Elexicon Energy is the fourth-largest municipally owned electricity distributor in Ontario. Our mission is to provide our customers with reliable, affordable energy services and to continuously improve to meet their needs, while ensuring the needs of our shareholders are met through sustainable growth.
WHY JOIN OUR TEAM?
At Elexicon Energy we believe in living and leading our values through our daily actions. Our people are passionate about what they do and are engaged in day-to-day operations, projects and initiatives to support Our Why of empowering the communities we serve and helping customers create the possibilities that energize their future. This is an exciting time to join our growing team as we develop the strategies and plans to support a new brand and vision for customer centricity and operational excellence!
The Supervisor, Cyber Security is a well-rounded leader, equally adept in security governance and hands-on technical execution. As the operational lead of Elexicon's cyber security program, you will spend approximately half your time building and sustaining the governance structures that keep the organization aligned with cyber security frameworks and standards, and the other half performing technical work that brings those controls to life, such as configuring tooling, hardening systems, responding to incidents, and driving measurable security improvements across IT and OT environments.
This is a role for a practitioner who leads. The ideal candidate is equally comfortable writing policy as they are tuning custom detection rules, and equally confident preparing board-level risk reports as they are administering privileged access controls. Reporting to the Manager, Technology and Security Operations, this role works in close partnership with IT/OT teams, Enterprise Risk Management, Privacy and Information Management, and key external partners including Elexicon's managed security service provider and regulatory bodies.
DUTIES & RESPONSIBILITIES
Cyber Security Strategy, Architecture & Roadmap
- Own and deliver Elexicon's cyber security target-state architecture and multi-year maturity roadmap across IT, OT, cloud, identity, data, endpoint, and third-party environments — including current-state assessment, prioritized initiatives, investment planning, and measurable outcomes.
- Translate regulatory requirements, enterprise risk priorities, threat intelligence, and leading practices into a practical, funded program of work that improves security maturity and resilience over time.
- Define security reference architectures and control standards; lead security architecture reviews for major technology initiatives, vendor onboarding, cloud deployments, OT connectivity, and business transformation projects.
- Embed secure-by-design practices into technology delivery, procurement, cloud adoption, application changes, and OT modernization through architecture reviews, threat modelling, and control requirements.
- Define and maintain cyber security controls for AI-enabled tools, partnering with Privacy, Information Management, Legal, and business leaders to ensure AI adoption is secure, governed, and aligned with enterprise risk tolerance.
Governance, Risk & Compliance
- Lead the full lifecycle of Elexicon's cyber security policy suite — creation, review, approval, publication, exception management, versioning, and annual review — ensuring policies remain current, enforceable, and aligned with regulatory expectations.
- Own and maintain cyber security operational plans and playbooks (e.g., incident response, disaster recovery, access reviews, vulnerability response, vendor onboarding).
- Lead Elexicon's ongoing alignment with the Ontario Cyber Security Framework (OSCF), including self-assessments, evidence collection, regulatory submissions, remediation tracking, and support for OEB-mandated independent assessments.
- Maintain a control catalog mapped to OSCF, NIST CSF 2.0, and CIS Controls; manage the cyber risk register and associated remediation plans.
- Own cyber security dashboards and executive-level reporting for the Enterprise Risk Management (ERM) program, including security posture, risk exposure, Key Risk Indicators, and control effectiveness.
- Administer Elexicon's Third-Party Risk Management (TPRM) program: vendor due diligence, contractual cyber security requirements, ongoing assurance reviews, and findings remediation.
- Liaise with regulatory bodies and the Privacy and Information Management function on compliance obligations, privacy impact assessments, breach response, and records management; support internal and external audits.
Technical Security Operations
- Configure, manage, and tune security tooling across Elexicon's M365 and Azure environment, including Defender (Endpoint, Identity, Cloud Apps), Purview (DLP, data classification), and Conditional Access policies in Entra ID.
- Own the security monitoring and detection engineering lifecycle — log source strategy, custom detection rules, alert quality, threat hunting, escalation procedures, and MSSP/SOC performance management.
