Description
Focus Systems is seeking an experienced Security Specialist – Senior (1895) to support a public-sector healthcare organization supporting digital health initiatives. The engagement is focused on security governance, risk & compliance, and cyber defense operations, including audit support, threat and risk assessments, policy and standards development, risk registers, executive reporting, and security program documentation.
If you have strong experience leading information security governance activities within complex public-sector environments, supporting IPC and OAGO audits, conducting TRAs, and translating security risk into clear executive-ready reporting, this is an exciting opportunity to contribute to digital health security initiatives.
Key Details
- Location: Primarily remote within Canada; hybrid attendance may be requested
- Contract: 1 year – half-time – expected 125 business days in the year. 78 days between Aug 17 and Mar 31, 2027, and then 48 days between Apr 1, 2027, and Aug 13. (This position is part-time.)
- Industry: Public Sector / Healthcare / Digital Health / Cybersecurity
- Remote Setup Requirement: Private office, hard-wired internet, and candidate-provided monitor, keyboard, and mouse
Role Overview
The Security Specialist – Senior (1895) will lead and support multiple information security initiatives across security governance, risk management, compliance, cyber defense operations, audit support, policy and standards development, executive reporting, and TRAs. The successful candidate will help strengthen security governance practices, document and communicate risk, and support audit and compliance activities in a public-sector healthcare / digital health environment.
Key Responsibilities
- Lead and support security governance, risk management, compliance, and cyber defense operations initiatives
- Conduct and support threat and risk assessments using NIST CSF, HTRA, ISO 27001, and related security frameworks
- Support IPC and OAGO audit activities, including evidence gathering, issue tracking, findings analysis, and remediation planning
- Develop, review, and maintain information security policies, standards, governance documentation, and program materials
- Prepare executive reports, risk registers, cybersecurity program updates, briefings, and presentations
- Analyze security risks, control gaps, compliance findings, and operational security concerns, then recommend practical mitigation approaches
- Collaborate with security, IT, audit, business, and executive stakeholders to align security work with organizational priorities
- Support cyber defense reporting, governance forums, risk tracking, and ongoing security program maturity activities
Mandatory Qualifications
- Degree or diploma in Information Security, Computer Science, IT, or a related field
- Relevant security certification(s) such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor; copies required if available
- 8+ years of hands-on IPC and OAGO audit experience
- 5+ years conducting TRAs using NIST CSF, HTRA, and ISO 27001
- 5+ years in information security governance, policy, and standards development
- 5+ years preparing executive reports, cybersecurity programs, risk registers, and presentations
- Public-sector experience
- Ability to meet the remote/hybrid work arrangement and equipment requirements described above
Application Deadline
Please complete your initial application by July 20, 2026, at 11;00 PM CST. Only candidates selected to proceed to the next stage will be contacted and invited to complete their application package.





