On-siteFull Time

Salary

$60.72 - $75.9 / hr

Location

Ajax, ON

Ajax, Ontario L1S 0A1

Posted

Jul 22, 2026

Role overview

The Supervisor, Cyber Security is a well-rounded leader, equally adept in security governance and hands-on technical execution. As the operational lead of Elexicon's cyber security program, you will spend approximately half your time building and sustaining the governance structures that keep the organization aligned with cyber security frameworks and standards, and the other half performing technical work that brings those controls to life, such as configuring tooling, hardening systems, responding to incidents, and driving measurable security improvements across IT and OT environments.

This is a role for a practitioner who leads. The ideal candidate is equally comfortable writing policy as they are tuning custom detection rules, and equally confident preparing board-level risk reports as they are administering privileged access controls. Reporting to the Manager, Technology and Security Operations, this role works in close partnership with IT/OT teams, Enterprise Risk Management, Privacy and Information Management, and key external partners including Elexicon's managed security service provider and regulatory bodies.
DUTIES & RESPONSIBILITIES

Cyber Security Strategy, Architecture & Roadmap

Own and deliver Elexicon's cyber security target-state architecture and multi-year maturity roadmap across IT, OT, cloud, identity, data, endpoint, and third-party environments — including current-state assessment, prioritized initiatives, investment planning, and measurable outcomes.
Translate regulatory requirements, enterprise risk priorities, threat intelligence, and leading practices into a practical, funded program of work that improves security maturity and resilience over time.
Define security reference architectures and control standards; lead security architecture reviews for major technology initiatives, vendor onboarding, cloud deployments, OT connectivity, and business transformation projects.
Embed secure-by-design practices into technology delivery, procurement, cloud adoption, application changes, and OT modernization through architecture reviews, threat modelling, and control requirements.
Define and maintain cyber security controls for AI-enabled tools, partnering with Privacy, Information Management, Legal, and business leaders to ensure AI adoption is secure, governed, and aligned with enterprise risk tolerance.

Governance, Risk & Compliance

Lead the full lifecycle of Elexicon's cyber security policy suite — creation, review, approval, publication, exception management, versioning, and annual review — ensuring policies remain current, enforceable, and aligned with regulatory expectations.
Own and maintain cyber security operational plans and playbooks (e.g., incident response, disaster recovery, access reviews, vulnerability response, vendor onboarding).
Lead Elexicon's ongoing alignment with the Ontario Cyber Security Framework (OSCF), including self-assessments, evidence collection, regulatory submissions, remediation tracking, and support for OEB-mandated independent assessments.
Maintain a control catalog mapped to OSCF, NIST CSF 2.0, and CIS Controls; manage the cyber risk register and associated remediation plans.
Own cyber security dashboards and executive-level reporting for the Enterprise Risk Management (ERM) program, including security posture, risk exposure, Key Risk Indicators, and control effectiveness.
Administer Elexicon's Third-Party Risk Management (TPRM) program: vendor due diligence, contractual cyber security requirements, ongoing assurance reviews, and findings remediation.
Liaise with regulatory bodies and the Privacy and Information Management function on compliance obligations, privacy impact assessments, breach response, and records management; support internal and external audits.

Technical Security Operations

Configure, manage, and tune security tooling across Elexicon's M365 and Azure environment, including Defender (Endpoint, Identity, Cloud Apps), Purview (DLP, data classification), and Conditional Access policies in Entra ID.
Own the security monitoring and detection engineering lifecycle — log source strategy, custom detection rules, alert quality, threat hunting, escalation procedures, and MSSP/SOC performance management.
Own vulnerability management end-to-end: scan execution and review, findings validation, remediation tracking, patching SLAs, and KRI reporting; manage endpoint security posture via Intune and Defender for Endpoint.
Serve as Cyber Incident Response Lead: maintain the IR plan and playbooks, coordinate annual tabletop exercises, lead post-incident root cause analysis and enterprise-wide remediation, and ensure alignment with OEB incident reporting obligations.
Establish and test cyber resilience capabilities, including ransomware response, immutable backup validation, critical system recovery plans, and break-glass access procedures across IT and OT environments.
Administer and continuously improve cloud and identity security posture, including Secure Score initiatives, zero-trust access controls, and periodic access reviews enforcing RBAC/ABAC principles.
Conduct technical security reviews of firewall rules, network segmentation, and OT access boundaries.
Establish and maintain an OT cyber security program for SCADA, ADMS, DERMS, AMI, substations, and field communications — including asset visibility, secure remote access, segmentation, vendor access controls, and OT-specific incident response.

People Leadership & Program Operations

Supervise, coach, and develop cyber security analysts; manage workload prioritization and performance.
Manage relationships with managed security service providers and vendor performance.
Own the security awareness training program; tailor campaigns by risk profile and track measurable behaviour change.
Build effective partnerships with business leaders and foster a culture of shared cyber accountability across the organization.
Provide input to security budget planning and support procurement processes for security tools and services.

WHAT YOU NEED TO BE SUCCESSFUL

5–8 years of progressive cyber security experience, with 2–3 years in a supervisory or team lead capacity.
Proven track record of hands-on technical security work, including direct tool administration and incident response execution, not solely in an advisory or governance capacity.
Demonstrated experience with governance, policy/standards management, regulatory compliance, and incident response leadership.
Strong familiarity with the Ontario Cyber Security Framework and at least one of: NIST CSF 2.0, COBIT, ISO/IEC 27001; ability to map and rationalize controls across frameworks.
Hands-on understanding of modern enterprise/cloud security (e.g., M365), EDR/XDR, SIEM/SOAR, IAM (RBAC, PAM), data protection, vulnerability management, and network security/segmentation.
Familiarity with OT/SCADA environments and the security considerations unique to converged IT/OT infrastructure.
Excellent stakeholder management, executive communication, and decision-making under pressure.

MINIMUM REQUIREMENTS

Cyber Security, Computer Science, Computer Engineering degree, or equivalent combination of education and experience.

Sector experience (preferred): Energy/utility, critical infrastructure, or regulated environments; exposure to OT/SCADA and business continuity/disaster recovery.
CISSP, CISM, CRISC, or GIAC certifications are an asset
ITIL Foundation (or higher), COBIT
ISO/IEC 27001 Lead Implementer/Lead Auditor (optional)

Compensation Package: $118,400.00 - $148,000.00 CAD annually + Competitive Bonus + Benefits + OMERS Pension Plan
The above range reflects the reasonable estimate for the position at the time of posting. Within the range, hiring compensation will be determined based on relevant qualifications, experience, skillset, education/ training, and other organizational needs.
Note: This posting is for a new position.