About Us
SickKids Foundation, with over 50 years of philanthropic impact is Canada's largest charitable funder of child health research, learning and care, raising over $200 million last year. As a national charity, SickKids Foundation invests in national and international initiatives to benefit children in Canada and around the world. As the fundraising partner to The Hospital for Sick Children (SickKids), we are aligned in supporting Precision Child Health (PCH), the future of tailoring medicine to each child's unique traits so SickKids can diagnose faster, treat smarter, and predict better.
We are driven by our core values of integrity, collaboration, excellence, innovation, and inclusion, with goals of delivering a superior donor experience, investing in our people and culture, driving innovative and sustainable fundraising, and disrupting the market through data and technology.
SickKids Foundation is committed to an inclusive culture by embedding equity, diversity and inclusion in our policies, practices, and behaviours. We aim to build awareness and skills in this area, both internally and with our partners. Our commitment extends to creating a safe, positive work environment. For details on our Equity, Diversity & Inclusion commitment, please click here.
We’re committed to attracting and retaining passionate individuals to help create a healthier future. That’s why SickKids Foundation is looking for a new Associate Director, Cybersecurity.
Description Of The Position
The Associate Director, Cybersecurity is a senior leadership role responsible for driving hands-on security operations, managing enterprise cyber risk, and maturing the organization's security posture. The incumbent will lead day-to-day security monitoring and incident response activities, oversee the risk register, champion security awareness, and ensure the organization is aligned with industry frameworks including MITRE ATT&CK and the NIST Cybersecurity Framework. The role reports to the Director, Infrastructure, Automation & Cybersecurity and is expected to actively leverage AI-enabled tools and automation to improve detection, response, and operational efficiency across the security program.
Key Responsibilities
Security Operations (Hands-On)
- Monitor, triage, and respond to security events, alerts, and incidents across SIEM, EDR, email security, and WAF platforms.
- Lead Level 2/3 incident analysis and drive root-cause investigations to resolution.
- Maintain and tune detection rules, alert thresholds, and playbooks to reduce false-positive rates.
- Administer and optimise security tooling including Imperva (WAF / Database Security), Abnormal AI (Email Security), and Sophos (EDR / Endpoint Protection).
- Collaborate with vendors to ensure tools are current, licensed, and properly integrated.
Frameworks & Threat Intelligence
- Apply MITRE ATT&CK techniques and tactics to map threat actor behaviour and improve detection coverage.
- Align security controls and risk assessments to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
- Integrate threat intelligence feeds into operational tooling to proactively identify emerging risks.
IT Risk Management
- Maintain the IT/Cyber Risk Register — identify, assess, score, and track remediation of risks in partnership with IT, legal, and business stakeholders.
- Conduct periodic risk reviews and present risk status updates to leadership and governance committees.
Security Awareness & Education
- Design, build, and execute enterprise-wide Cybersecurity Awareness Campaigns across multiple channels (intranet, email, digital signage, lunch-and-learns).
Phishing Simulation / Tabletop Exercises
- Coordinate and execute regular phishing simulation exercises using approved simulation platforms. Analyse simulation results, identify high-risk user segments, and administer remedial training.
- Coordinate the annual Cybersecurity Tabletop Exercise — develop scenarios, coordinate participants (IT, legal, HR, communications, executive leadership), and facilitate sessions.
- Document lessons learned, produce after-action reports, and track improvement items to closure.
Cybersecurity Architecture & Policy
- Provide input on security architecture reviews for new projects, cloud deployments, and third-party integrations.
- Maintain, review, and update Cybersecurity Policies, Standards, and Procedures on a defined review cycle.
Cybersecurity Tool Management
- Evaluate tool effectiveness, identify capability gaps, and make recommendations for tooling enhancements.
- Collaborate with vendors to ensure tools are current, licensed, and properly integrated.
Automation & AI-Enabled Security (New)
- Actively incorporate artificial intelligence and advanced automation into security operations, including threat detection, alert triage, analysis, and reporting, to enable faster and more consistent outcomes.
- Identify and reduce manual, repetitive security tasks through automation, orchestration, and standardized workflows rather than increased headcount.
- Maintain current, practical expertise in AI-enabled security tooling and demonstrate personal proficiency in using these tools to accelerate analysis and decision-making.
- Ensure AI is applied responsibly, securely, and in alignment with enterprise governance, privacy, and ethical standards.
- Continuously evaluate emerging AI-enabled security capabilities and recommend adoption where they improve detection, response time, or operational efficiency.
Qualifications
- 8+ years of progressive cybersecurity experience, with at least 5 years in a senior or lead role.
- Hands-on experience in a Security Operations Centre (SOC) environment — monitoring, triage, and incident response.
- Demonstrated working knowledge of MITRE ATT&CK framework and NIST CSF.
- Proven experience owning or contributing to an IT/Cyber Risk Register.
- Experience delivering security awareness programs and phishing simulations.
- Familiarity with security tools: Imperva, Abnormal AI, and Sophos (or comparable equivalents).
- Good understanding of cybersecurity architecture principles, network security, and cloud security.
- Excellent communication and stakeholder management skills — ability to translate technical risk into business language.
- Experience using automation and AI-enabled security tools to improve operational effectiveness.
Preferred
- Nice to have CISSP, CISM, GIAC or equivalent.
- Familiarity with additional frameworks: ISO 27001, SOC 2, CIS Controls.
- Experience with SOAR platforms and automation of security workflows.
- Post-secondary education in Computer Science, Information Security, or a related discipline.
Total Compensation Package
Expected Hiring Salary Range: $99,297- $124,121; with the ability to progress to a maximum of $142,739 with demonstrated experience and proficiency. To ensure fair and equitable pay at SickKids Foundation, placement on the salary range will be based on your years of experience, skills, and qualifications relevant to the Associate Director, Cybersecurity.
To help you lead in the fight for kids’ health and to support your health, wellness, and career growth, in addition to competitive compensation, we offer a comprehensive benefit package (includes a flex benefit plan), tuition reimbursement, flexible work arrangements, pension plan and birth parent/parental top up – to name a few!
Position Status: Permanent Full-Time.
Hours: Hybrid work model: minimum two days per week in-office (Tuesday and Wednesday).
Available To: Internal and External Candidates.
Available: Immediately; this posting is for an existing vacancy.
Applications will be reviewed on an ongoing basis. We encourage interested candidates to apply early.
How to apply: Please apply on-line by visiting our website: https://www.sickkidsfoundation.com/careersandvolunteers
Please note that automated tools, including artificial intelligence, may be used to support the pre-screening of applications as part of our recruitment process.
SickKids Foundation is committed to its people and the talents, capabilities, and perspectives they bring to our mission. We live that commitment by being open and accessible to all, by valuing and respecting every individual, and by equally supporting every employee. As an organization proud to have joined the BlackNorth Initiative’s CEO pledge, we uphold our commitment by inviting and encouraging individuals from diverse lived experiences from Black, Indigenous, communities of colour, people with disabilities, 2SLGBTQIA+ community and all candidates who may contribute to the further diversification of the Foundation’s community.
Candidates who require accommodation during the recruitment process should contact the People & Culture team at: recruitment@sickkidsfoundation.com