Lead, Cybersecurity Programs - Toronto
1 day ago

Job description
Job SummaryReporting directly to the Director, Cybersecurity, the Lead, Cybersecurity Programs at Porter is tasked with validating and implementing the controls used to secure the company's digital frontier. This role encompasses working within and enforcing a comprehensive cybersecurity strategy, anchored in the rigorous standards set by the NIST Cybersecurity Framework and NIST guidelines.
A critical component of this strategy is the maintaining of a 24/7 cybersecurity operation to ensure Porter's preparedness against cyber threats with optimized response times. Additionally, the Program Lead is responsible for validating and remediating robust data security and privacy protocols to safeguard Porter's sensitive information, incorporating data classification, encryption, and compliance with data protection laws. The Program Lead is expected to review and deliver on projects with the goal of improving upon Porter's cybersecurity posture.
Additional scope of this role includes reporting on the enforcement of cybersecurity standards across IT and business sponsored projects, monitoring a proactive cyber defence infrastructure, monitoring organizational cybersecurity awareness and providing regular cybersecurity reports. The Lead, Cybersecurity Programs will work with third-party vendors to help bolster Porter's cybersecurity defences, ensuring adaptability and strength in the face of evolving cyber threats.
The success of the role will be measured by their ability to assist to achieve targeted maturity levels within the NIST framework, contributing to significantly reduce incident response times, helping to decrease vulnerabilities and breaches, validating participation in cybersecurity awareness within the organization, working with third-party vendors collaboratively, and securing necessary industry or regulatory cybersecurity certifications.
Duties & Responsibilities- Cybersecurity Framework Implementation: Implementation of Porter's cybersecurity strategy, guided by the NIST Cybersecurity Framework and NIST guidelines, to ensure a robust cybersecurity posture.
- Embed Cyber Principles in Design: Review the design of business sponsored projects to ensure adherence to controls, standards and policies.
- Enhance Cybersecurity Posture: Deliver projects in a timely manner with this goal in mind.
- Participate in 24/7 Cybersecurity Monitoring: Participate in a 24/7 cybersecurity monitoring, detection, and response operation, equipped with advanced technologies such as Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and Endpoint Detection and Response (EDR), aiming to optimize incident response times (Mean Time to Detect - MTTD and Mean Time to Respond - MTTR), ensuring Porter's readiness to rapidly address and neutralize threats.
- Data Security and Privacy: Participate in the implementation of comprehensive data security and privacy measures, ensuring the protection and confidentiality of Porter's sensitive information. This includes implementing data classification, encryption strategies, and access controls, as well as ensuring compliance with relevant data protection regulations.
- Work with Cybersecurity Standards: Work within the cybersecurity standards for IT projects to ensure compliance, aligning project objectives with Porter's cybersecurity strategy and minimizing risks.
- Defend all assets: Participate in providing a comprehensive cyber defence function that includes vulnerability management and ethical hacking to proactively secure Porter's IT and OT systems against potential breaches.
- Ensure Organizational Cybersecurity Awareness: Ensire ongoing cybersecurity awareness training participation, help organize regular phishing simulations, and participate in tabletop exercises to bolster organizational resilience against cyber threats.
- Develop Third-Party Vendor Relationships: Build collaborations and participate with third-party vendors to supplement and enhance Porter's cybersecurity capabilities, ensuring alignment with our strategic defence objectives. This includes managing external engagements for penetration testing of internal and external applications and networks.
- Monitor Success and Compliance: Develop reports on key performance indicators related to cybersecurity readiness, incident response times, compliance rates with cybersecurity standards, and effectiveness of cybersecurity awareness programs.
- Foster a Culture of Continuous Improvement: Encourage an environment of continuous learning and development within the cybersecurity team, promoting innovation and proactive approaches to cybersecurity challenges.
- Lead by Example: Model leadership that prioritizes security, demonstrating commitment to protecting Porter's assets and data through actions, collaboration and a hands-on approach to cybersecurity management.
- Actively participates in Porter's Safety Management System (SMS) including, reporting hazards and incidents encountered in daily operations; understand, comply and promote the Company Safety Policy.
- Other Duties as Assigned
Concern for Safety: Identifying hazardous or potentially hazardous situations and taking appropriate action to maintain a safe environment for self and others.
Teamwork: Working collaboratively with others to achieve organizational goals.
Passenger/Customer Service: Providing service excellence to internal and/or external customers (passengers).
Initiative: Dealing with situations and issues proactively and persistently, seizing opportunities that arise.
Results Focus: Focusing efforts on achieving high quality results consistent with the organization's standards.
Fostering Communication: Listening and communicating openly, honestly, and respectfully with different audiences, promoting dialogue and building consensus.
- Bachelor's degree in Computer Science, Information Security, Engineering, Business Administration, or a closely related field.
- Cybersecurity certifications (SANS, CEH, ISACA, OffSec, CompTIA as examples)
- Proven experience in IT and cybersecurity, including 24/7 operations and familiarity with NIST frameworks.
