Together, we do amazing things every day.
Imagine a supportive employer, a career that fits your lifestyle, and many learning opportunities. With the Hamilton Family Health Team, you can have all of that, and more. We work hard to create an innovative and diverse workplace that values the contributions of our employees. No matter what your role, working with us is about making a difference – every day!
Your Opportunity:
We are seeking an experienced and relationship-driven Cyber Security Advisor for a 12-month contract to lead cybersecurity risk assessments and practical risk mitigation planning across a network of affiliated community-based healthcare organizations.
The Cybersecurity Advisor supports affiliated practices in strengthening their cybersecurity posture by assessing risks, developing action plans, and guiding the implementation of security improvements. Working collaboratively with practice leadership, Security Champions, and external IT providers, the Advisor monitors progress, promotes security awareness, and supports the protection of sensitive health information. The role will be working closely with the IT Manager, Privacy Officer, affiliate site leadership, and external vendors and partners as required.
Roles and Responsibilities:
- Schedule and conduct on-site and virtual Cyber Resilience Assessments and Scorecards across affiliated practices.
- Review assessment results to identify security gaps, risks, and opportunities for improvement.
- Develop practical, prioritized action plans tailored to each practice’s needs, resources, and technical capabilities.
- Collaborate with practice leadership, Security Champions, and external IT providers to implement and verify recommended security controls.
- Provide guidance on cybersecurity best practices, baseline security requirements, and risk mitigation strategies.
- Track outstanding action items and follow up with practices and IT providers to ensure timely implementation of improvements.
- Coordinate enrollment in the organization’s Security Awareness Platform and monitor staff participation and training completion.
- Promote cybersecurity awareness and encourage safe practices among clinical and administrative staff.
- Maintain cybersecurity reporting dashboards and monitor assessment results, Scorecard trends, control adoption, action plan progress, and training completion.
- Identify recurring security gaps and recommend opportunities to improve cybersecurity across the affiliated practice network.
- Communicate assessment findings, risks, and recommendations in clear, practical language to support informed decision-making.
- Build strong relationships with practice stakeholders and encourage accountability for ongoing cybersecurity improvements.
- Provide regular updates on progress, outstanding risks, and areas requiring additional support.
- Support the adoption of new security practices while considering operational requirements and minimizing disruption to patient care.
- Maintain confidentiality and support the protection of sensitive health information in accordance with applicable privacy requirements.
Qualifications and Skills:
- 3-5 years of progressive experience in IT systems, cybersecurity, and security controls, preferably in a healthcare environment.
- Undergraduate degree in Information Technology, Computer Science, Engineering, or a related field, or equivalent experience.
- Strong understanding of cybersecurity frameworks and standards, including NIST Cybersecurity Framework (CSF), CIS Controls, and ISO 27001.
- Knowledge of privacy requirements and practices for protecting sensitive health information.
- Experience coordinating initiatives, tracking action items, monitoring progress, and supporting the implementation of security improvements.
- Strong communication, relationship-building, organizational, and problem-solving skills.
- Ability to work independently, manage multiple practice locations, and collaborate effectively with internal and external stakeholders.
- Ability to translate technical cybersecurity findings into practical business recommendations.
- Cybersecurity certifications such as CISSP, CISM, CRISC, or HCISPP are considered an asset.
Work Requirements
- Full-time contract position, Monday to Friday, with occasional flexibility to accommodate practice schedules.
- Combination of on-site visits to affiliated practices across the HFHT network and remote or office-based work.
- Valid Ontario Class G driver’s licence and reliable personal vehicle for local travel.
- Mileage reimbursed in accordance with HFHT policy.
- Ability to work in active clinical environments while maintaining patient privacy, confidentiality, and minimal disruption to care.
Working Conditions
- Hybrid work model with regular onsite visits to affiliated healthcare and community partner locations
- Travel across multiple locations is required.
- Must be comfortable working within varied technical, operational, and organizational environments
- Valid driver’s license and reliable access to transportation required.
Why join the HFHT?
Competitive Employee Value Proposition including, but not limited to:
Healthcare of Ontario Pension (HOOPP)
Extended health care benefits including health, dental, vision & critical Illness insurance
Meaningful, purpose-based work
12 paid Stat holidays and one (1) extra float day
Flexible work schedule
Ongoing green initiatives
Summary
Classification: Non-Union
Primary Location: Hamilton
Employee Class: Temporary Full Time (Up to 12 Months)
Schedule: Monday-Friday
Salary: $67,400-77,000.88
Application Instructions:
Interested applicants please submit résumé and cover letter as one document using naming convention
Last name, First name Position via email: hr@hamiltonfht.ca
Note:
If successful in receiving a job offer with the Hamilton Family Health Team, new hires will be required to provide proof of full COVID-19 vaccination prior to start date as a condition of their employment. If successful candidates are unable to get their COVID-19 vaccination as a result of a medical exemption, they will be required to submit supporting documentation to determine if they are exempt from this requirement.