Associate Director, Cybersecurity Governance, Risk & Compliance
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Staff - Non Union
Job TitleAssociate Director, Cybersecurity Governance, Risk & Compliance
DepartmentOCIO | Chief Information Security Office
Compensation$13,137.75 - $20,502.83 CAD Monthly
Posting End DateJuly 26, 2026 (Applications accepted until 11:59 PM on the posting end date)
Job SummaryThe Associate Director, Cybersecurity Governance, Risk, and Compliance oversees the portfolio of services delivered as part of the Compliance and Risk Assessment team of the UBC Privacy & Information Security Management (PrISM) initiative. The function reports directly to the Chief Information Security Officer (CISO) and the Executive Director, Safety and Risk Services and ensures that cybersecurity risks are identified, communicated, and managed in collaboration with the CIO, CISO, and Enterprise Risk Management team.
The role establishes and sustains second‑line risk management processes, leads the Risk and Compliance team in optimizing risk assessment practices, and improves institutional visibility of cybersecurity and privacy‑related risks through training and compliance.
- Leads the teams responsible for identifying, interpreting, and communicating privacy and information security related risks across the University.
- Develops and maintains the practices and processes to address significant privacy and information security risks relating to UBC electronic information and systems.
- Leads the development of a risk register aligned with Enterprise Risk Management processes and translates operational technology risk information into clear institutional insights for the CIO, executive leadership, and governance bodies.
- Provides strategic risk advice to leadership regarding institutional exposure to technology risks including cybersecurity, system resilience, third‑party dependencies, and emerging technologies as they relate to privacy and information security.
- Oversees the enterprise Privacy Impact and Security Threat Risk Assessment services, ensuring continuous improvement of processes and practices.
- Provides privacy and cybersecurity risk advisory services and methodologies to complex digital initiatives, technology‑enabled transformation programs, and major institutional technology investments.
- Advises on risks associated with emerging technologies such as artificial intelligence, advanced analytics, and digital platforms as they relate to privacy and information security.
- Leads the development of institutional responses to technology‑related risk where mitigation requires a coordinated response beyond the scope of Information Technology.
- Directs the Information Security Compliance Support Program and related risk‑based compliance initiatives.
- Ensures technology risk and compliance activities align with institutional policy frameworks, risk appetite, and evolving regulatory expectations.
- Leads the development of governance processes and practices at the local level with Faculties and Academic Units to support efficient, consistent, and operationally aligned IT risk assessment and management.
- Participates in the development of UBC‑wide rules pertaining to the use, management, and security of UBC electronic information and systems.
- Leads and mentors a multidisciplinary team delivering technology risk and compliance services, fostering collaboration across governance, risk, and technology communities.
The Associate Director has a dual reporting relationship to the Chief Information Security Officer (CISO) and the Executive Director, Safety and Risk Services. The role closely collaborates with Enterprise Risk and Assurance and the CIO portfolio to integrate technology risk insights into the Institutional Risk Register and enterprise risk governance processes.
Consequence of ErrorThis role is critical to ensuring that the University understands the gaps and resulting exposure related to information technology management. Failure to identify, interpret, or communicate technology‑related risks can result in privacy or cybersecurity breaches, operational…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: