Back to job search
OC
OSCO Construction GroupVerified Job Source

Director, IT Cyber Security & Resilience

The Director leads the enterprise cyber security strategy, governance, and resilience initiatives across the organization. They partner with executive leadership to align security priorities with business objectives while overseeing risk reduction and incident response programs.

  • On-site
  • Saint John, NB
  • Posted Aug 26, 2026
  • 1 position

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Job summary

Job Summary: The Director, IT Cyber Security & Resilience is responsible for leading and advancing cyber security, risk management and resilience across Ocean Capital Group and its operating companies. This role provides enterprise leadership for cyber strategy, governance, risk reduction, incident response, third-party security and business resilience while ensuring the protection of technology assets, operational environments and information. Working closely with executive leadership, business stakeholders, Enterprise Risk and IT teams, the Director develops practical and scalable cyber security solutions that support business continuity, operational performance, growth and responsible risk management. The role serves as a trusted advisor to the business, balancing security requirements with organizational objectives and operational realities. Responsibilities: * Lead the organization's cyber security strategy, roadmap, governance framework and resilience initiatives across the enterprise * Partner with executive leaders, operating companies and business stakeholders to align cyber security priorities with business objectives and risk tolerance * Provide leadership and oversight for cyber security operations, risk reduction activities, vulnerability management, control effectiveness and continuous improvement programs * Establish meaningful cyber security metrics, dashboards and reporting to communicate risks, performance, and improvement priorities to leadership * Embed secure-by-design principles into enterprise architecture, infrastructure, applications, projects, and operational processes * Review and provide security oversight for major technology initiatives, implementations and business transformation activities * Lead organizational preparedness for cyber incidents through effective governance, response planning, recovery capabilities and resilience testing * Partner with Enterprise Risk to strengthen incident response, disaster recovery, business continuity and enterprise resilience programs * Develop and maintain cyber security policies, standards, controls and governance practices that support compliance and risk management objectives * Lead third-party cyber risk management activities, including supplier assessments, security reviews, contractual requirements and ongoing monitoring of critical technology partners * Build and maintain relationships with external cyber security advisors, vendors and industry partners to support emerging threat awareness and best practices * Lead, develop and strengthen cyber security capabilities, awareness and culture across the organization while fostering accountability and informed decision-making Technical/Business Requirements: * Bachelor's degree in Computer Science, Information Security, Information Systems, Engineering or a related discipline * 10+ years of progressive experience in cyber security, information security or technology risk management * Minimum 5 years of leadership experience in cyber security, technology or risk management functions * Experience leading enterprise cyber security programs within complex, multi-site or multi-business-unit organizations * Strong understanding of cyber governance, risk management, security operations, vulnerability management, incident response, resilience and compliance requirements * Experience developing cyber security strategies, roadmaps and investment priorities aligned with business objectives * Demonstrated experience working with executive leaders, business stakeholders and external service providers * Experience managing third-party cyber risk, supplier security programs, and technology vendor relationships * Exposure to industrial, manufacturing, or operational technology (OT) environments is considered an asset * Professional certifications such as CISSP, CISM, CCSP, GICSP, or equivalent are considered assets Leadership Requirements: * Strategic leadership and enterprise thinking * Executive presence and influence * Risk assessment and decision-making * Relationship building and stakeholder management * Business partnership and advisory capability * Change leadership and continuous improvement mindset * Strong communication and executive reporting skills As a member of the OSCO Construction Group, we offer a comprehensive compensation package including health and dental coverage, life insurance, RRSP and tax-free savings account options. Additionally, we offer educational bursaries to children of employees, health & wellness programming, celebratory events and employee sport team sponsorships. About OSCO The origins of the OSCO Construction Group go back to 1955 when Ocean Steel & Construction Ltd. was founded in Saint John, New Brunswick. Since that time, the OSCO Construction Group has grown to encompass four main operating sectors: Steel, Concrete, Construction and Corporate. Within these sectors lie an ever-expanding number of companies and divisions, serving a growing market area and employing over twelve hundred employees.

What you’ll do

The Director leads the enterprise cyber security strategy, governance, and resilience initiatives across the organization. They partner with executive leadership to align security priorities with business objectives while overseeing risk reduction and incident response programs.

Requirements

Candidates must have a bachelor's degree in a relevant field and at least 10 years of progressive experience in cyber security or technology risk management. Strong leadership skills and experience managing enterprise-level security programs in complex organizations are required.

Benefits

• Health coverage • Dental coverage • Life insurance • RRSP • Tax-free savings account options • Educational bursaries • Health & wellness programming • Celebratory events • Employee sport team sponsorships

Listed skills

  • LeadershipPreferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cyber security strategy
  • Risk management
  • Governance
  • Incident response
  • Vulnerability management
  • Business resilience
  • Disaster recovery
  • Third-party risk management
  • Security operations
  • Compliance
  • Enterprise architecture
  • Leadership
  • Stakeholder management
  • Strategic planning
  • Operational technology
  • Cyber security metrics
  • Executive Presence
  • Change Leadership
  • Influencing Skills
  • Cyber Governance
  • Cyber Operations
  • Cyber Security Strategy
  • Operational Performance Management
  • Certified Cloud Security Professional (CCSP)
  • Influencing Without Authority
  • Accountability
  • Cyber Security Policies
  • Business Objectives
  • Resilience
  • Cyber Risk
  • Planning
  • GIAC Global Industrial Cyber Security Professional
  • Systems Engineering
  • Business Continuity
  • Dashboard
  • Management
  • Business Requirements
  • Business Transformation
  • Certified Information Systems Security Professional
  • Certified Information Security Manager
  • Decision Making
  • Communication
  • Computer Science
  • Continuous Improvement Process
  • Cyber Security
  • Design Elements And Principles
  • Disaster Recovery
  • Incident Response
  • GIAC Certifications
  • Scalability

Job areas

  • Security & Safety
  • Management & Leadership
  • Technology
  • Construction
  • Manufacturing
  • Director of Cyber Security
  • Cyber Security Manager / Administrator
  • Database and Network Professionals Not Elsewhere Classified
  • Information Security Engineers
  • Computer Occupations, All Other

Additional details

Minimum education
Bachelor’s degree
Minimum experience
10+ years
Posting language
English
Working hours
40 hours per week