IMMEDIATE INTERIM OPPORTUNITY
Interim Chief Information Security Officer
Reports to Chief Information Officer
Duration: 4-6 Months
Location: Toronto
Hybrid working
Our client, a leading academic institution, is making a significant investment in information security through the creation of a new Chief Information Security Officer position reporting to the CIO. This is an exceptional opportunity for a seasoned security leader to provide both strategic advice and operational leadership while building and strengthening this critical function. Working across the institution, the CISO will define the strategy, governance, policies and capabilities required to deepen and broaden information security, protect data and effectively manage evolving cyber risks. This is a highly purposeful mandate for someone who has built or transformed a security function before and wants to make a lasting impact within an important Canadian institution.
- RESPONSIBILITIES:
- Strategy and Governance Oversee institution-wide security resources and advise on policy, legislation, regulation, and technology.
- Lead security policies and practices that protect data and ensure compliance.
- Manage regulatory compliance, including Ontario’s Enhancing Digital Security and Trust Act (2024), required contacts, biennial assessments, incident reporting, and executive and Board updates.
- Assess AI-related threats, defenses, adoption risks, phishing, agentic attacks, and third-party data leakage.
- Embed security controls in AI governance with the future Office of AI and key stakeholders.
- Maintain cyber insurance eligibility and advise on coverage and risk transfer.
- Support cloud adoption through risk-based vendor assessments and shared-responsibility guidance.
- Risk Management and Compliance Assess security controls and advise executives on improvements.
- Identify security risks and monitor compliance with standards and policies.
- Lead third-party risk management, including HECVAT reviews, SOC 2 Type II attestations, cloud assessments, and shared-responsibility guidance.
- Coordinate and track security audits, findings, timelines, and outcomes.
- Align records retention and data disposal with policy, legislation, privacy, and cybersecurity requirements.
- Security Operations and Technology
- Implement technical standards, services, and tools that reduce cyber risk.
- Coordinate vulnerability assessments and promote effective security practices.
- Lead response and communications for suspected and confirmed incidents.
- Maintain incident response protocols and conduct regular tabletop exercises.
- Maintain continuity, succession, and cross-training plans for disrupted operations.
- Reporting, Metrics, and Board Accountability
- Report cybersecurity risk, control effectiveness, and strategy to executives and the Board Audit & Risk Committee.
- Maintain metrics for maturity, insurance, third-party ratings, vulnerabilities, and training completion.
- Present the security dashboard on an established schedule.
- Education, Awareness, and Security Culture Lead security awareness programs and set measurable training targets for staff, faculty, and students.
- Report training completion and remediation plans to executives and the Board.
- Track higher-education security issues and consult governments and industry partners.
- Support cybersecurity-related academic programs as needed.
- External Partnerships and Collaboration Represent the organization in multi-agency threat-sharing, incident planning, and tabletop exercises.
- Partner with Privacy, Legal, Communications, and academic leaders on security matters.
- People Leadership Lead, coach, and develop IT security staff within a client-focused culture.
- Oversee service quality, efficiency, stakeholder engagement, and SLAs.
- Build recruitment and retention plans that strengthen business and technical capability.
- Duties may change based on organizational needs and CIO direction.
REQUIRED SKILLS/ABILITIES:
- Expert knowledge of NIST, ISACA, CIS Controls, and applicable legislation, including Ontario’s Enhancing Digital Security and Trust Act, FIPPA, PIPEDA, and PHIPA.
- Strong understanding of AI-enabled threats, defensive tools, vendor capabilities, and institutional AI risk.
- Knowledge of nation-state threats and geopolitical risks affecting Canadian post-secondary institutions.
- Expertise in network, endpoint, cloud, identity, vulnerability, and incident response security.
- Proven ability to develop cybersecurity strategy, assess risk, prioritize threats, and implement mitigation plans.
- Strong leadership, change management, negotiation, influencing, and decision-making skills.
- Experience leading teams, projects, budgets, workforce planning, and service delivery.
- Excellent communication skills, including executive and Board-level reports and policies.
- Ability to perform effectively under ambiguity and pressure.
- Proven vendor, contractor, and third-party negotiation skills.
- Results-oriented and financially astute, with strong fiduciary judgment.
EDUCATION AND EXPERIENCE:
- A master’s degree in information security, or other related field plus equivalent training and experience.
- Information security management qualifications such as CISSP (Certified Information Systems Security Professional), or CISM (Certified Information Security Manager).
- Minimum 10 years’ progressively responsible experience in computing and information security, network security issues, and security incident response or related information technology fields, preferably in a higher education or equivalent complex environment.
- Minimum 5 years of experience in senior leadership and people management.
- Experience developing and administering an IS program and IS policy and regulations in a complex environment.
- Expertise in cyber security, in strategic planning, change management, resource management and reporting
PLEASE SEND YOUR CV (AS A WORD DOC) TO: Interim.Applications@LHHknightsbridge.com (Subject: Job Title)
LHH Knightsbridge Interim Management is a service to help our clients address a wide range of scenarios including leadership support due to sudden departures, driving key change initiatives or leading transformation projects. Our interim executives step in with minimal downtime to meet specific objectives and deliver results. All have held senior positions in the past and have now chosen to offer their unique depth and breadth of experience to organizations on a limited engagement basis.
Follow the LHH Knightsbridge LinkedIn page and set up a job alert to learn about new Executive Interim opportunities.
Lee Hecht Harrison Knightsbridge Corp. is committed to providing equitable treatment and accommodation to ensure a barrier-free recruitment process. In accordance with the Ontario Human Rights Code, Accessibility for Ontarians with Disabilities Act and our AODA policy, a request for accommodation will be accepted as part of the hiring process. If you require accommodation to apply or if selected to participate in an assessment process, please provide your accommodation needs in advance to the Recruitment Lead for this opportunity.
We thank all interested candidates in advance; however, only individuals selected for interviews will be contacted.
October 2026