Job Description
The Director, IT Cyber Security & Resilience is responsible for leading and advancing cyber security, risk management and resilience across Ocean Capital Group and its operating companies. This role provides enterprise leadership for cyber strategy, governance, risk reduction, incident response, third-party security and business resilience while ensuring the protection of technology assets, operational environments and information.
Working closely with executive leadership, business stakeholders, Enterprise Risk and IT teams, the Director develops practical and scalable cyber security solutions that support business continuity, operational performance, growth and responsible risk management. The role serves as a trusted advisor to the business, balancing security requirements with organizational objectives and operational realities.
Responsibilities:
- Lead the organization's cyber security strategy, roadmap, governance framework and resilience initiatives across the enterprise
- Partner with executive leaders, operating companies and business stakeholders to align cyber security priorities with business objectives and risk tolerance
- Provide leadership and oversight for cyber security operations, risk reduction activities, vulnerability management, control effectiveness and continuous improvement programs
- Establish meaningful cyber security metrics, dashboards and reporting to communicate risks, performance, and improvement priorities to leadership
- Embed secure-by-design principles into enterprise architecture, infrastructure, applications, projects, and operational processes
- Review and provide security oversight for major technology initiatives, implementations and business transformation activities
- Lead organizational preparedness for cyber incidents through effective governance, response planning, recovery capabilities and resilience testing
- Partner with Enterprise Risk to strengthen incident response, disaster recovery, business continuity and enterprise resilience programs
- Develop and maintain cyber security policies, standards, controls and governance practices that support compliance and risk management objectives
- Lead third-party cyber risk management activities, including supplier assessments, security reviews, contractual requirements and ongoing monitoring of critical technology partners
- Build and maintain relationships with external cyber security advisors, vendors and industry partners to support emerging threat awareness and best practices
- Lead, develop and strengthen cyber security capabilities, awareness and culture across the organization while fostering accountability and informed decision-making
Technical/Business Requirements:
- Bachelor's degree in Computer Science, Information Security, Information Systems, Engineering or a related discipline
- 10+ years of progressive experience in cyber security, information security or technology risk management
- Minimum 5 years of leadership experience in cyber security, technology or risk management functions
- Experience leading enterprise cyber security programs within complex, multi-site or multi-business-unit organizations
- Strong understanding of cyber governance, risk management, security operations, vulnerability management, incident response, resilience and compliance requirements
- Experience developing cyber security strategies, roadmaps and investment priorities aligned with business objectives
- Demonstrated experience working with executive leaders, business stakeholders and external service providers
- Experience managing third-party cyber risk, supplier security programs, and technology vendor relationships
- Exposure to industrial, manufacturing, or operational technology (OT) environments is considered an asset
- Professional certifications such as CISSP, CISM, CCSP, GICSP, or equivalent are considered assets
Leadership Requirements:
- Strategic leadership and enterprise thinking
- Executive presence and influence
- Risk assessment and decision-making
- Relationship building and stakeholder management
- Business partnership and advisory capability
- Change leadership and continuous improvement mindset
- Strong communication and executive reporting skills
As a member of the OSCO Construction Group, we offer a comprehensive compensation package including health and dental coverage, life insurance, RRSP and tax-free savings account options. Additionally, we offer educational bursaries to children of employees, health & wellness programming, celebratory events and employee sport team sponsorships.
About OSCO
The origins of the OSCO Construction Group go back to 1955 when Ocean Steel & Construction Ltd. was founded in Saint John, New Brunswick. Since that time, the OSCO Construction Group has grown to encompass four main operating sectors: Steel, Concrete, Construction and Corporate. Within these sectors lie an ever-expanding number of companies and divisions, serving a growing market area and employing over twelve hundred employees.