Durham College

Principal Investigator, Cybersecurity

Durham College · Oshawa, Ontario, Canada · CA$119K/yr

Higher Education · 11-50 employees

Yesterday
Mid (2-5 yrs) Part-time Contractor Canada
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Principal Investigator will oversee the development of cybersecurity solutions for industry partners through applied research and knowledge transfer projects. They are responsible for managing compliance programs, conducting risk assessments, and coordinating external audits.

What they look for

Cybersecurity Compliance Governance Risk Assessment SOC 2 Type 2 ISO 27001 NIST SP 800-53 Cloud Security Internal Audits Remediation Planning Vendor Risk Management Information Security Project Management Technical Documentation Gap Analysis

Requirements

Candidates must have an undergraduate degree in a relevant field and three to five years of industry experience, including specific expertise in GRC and compliance frameworks. Strong communication skills and the ability to manage security controls across cloud and on-premises environments are required.

Full description

Principal Investigator, Cybersecurity COMPETITION NO. ADP23-03

About Durham College: Durham College (DC) is a leading post-secondary institution that supports students to develop career-ready skills for the ever-changing job market. With a focus on experiential learning through field placements, applied research, co-ops and other hands-on opportunities, DC grads are known for having the skills and knowledge they need to adapt to the ever-changing workforce.

A leader in innovative teaching and learning, Durham College offers a wide range of market-driven programs across multiple disciplines, including culinary management, farming and horticulture, business, IT, construction and trades, science and technology, health care, engineering, social and community services, media, art and design.

Our modern campuses in Oshawa and Whitby offer 145 programs – including six bachelor’s degrees and 11 apprenticeship programs – to more than 11,000 full-time post-secondary and nearly 3,000 apprenticeship students. In addition, we have more than 16,000 student registrations in professional and part-time learning. More than 120,000 alumni represent the college, both locally and around the world.

DC has an estimated annual economic impact of more than $913 million on Durham Region and is proud to be an active and engaged member of the communities we serve by contributing resources and expertise to enhance social and economic well-being through partnerships, investments and collaboration.

Durham College is seeking experienced and motivated professionals who share our commitment to quality and student success. The Office of Research Services, Innovation and Entrepreneurship is currently seeking applications from qualified individuals who are interested in joining the Centre for Cybersecurity Innovation, on a part-time, project-based contract to oversee the development of real-world solutions for industry partners through applied research and knowledge transfer projects.

Teams of expert faculty, students and recent graduates collaborate with industry partners and their staff to deliver innovative cybersecurity-based solutions to pressing business problems and opportunities. Projects can include producing and testing prototypes, evaluating new technologies, and developing new or improved products or processes for small- and medium-sized businesses (SMEs). All projects are funded by provincial or federal government grants.

The Centre for Cybersecurity Innovation is located at the Oshawa Campus and provides SMEs access to facilities, equipment, technical expertise, and project services to assist them in product development, technology adoption, expansion into new markets and commercialization of new products, services and processes.

Position Information: Hourly Rate: $57.41 Hours: Up to 24 hours per week, Monday to Friday. Reporting To: Director, Applied Research Vacancy Status: This posting is part of an ongoing recruitment process to maintain an applicant pool. Recruitment is continuous and dependent on project needs; candidates may be contacted as new projects arise

Duties and Responsibilities:

The responsibilities of a Principal Investigator include, but are not limited to:

  • Develop, review, and

update security policies, procedures, and governance documentation to meet compliance standards.

  • Conduct comprehensive

gap assessments against relevant frameworks, identify areas of non-compliance, and recommend actionable remediation steps.

  • Lead the implementation,

maintenance, and continuous improvement of SOC 2 Type 2, ISO 27001, and NIST SP 800-53/800-171 compliance programs.

  • Design, implement, and

document security controls across cloud and on-premises environments, ensuring alignment with framework requirements.

  • Develop and manage

remediation plans, conduct internal audits and readiness assessments, and track progress toward compliance objectives.

  • Perform risk

assessments, maintain risk registers, and support third-party/vendor risk management processes. Assess and enhance the security of cloud infrastructure, ensuring compliance with SOC 2, ISO 27001, and NIST requirements.

  • Coordinate and support

external audits, manage evidence collection, and serve as the primary liaison with auditors.

Qualifications:

The ideal candidate will meet or exceed the following qualifications:

  • An undergraduate degree in Cybersecurity, Information Technology,

Business or a related field, preferably a masters degree.

  • Three to five years of relevant industry experience and demonstrated

ability in fields and technologies relevant to project opportunities

  • 3+ years of experience

in GRC, information security, or compliance roles.

  • In-depth knowledge of

SOC 2 Type 2, ISO 27001, and NIST frameworks.

  • Experience with gap

analysis, internal audits, and remediation planning.

  • Strong understanding of

cloud security principles and cloud infrastructure (AWS, Azure, GCP, etc.).

  • Familiarity with GRC and

audit management tools (e.g., Secureframe, Drata, Vanta, Sprinto).

  • Excellent written and

verbal communication skills; ability to communicate complex compliance requirements to technical and non-technical audiences.

  • Strong organizational

and project management abilities.

  • Experience developing

and maintaining security policies and governance documentation.

  • Ability to work

independently and collaboratively in a fast-paced environment.

The ideal candidate will possess the following qualifications:

  • ISO/IEC 27001 Lead Auditor/Implementer, CISA, CRISC, CGRC,

or similar certifications.

  • Experience supporting SOC 2 Type 2, ISO 27001, or NIST

certification and audit processes.

  • Knowledge of vulnerability management, SIEM, and cloud

security assessment tools.

  • Experience in SaaS or cloud-native environments.

Please apply below by submitting your cover letter and resume to the online portal. Competition number ADP23-03.

Contact Us T:905.721.3073 HumanResources@durhamcollege.ca C Wing, Second Floor - 2000 Simcoe St. N. Oshawa, ON

Durham College invites applications from all qualified individuals. Durham is committed to fostering workplace diversity, and, provides accommodations to applicants with disabilities throughout our hiring process. If you require this information in alternate format; require communication supports; an accommodation in applying for a posting and/or if you are selected for an interview, please contact our Human Resources (HR) department and an HR assistant will work with you to meet your needs.

We thank you for your interest in employment with Durham College however, only those candidates selected for an interview will be contacted.

Land Acknowledgement Durham College is situated on the traditional lands of the First Peoples of the Mississaugas of Scugog Island First Nation. These lands are covered under the Williams Treaties and rest within the traditional territory of the Anishinaabeg. We offer our gratitude to the Indigenous Peoples who care for and, through the treaty process, share the lands on which we live, learn, teach and prosper today.