Back to job search
LHH Knightsbridge logo

Interim Chief Information Security Officer

  • Toronto, ON
  • Hybrid
  • Posted Oct 4, 2026
  • 1 position

Opens LinkedIn

Sign in to save this job
Employment type
Contract
Experience level
Lead · 10+ years
Minimum education
Professional degree
Posting language
English
Working hours
40 hours per week
Seniority
Executive
Application method
Direct apply is available

Job summary

Lead the institution’s information security strategy, governance, operations, and risk management, including regulatory compliance, AI and cloud security, third-party assessments, and incident response. Report security risks and performance to executives and the Board, build security awareness and partnerships, and lead the IT security team and service delivery.

Job details

IMMEDIATE INTERIM OPPORTUNITY Interim Chief Information Security Officer Reports to Chief Information Officer Duration: 4-6 Months Location: Toronto Hybrid working Our client, a leading academic institution, is making a significant investment in information security through the creation of a new Chief Information Security Officer position reporting to the CIO. This is an exceptional opportunity for a seasoned security leader to provide both strategic advice and operational leadership while building and strengthening this critical function. Working across the institution, the CISO will define the strategy, governance, policies and capabilities required to deepen and broaden information security, protect data and effectively manage evolving cyber risks. This is a highly purposeful mandate for someone who has built or transformed a security function before and wants to make a lasting impact within an important Canadian institution. RESPONSIBILITIES: Strategy and Governance Oversee institution-wide security resources and advise on policy, legislation, regulation, and technology. Lead security policies and practices that protect data and ensure compliance. Manage regulatory compliance, including Ontario’s Enhancing Digital Security and Trust Act (2024), required contacts, biennial assessments, incident reporting, and executive and Board updates. Assess AI-related threats, defenses, adoption risks, phishing, agentic attacks, and third-party data leakage. Embed security controls in AI governance with the future Office of AI and key stakeholders. Maintain cyber insurance eligibility and advise on coverage and risk transfer. Support cloud adoption through risk-based vendor assessments and shared-responsibility guidance. Risk Management and Compliance Assess security controls and advise executives on improvements. Identify security risks and monitor compliance with standards and policies. Lead third-party risk management, including HECVAT reviews, SOC 2 Type II attestations, cloud assessments, and shared-responsibility guidance. Coordinate and track security audits, findings, timelines, and outcomes. Align records retention and data disposal with policy, legislation, privacy, and cybersecurity requirements. 2. Security Operations and Technology Implement technical standards, services, and tools that reduce cyber risk. Coordinate vulnerability assessments and promote effective security practices. Lead response and communications for suspected and confirmed incidents. Maintain incident response protocols and conduct regular tabletop exercises. Maintain continuity, succession, and cross-training plans for disrupted operations. 3. Reporting, Metrics, and Board Accountability Report cybersecurity risk, control effectiveness, and strategy to executives and the Board Audit & Risk Committee. Maintain metrics for maturity, insurance, third-party ratings, vulnerabilities, and training completion. Present the security dashboard on an established schedule. Education, Awareness, and Security Culture Lead security awareness programs and set measurable training targets for staff, faculty, and students. Report training completion and remediation plans to executives and the Board. Track higher-education security issues and consult governments and industry partners. Support cybersecurity-related academic programs as needed. External Partnerships and Collaboration Represent the organization in multi-agency threat-sharing, incident planning, and tabletop exercises. Partner with Privacy, Legal, Communications, and academic leaders on security matters. People Leadership Lead, coach, and develop IT security staff within a client-focused culture. Oversee service quality, efficiency, stakeholder engagement, and SLAs. Build recruitment and retention plans that strengthen business and technical capability. Duties may change based on organizational needs and CIO direction. REQUIRED SKILLS/ABILITIES: Expert knowledge of NIST, ISACA, CIS Controls, and applicable legislation, including Ontario’s Enhancing Digital Security and Trust Act, FIPPA, PIPEDA, and PHIPA. Strong understanding of AI-enabled threats, defensive tools, vendor capabilities, and institutional AI risk. Knowledge of nation-state threats and geopolitical risks affecting Canadian post-secondary institutions. Expertise in network, endpoint, cloud, identity, vulnerability, and incident response security. Proven ability to develop cybersecurity strategy, assess risk, prioritize threats, and implement mitigation plans. Strong leadership, change management, negotiation, influencing, and decision-making skills. Experience leading teams, projects, budgets, workforce planning, and service delivery. Excellent communication skills, including executive and Board-level reports and policies. Ability to perform effectively under ambiguity and pressure. Proven vendor, contractor, and third-party negotiation skills. Results-oriented and financially astute, with strong fiduciary judgment. EDUCATION AND EXPERIENCE: A master’s degree in information security, or other related field plus equivalent training and experience. Information security management qualifications such as CISSP (Certified Information Systems Security Professional), or CISM (Certified Information Security Manager). Minimum 10 years’ progressively responsible experience in computing and information security, network security issues, and security incident response or related information technology fields, preferably in a higher education or equivalent complex environment. Minimum 5 years of experience in senior leadership and people management. Experience developing and administering an IS program and IS policy and regulations in a complex environment. Expertise in cyber security, in strategic planning, change management, resource management and reporting PLEASE SEND YOUR CV (AS A WORD DOC) TO: Interim.Applications@LHHknightsbridge.com (Subject: Job Title) LHH Knightsbridge Interim Management is a service to help our clients address a wide range of scenarios including leadership support due to sudden departures, driving key change initiatives or leading transformation projects. Our interim executives step in with minimal downtime to meet specific objectives and deliver results. All have held senior positions in the past and have now chosen to offer their unique depth and breadth of experience to organizations on a limited engagement basis. Follow the LHH Knightsbridge LinkedIn page and set up a job alert to learn about new Executive Interim opportunities. Lee Hecht Harrison Knightsbridge Corp. is committed to providing equitable treatment and accommodation to ensure a barrier-free recruitment process. In accordance with the Ontario Human Rights Code, Accessibility for Ontarians with Disabilities Act and our AODA policy, a request for accommodation will be accepted as part of the hiring process. If you require accommodation to apply or if selected to participate in an assessment process, please provide your accommodation needs in advance to the Recruitment Lead for this opportunity. We thank all interested candidates in advance; however, only individuals selected for interviews will be contacted. October 2026

What you’ll do

Lead the institution’s information security strategy, governance, operations, and risk management, including regulatory compliance, AI and cloud security, third-party assessments, and incident response. Report security risks and performance to executives and the Board, build security awareness and partnerships, and lead the IT security team and service delivery.

Requirements

Requires a master’s degree in information security or a related field, relevant security management qualifications such as CISSP or CISM, and at least 10 years of progressively responsible information security or related IT experience. Candidates must also have at least five years of senior leadership and people management experience, with expertise in security programs, strategy, risk, and complex environments.

Listed skills

  • Risk Management · Preferred
  • Regulatory Compliance · Preferred
  • People leadership · Preferred
  • Change Management · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cybersecurity Strategy
  • Security Governance
  • Risk Management
  • Regulatory Compliance
  • Incident Response
  • Cloud Security
  • Third-Party Risk Management
  • AI Security
  • Vulnerability Management
  • Security Auditing
  • Security Awareness Training
  • Board-Level Reporting
  • People Leadership
  • Change Management
  • Vendor Negotiation
  • NIST, ISACA, and CIS Controls

Job areas

  • Security & Safety
  • Technology
  • Management & Leadership
  • Education
  • Government & Public Sector

More jobs from LHH Knightsbridge

See all jobs from LHH Knightsbridge