Principal Investigator, Cybersecurity
- Oshawa, ON
- On-site
- Posted Aug 7, 2026
- 1 position
$57 / hour
Opens an external site
- Employment type
- Part-time, Contract
- Experience level
- Mid-level · 2+ years
- Minimum education
- Bachelor’s degree
- Posting language
- English
- Working hours
- 24 hours per week
Job summary
The Principal Investigator will oversee the development of cybersecurity solutions for industry partners through applied research and knowledge transfer projects. They are responsible for managing compliance programs, conducting risk assessments, and coordinating external audits.
Job details
Principal Investigator, Cybersecurity COMPETITION NO. ADP23-03 About Durham College: Durham College (DC) is a leading post-secondary institution that supports students to develop career-ready skills for the ever-changing job market. With a focus on experiential learning through field placements, applied research, co-ops and other hands-on opportunities, DC grads are known for having the skills and knowledge they need to adapt to the ever-changing workforce. A leader in innovative teaching and learning, Durham College offers a wide range of market-driven programs across multiple disciplines, including culinary management, farming and horticulture, business, IT, construction and trades, science and technology, health care, engineering, social and community services, media, art and design. Our modern campuses in Oshawa and Whitby offer 145 programs – including six bachelor’s degrees and 11 apprenticeship programs – to more than 11,000 full-time post-secondary and nearly 3,000 apprenticeship students. In addition, we have more than 16,000 student registrations in professional and part-time learning. More than 120,000 alumni represent the college, both locally and around the world. DC has an estimated annual economic impact of more than $913 million on Durham Region and is proud to be an active and engaged member of the communities we serve by contributing resources and expertise to enhance social and economic well-being through partnerships, investments and collaboration. Durham College is seeking experienced and motivated professionals who share our commitment to quality and student success. The Office of Research Services, Innovation and Entrepreneurship is currently seeking applications from qualified individuals who are interested in joining the Centre for Cybersecurity Innovation, on a part-time, project-based contract to oversee the development of real-world solutions for industry partners through applied research and knowledge transfer projects. Teams of expert faculty, students and recent graduates collaborate with industry partners and their staff to deliver innovative cybersecurity-based solutions to pressing business problems and opportunities. Projects can include producing and testing prototypes, evaluating new technologies, and developing new or improved products or processes for small- and medium-sized businesses (SMEs). All projects are funded by provincial or federal government grants. The Centre for Cybersecurity Innovation is located at the Oshawa Campus and provides SMEs access to facilities, equipment, technical expertise, and project services to assist them in product development, technology adoption, expansion into new markets and commercialization of new products, services and processes. Position Information: Hourly Rate: $57.41 Hours: Up to 24 hours per week, Monday to Friday. Reporting To: Director, Applied Research Vacancy Status: This posting is part of an ongoing recruitment process to maintain an applicant pool. Recruitment is continuous and dependent on project needs; candidates may be contacted as new projects arise Duties and Responsibilities: The responsibilities of a Principal Investigator include, but are not limited to: Develop, review, and update security policies, procedures, and governance documentation to meet compliance standards. Conduct comprehensive gap assessments against relevant frameworks, identify areas of non-compliance, and recommend actionable remediation steps. Lead the implementation, maintenance, and continuous improvement of SOC 2 Type 2, ISO 27001, and NIST SP 800-53/800-171 compliance programs. Design, implement, and document security controls across cloud and on-premises environments, ensuring alignment with framework requirements. Develop and manage remediation plans, conduct internal audits and readiness assessments, and track progress toward compliance objectives. Perform risk assessments, maintain risk registers, and support third-party/vendor risk management processes. Assess and enhance the security of cloud infrastructure, ensuring compliance with SOC 2, ISO 27001, and NIST requirements. Coordinate and support external audits, manage evidence collection, and serve as the primary liaison with auditors. Qualifications: The ideal candidate will meet or exceed the following