- Own vulnerability management end-to-end: scan execution and review, findings validation, remediation tracking, patching SLAs, and KRI reporting; manage endpoint security posture via Intune and Defender for Endpoint.
- Serve as Cyber Incident Response Lead: maintain the IR plan and playbooks, coordinate annual tabletop exercises, lead post-incident root cause analysis and enterprise-wide remediation, and ensure alignment with OEB incident reporting obligations.
- Establish and test cyber resilience capabilities, including ransomware response, immutable backup validation, critical system recovery plans, and break-glass access procedures across IT and OT environments.
- Administer and continuously improve cloud and identity security posture, including Secure Score initiatives, zero-trust access controls, and periodic access reviews enforcing RBAC/ABAC principles.
- Conduct technical security reviews of firewall rules, network segmentation, and OT access boundaries.
- Establish and maintain an OT cyber security program for SCADA, ADMS, DERMS, AMI, substations, and field communications — including asset visibility, secure remote access, segmentation, vendor access controls, and OT-specific incident response.
People Leadership & Program Operations
- Supervise, coach, and develop cyber security analysts; manage workload prioritization and performance.
- Manage relationships with managed security service providers and vendor performance.
- Own the security awareness training program; tailor campaigns by risk profile and track measurable behaviour change.
- Build effective partnerships with business leaders and foster a culture of shared cyber accountability across the organization.
- Provide input to security budget planning and support procurement processes for security tools and services.
WHAT YOU NEED TO BE SUCCESSFUL
- 5–8 years of progressive cyber security experience, with 2–3 years in a supervisory or team lead capacity.
- Proven track record of hands-on technical security work, including direct tool administration and incident response execution, not solely in an advisory or governance capacity.
- Demonstrated experience with governance, policy/standards management, regulatory compliance, and incident response leadership.
- Strong familiarity with the Ontario Cyber Security Framework and at least one of: NIST CSF 2.0, COBIT, ISO/IEC 27001; ability to map and rationalize controls across frameworks.
- Hands-on understanding of modern enterprise/cloud security (e.g., M365), EDR/XDR, SIEM/SOAR, IAM (RBAC, PAM), data protection, vulnerability management, and network security/segmentation.
- Familiarity with OT/SCADA environments and the security considerations unique to converged IT/OT infrastructure.
- Excellent stakeholder management, executive communication, and decision-making under pressure.
MINIMUM REQUIREMENTS
- Cyber Security, Computer Science, Computer Engineering degree, or equivalent combination of education and experience.
- Sector experience (preferred): Energy/utility, critical infrastructure, or regulated environments; exposure to OT/SCADA and business continuity/disaster recovery.
- CISSP, CISM, CRISC, or GIAC certifications are an asset
- ITIL Foundation (or higher), COBIT
- ISO/IEC 27001 Lead Implementer/Lead Auditor (optional)
Compensation Package: $118,400.00 - $148,000.00 CAD annually + Competitive Bonus + Benefits + OMERS Pension Plan
The above range reflects the reasonable estimate for the position at the time of posting. Within the range, hiring compensation will be determined based on relevant qualifications, experience, skillset, education/ training, and other organizational needs.
Note: This posting is for a new position.
Our Commitment to Diversity, Equity, Inclusion and Belonging:
Elexicon Energy embraces and celebrates our collective diversity. We are committed to fostering an inclusive, diverse and equitable workplace built on respect, support and collaboration.
Elexicon Energy is an equal opportunity employer. We value an inclusive and supportive workplace which truly reflects the diversity of the communities we serve. We welcome all individuals to apply and do not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, Indigenous/Métis status, or other legally protected status.
In accordance with the Ontario Human Rights Code and Accessibility for Ontarians with Disabilities Act, 2005, accommodation is available upon request at any point during the recruitment process. If you require accommodation please email us at
[email protected] and we will work to meet your needs.
We thank all applicants; however, only those to be considered will be contacted.