. We are focused on prioritizing and optimizing technological investments that facilitate the best student experience, as well as the activities of faculty, researchers and staff. Our greatest strength are the people working with us. People like you, professionals eager to flex their intellectual muscle and achieve new heights in their career. Working here gives you access to a great IT environment, rich with a diverse range of platforms, products, and services. This is a place where innovative ideas are welcome.

In a nutshell: working here is challenging and rewarding. It’ll bring out the best of you. We want people that have the drive to advance IT in higher education. We have the technologies to keep your inner fires burning, and benefits that can help you sustain a better lifestyle. And all this minutes away from gyms, the Byward Market, downtown, and the Rideau Canal at lunch time for runners and skaters.
Position Purpose
Reporting to the Chief Information Security Officer, the incumbent is responsible for designing and implementing an overall information security risk and compliance management process for the University. The incumbent will manage the process of gathering, analyzing, and assessing the current and future information security and privacy threats to the University. He/she will focus on delivering the objectives within the University’s information security strategy as well as enhancing a security program that identifies and addresses security and privacy risks and requirements. The incumbent works with various stakeholders across the University to drive the information security agenda, ensuring it meets complex compliance requirements, as well as maintaining, monitoring, and promoting information security best practices. He/she acts as a specialist with a deep knowledge of various security risk management and compliance frameworks and plays an integral role ensuring security controls and requirements are incorporated into all information technology projects and initiatives.


In this role, your responsibilities will include:

  • Security Risk Management: Manages the process of gathering, analyzing, and assessing the current and future threat landscape. Conducts information security risk assessments across the organization at suitable intervals. Ensures key risks are understood, communicated, and tracked on the risk register. Analyzes the financial, reputational, and legal impacts to the University when information security risks occur and provides guidance and recommendations on how to best mitigates these risks.

  • Compliance Management: Manages the process of ensuring information technology projects, initiatives, and external vendor contracts are compliant with the established information security policies, standards, and procedures of the University. Collaborates closely with stakeholders to ensure security is factored into the evaluation, selection, installation, and configuration of hardware, software, and applications. Conducts periodic reviews of vendor environments to ensure information security controls continue to remain compliant with established contracts.

  • Monitoring and Reporting: Responsible for monitoring and reporting on various information security risk and compliancy metrics. Provides regular updates to key stakeholders and executive leadership offering a realistic overview of risks and threats throughout the organization.

  • Policies and Standards: Create and keep up to date new and existing information security policies and procedures to ensure operating efficiency and regulatory compliance. Coordinates the development and implementation of technical controls and configurations to align with security policies and legal, regulatory, and audit requirements. Responsible for ensuring policies and procedures are enforced in a consistent manner across the University.

  • Education and Awareness: Act as a subject matter expert in order to provide support, education, and training to staff with the goal of building risk awareness within the University. Actively participating by providing inputs and content towards the University’s information security awareness program.

  • Operations and Maintenance: Provide advisory support to operational teams in strengthening the University’s overall information security posture. Periodically review audit trails, system logs, and other monitoring data sources to ensure they are in compliance with policies, standards and audit requirements. Evaluate and documents requests for exceptions to policies, ensuring sufficient mitigating controls are in place. Ensure that internal and external audits are supported in development of an annual strategic audit plan. Continually review the operational components of the security incident management processes to ensure they comply with the established incident response plan. Formally documents risk assessment results and provide regular updates to management.

What you will bring:

  • University degree in Computer Science or Information Technology or a related field or an equivalent combination of education and experience.

  • Minimum of seven (7) years of information security, IT audit and/or IT Risk Management experience.

  • Expert understanding of NIST and ISO Risk Management Frameworks, ITSG-33, NIST CSF, ISO 27002, COBIT, SOC 2, and other relevant frameworks.

  • Experience with security assessments (AI, Cloud, SaaS, etc.).

  • Experience with risk discovery and assessment, as well as appropriate mitigation and controls.

  • Good knowledge of the latest trends in information security and risk management, e.g. evolving technologies, cyber risk mitigation, etc.

  • Experience of auditing IT environments, either through an internal or external audit role.

  • Broad knowledge of IT architecture and underpinning technologies including but not limited to: identity and access management, cloud hosting providers, database administration.

  • Experience designing and supporting large-scale, end-to-end information security systems in a complex, both on-premises and cloud hosted, multi-platform environment.

  • Knowledge of security technologies such as various monitoring and log aggregation platforms, penetration testing frameworks, operating systems, vulnerability scanners, and endpoint security solutions.

  • Leadership skills, ability to coach and mentor other IT professionals.

  • In-depth analytical skills for complex problem solving – identification, diagnosis, resolution.

  • Knowledge of the University’s information technology and security policies, procedures and standards would be considered an asset.

  • Experience in project management and meeting strict deadlines.

  • Good communication skills to interact with team members, support personnel, and provide technical guidance and expertise to clients and management.

  • CISSP or CRISC or other information security certifications is an asset.

  • Ability to work a flexible schedule including occasional weekends and evenings.

  • Bilingual: French and English (spoken and written).

#LI-Hybrid #LI-DP1

Key Competencies at uOttawa:
Here are the required competencies for all or our employees at uOttawa:

Planning: Organize in time a series of actions or events in order to realize an objective or a project. Plan and organize own work and priorities in regular daily activities.
Initiative: Demonstrate creativity and initiative to suggest improvements and encourage positive results. Is proactive and self-starting. Show availability and willingness to go above and beyond whenever it is possible.
Client Service Orientation: Help or serve others to meet their needs. This implies anticipating and identifying the needs of internal and external clients and finding solutions on how to meet them.
Teamwork and Cooperation: Cooperate and work well with other members of the team to reach common goal(s). Accept and give constructive feedback. Able to adjust own behaviour to reach the goals of the team.

The University of Ottawa embraces diversity and inclusion in the workplace. We are passionate about our people and committed to employment equity. We foster a culture of respect, teamwork and inclusion, where collaboration, innovation, and creativity fuel our quest for research and teaching excellence. While all qualified persons are invited to apply, we welcome applications from qualified Indigenous persons, racialized persons, persons with disabilities, women and LGBTQIA2S+ persons. The University is committed to creating and maintaining an accessible, barrier-free work environment. The University is also committed to working with applicants with disabilities requesting accommodation during the recruitment, assessment and selection processes. Applicants with disabilities may contact hrtalentmanagement@uottawa.ca to communicate the accommodation need. All qualified candidates are encouraged to apply; however, Canadians and permanent residents will be given priority.

Note: if this is a union position: The hiring process will be governed by the current collective agreement related to the union affiliation noted above; you can click here to find out more.

If this is a front-line position with responsibilities to interact with students, selected candidates must be rated at the Low Advanced proficiency level or higher for both oral comprehension and reading comprehension in their second official language. The rating is determined by a proficiency test designed by the Official Languages and Bilingualism Institute.

Prior to May 1, 2022, the University required all students, faculty, staff, and visitors (including contractors) to be fully vaccinated against Covid-19 as defined in Policy 129 – Covid-19 Vaccination. This policy was suspended effective May 1, 2022 but may be reinstated at any point in the future depending on public health guidelines and the recommendations of experts.