- Cybersecurity related project delivery and project analysis experience
- Proven experience in cybersecurity programs, operational leadership, and fostering a culture of cybersecurity awareness and resilience.
- Demonstrable expertise in penetration tests, vulnerability assessment, and security monitoring
- Experience with cloud and local network infrastructure and security tools.
- Collaborative skills for working across teams and with external partners to enhance cybersecurity defences.
Toronto Downtown Office (250 Yonge Street) #LI-Hybrid
Company DescriptionSince 2006, Porter Airlines has been elevating the experience of economy air travel for every passenger, providing genuine hospitality with style, care and charm. Porter's fleet of Embraer E195-E2 and De Havilland Dash 8-400 aircraft serves North America, including a coast-to-coast domestic Canadian network, the U.S., Mexico, the Caribbean and Central America. Headquartered in Toronto, Porter is an Official 4 Star Airline in the World Airline Star Rating. Visit or follow @porterairlines on Instagram, Facebook and X.
Similar jobs
The Lead, · Cybersecurity Programs at Porter is tasked with validating and implementing the controls used to secure the company's digital frontier. · This role encompasses working within and enforcing a comprehensive cybersecurity strategy, ...
2 weeks ago
Validating and implementing controls to secure · Porter's digital frontier.Cybersecurity strategy anchored in NIST Cybersecurity Framework and guidelines. · ...
2 weeks ago
Lead large-scale, high-risk cybersecurity programs focused on Detection Engineering, SIEM, and Threat Intelligence to protect Critical Valued Assets. · ...
3 weeks ago
Lead large-scale, high-risk cybersecurity programs focused on Detection Engineering · , SIEM, · and Threat Intelligence to protect Critical Valued Assets. · ...
3 weeks ago
We don't just help students become job-ready graduates – we ignite futures. · As Canada-owned private career college, · our vision is bold, · our mission is clear, · and our values run deep.Credential level expectations · A program that meets government degree level standards inc ...
1 month ago
We are looking for a Cybersecurity Manager 1 to join our team in Toronto, ON. The successful candidate will be responsible for analyzing program security needs and determining security objectives. · ...
2 weeks ago
We're seeking a Senior OT Cybersecurity Leader with strong strategic and technical skills to support the growth of our expertise and our industrial control systems (ICS) cybersecurity team. · ...
3 weeks ago
The Cybersecurity Advisor ensures consistency of project solutions that are cyber secure by design. That is, · according to defined cybersecurity policy, technical roadmap, and Customer requirements/needs.Overseeing and maintaining the cybersecurity process that includes defining ...
1 week ago
We're looking for a full-time Network Security Intern in Toronto. You'll work alongside collaborative teammates to reduce Canada's busiest public transit system's carbon footprint by contributing to the On-Corridor Works project. · Taking on network security tasks in a cutting-ed ...
1 week ago
The Chief Technology Officer (CTO) provides visionary leadership and strategic direction for the hospital's digital infrastructure,cybersecurity,and telecommunications systems. · ...
1 month ago
We are expanding our Cyber practice in Canada and are looking for Consultants with hands-on experience across cybersecurity, information security, GRC. · The Role · We will work closely with clients to help them understand threats, · assess risks, · and implement practical soluti ...
1 month ago
We are seeking a highly skilled Client Experience Specialist to join our team. · ...
1 month ago
WoodGreen is seeking a Cybersecurity Lead to oversee its cybersecurity function ensuring proactive monitoring detection and response to threats through its Security Operations Centre SOC This role drives operational excellence in security processes manages incident response and c ...
1 month ago
Cyber Security Consultant Intern - (May 2026 - 12 months - Toron
Only for registered members
A career in IBM Consulting is rooted by long term relationships and close collaboration with clients across the globe.Develop an understanding of our client's future state cybersecurity goals and processes, then define the steps needed and leading technologies to help turn their ...
1 month ago
e-zinc is expanding its team to bring transformative technology to market and support the future of renewable energy. · develop and execute e-zinc's it strategy aligned with business growth manufacturing scale-up and technology roadmaps. · ...
3 weeks ago
We're looking for an experienced Cyber Incident Response Team Manager to join our team at Canadian Tire Corporation Limited. The successful candidate will have 5+ years of experience working in or leading a SOC/CIRT teams. · This is an exciting opportunity for someone who wants t ...
1 month ago
Cyber and Forensic Technology Consulting Analyst/Associate Intern (Summer 2026)
Only for registered members
Job summary:Our Summer Analyst/Associate Internship program mirrors the analyst experience to give you an understanding of our business and experience project work at Charles River Associates. ...
3 weeks ago
We have an immediate need for a Senior Product Manager to oversee the full lifecycle of the Silo platform. This candidate will guide investment and organizational focus from product concept, development, market positioning and placement, through post-sales engagement. · ...
1 month ago
Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting nearly 10,000 organizations from unknown threats using its proprieta ...
2 hours ago
Join our dynamic and rapidly growing team as an IT Project Manager and collaborate with top-notch professionals to deliver complex IT initiatives that drive real business outcomes. · ...
1 month ago