qualifications: An undergraduate degree in Cybersecurity, Information Technology, Business or a related field, preferably a masters degree. Three to five years of relevant industry experience and demonstrated ability in fields and technologies relevant to project opportunities 3+ years of experience in GRC, information security, or compliance roles. In-depth knowledge of SOC 2 Type 2, ISO 27001, and NIST frameworks. Experience with gap analysis, internal audits, and remediation planning. Strong understanding of cloud security principles and cloud infrastructure (AWS, Azure, GCP, etc.). Familiarity with GRC and audit management tools (e.g., Secureframe, Drata, Vanta, Sprinto). Excellent written and verbal communication skills; ability to communicate complex compliance requirements to technical and non-technical audiences. Strong organizational and project management abilities. Experience developing and maintaining security policies and governance documentation. Ability to work independently and collaboratively in a fast-paced environment. The ideal candidate will possess the following qualifications: ISO/IEC 27001 Lead Auditor/Implementer, CISA, CRISC, CGRC, or similar certifications. Experience supporting SOC 2 Type 2, ISO 27001, or NIST certification and audit processes. Knowledge of vulnerability management, SIEM, and cloud security assessment tools. Experience in SaaS or cloud-native environments. Please apply below by submitting your cover letter and resume to the online portal. Competition number ADP23-03. Contact Us T:905.721.3073 HumanResources@durhamcollege.ca C Wing, Second Floor - 2000 Simcoe St. N. Oshawa, ON Durham College invites applications from all qualified individuals. Durham is committed to fostering workplace diversity, and, provides accommodations to applicants with disabilities throughout our hiring process. If you require this information in alternate format; require communication supports; an accommodation in applying for a posting and/or if you are selected for an interview, please contact our Human Resources (HR) department and an HR assistant will work with you to meet your needs. We thank you for your interest in employment with Durham College however, only those candidates selected for an interview will be contacted. Land Acknowledgement Durham College is situated on the traditional lands of the First Peoples of the Mississaugas of Scugog Island First Nation. These lands are covered under the Williams Treaties and rest within the traditional territory of the Anishinaabeg. We offer our gratitude to the Indigenous Peoples who care for and, through the treaty process, share the lands on which we live, learn, teach and prosper today.
What you’ll do
The Principal Investigator will oversee the development of cybersecurity solutions for industry partners through applied research and knowledge transfer projects. They are responsible for managing compliance programs, conducting risk assessments, and coordinating external audits.
Requirements
Candidates must have an undergraduate degree in a relevant field and three to five years of industry experience, including specific expertise in GRC and compliance frameworks. Strong communication skills and the ability to manage security controls across cloud and on-premises environments are required.
Listed skills
- Project management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity
- Compliance
- Governance
- Risk Assessment
- SOC 2 Type 2
- ISO 27001
- NIST SP 800-53
- Cloud Security
- Internal Audits
- Remediation Planning
- Vendor Risk Management
- Information Security
- Project Management
- Technical Documentation
- Gap Analysis
- Certified Information System Auditor (CISA)
- Cloud-Native Computing
- Culinary Management
- Business Problems
- Talent Management
- NIST 800-53
- Audit Processes
- Evidence Collection
- Knowledge Transfer
- Planning
- Research
- Amazon Web Services
- Applied Research
- Teaching
- Auditing
- Audit Management
- Microsoft Azure
- Service Innovation
- Software As A Service (SaaS)
- Cloud Infrastructure
- Commercialization
- Communication
- Information Technology
- Continuous Improvement Process
- Security Controls
- Certified In Risk And Information Systems Control
- Cyber Security
- Entrepreneurship
- External Auditing
- Governance Risk Management And Compliance
- Horticulture
- Innovation
- ISO/IEC 27001
- Risk Management
- New Product Development
Job areas
- Technology
- Security & Safety
- Science & Research
- Education
- Principal Investigator
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Connectability Inc.
Technical Sales Specialist
Direct employerEasy Apply- Hybrid
- Posted Sep 5, 2026
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Direct employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 17, 2026
Government of Ontario
Registered Nurse
SponsoredDirect employerEasy Apply- On-site
- Lindsay, ON
- Posted Sep 17, 2026
