
Technology Architect 9513
- Toronto, ON
- Permanent
- Full-time
- 10+ years of experience mapping and adapting cyber security frameworks (e.g., NIST CSF v2, CIS Controls v8, COBIT, ISO/IEC 27001) for organizations of similar size and complexity to Ontario school boards.
- 10+ years of experience integrating cyber security frameworks and controls into enterprise risk management, governance structures, and organizational practices, including change management.
- 10+ years of experience conducting security assessments and developing cyber security and online privacy policies, standards, and guidelines—preferably within the public or broader public sector.
- Demonstrated experience applying privacy frameworks such as NIST Privacy Framework v1.1 and ISO/IEC 27701 is highly desirable.
- Demonstrated experience in cyber/online safety analysis and the development of related policies and standards is highly desirable.
- Experience with capability maturity models such as CMMI and CMMC is considered an asset.
- Strong knowledge of applicable legislation, including the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA); familiarity with the Education Act is desirable.
- Awareness of IoT and Operational Technology (OT) security issues is considered an asset.
- 10+ years of experience delivering presentations to senior leadership, management teams, and external stakeholders.
- 10+ years of experience preparing professional documentation, including security/privacy reports, status updates, recommendations, and briefing notes for both technical and non-technical audiences.
- Mandatory: One of the following security certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Desirable: Privacy certification such as Certified Information Privacy Professional (CIPP).
- Other relevant certifications such as CISA or CASP+ are considered assets.
- 5+ years of hands-on experience working in large public sector environments. Preferably experience working with the Ontario K-12 education sector.
- 5+ years of experience applying Ontario’s cybersecurity standards, including the GO-ITS 25.x series (Ontario IT Standards).
- Knowledge of Government of Ontario relevant legislation (e.g., Bill 194 / EDSTA).