The County of Haliburton is currently seeking a qualified candidate for the newly created full-time, permanent position of Cybersecurity Analyst.
Reporting to the Director of IT, the Cybersecurity Analyst provides functional leadership for the County’s cybersecurity program and leads day-to-day information security operations. The role coordinates and executes core cybersecurity activities including monitoring, incident response, vulnerability management, patching, endpoint protection, and security awareness, ensuring consistent application of security best practices across the organization.
Acting as the County’s primary cybersecurity subject-matter expert, the Cybersecurity Analyst guides operational security decisions and response efforts under the strategic direction and oversight of the Director of IT. The position supports risk assessments, policy compliance, and the security review of major technology initiatives, while collaborating with municipal partners and external forums to strengthen the County’s overall security posture.
The successful applicant will have at least 3 years of progressive experience in information technology operations, with a focus on security operations, monitoring, or incident response and relevant post-secondary education or an equivalent combination of education and experience. Industry recognized certifications are strong preferred. Experience in a municipal or public-sector environment is considered an asset. A valid G driver’s licence and reliable personal vehicle are required. This position is eligible for remote work.
For complete responsibilities and requirements of the position please see the below job description.
Please submit a detailed resume indicating your skills and experience no later than Friday, March 20 2026, at 4:30pm. Please send your resume to:
Sarah Hume, Human Resources Manager
shume@haliburtoncounty.ca
We thank all who apply for this position; however, only those selected for an interview will be contacted.
The County of Haliburton is an equal opportunity employer. Accommodation can be provided in all steps of the hiring process. For accommodation options and to ensure full and equal access during the recruitment and selection process, contact Human Resources.
In accordance with the Municipal Freedom of Information and Protection of Privacy Act, the information gathered will be used solely for the purpose of job selection.
POSITION SYNOPSIS AND PURPOSE
Reporting to the Director of IT, the Cybersecurity Analyst provides functional leadership for the County’s cybersecurity program and leads day-to-day information security operations. The role coordinates and executes core cybersecurity activities including monitoring, incident response, vulnerability management, patching, endpoint protection, and security awareness, ensuring consistent application of security best practices across the organization.
Acting as the County’s primary cybersecurity subject-matter expert, the Cybersecurity Analyst guides operational security decisions and response efforts under the strategic direction and oversight of the Director of IT. The position supports risk assessments, policy compliance, and the security review of major technology initiatives, while collaborating with municipal partners and external forums to strengthen the County’s overall security posture.
MAJOR RESPONSIBILITIES
Security Operations & Incident Response (40%)
- Monitor and analyze vulnerability scan results; coordinate and track remediation activities, escalating unresolved or high-risk issues to the Director of IT as required.
- Lead and coordinate patch management activities, including testing, validation, and deployment of updates for operating systems, applications, and firmware.
- Guide system and application hardening efforts by applying and maintaining standard security baselines and configuration guidelines.
- Maintain the Incident Response Plan (IRP), supporting playbooks, and incident documentation; log and track security incidents and contribute to post-incident reviews and lessons learned.
- Monitor endpoint protection and MDR/XDR alerts; perform initial triage, coordinate response actions, and escalate incidents in accordance with established thresholds.
- Support privileged access reviews, Conditional Access policy enforcement, and multi-factor authentication (MFA) compliance across County systems.
- Provide cybersecurity input into backup, recovery, and disaster recovery processes to ensure alignment with risk management and resilience objectives.
- Other duties as assigned.
Governance, Risk, & Compliance (20%)
- Develop, maintain, and update the IT risk register; support and coordinate Business Impact Analyses (BIAs) and Privacy Impact Assessments (PIAs) across County systems and services.
- Review, draft, and maintain IT security policies, standard operating procedures (SOPs), and guidelines under the strategic direction of the Director of IT.
- Monitor and track relevant regulatory and compliance requirements (e.g., MFIPPA, Bill 194, cyber insurance obligations), and support the alignment of policies, controls, and practices accordingly.
- Assist the Director of IT with cybersecurity dashboards, KPI development, and the preparation of periodic cybersecurity reporting for senior leadership and Council.
- Support vendor and third-party risk management activities by maintaining vendor risk logs, collecting security documentation, and assisting with security assessments and evaluations.
- Provide guidance to departments and IT teams on cybersecurity risk management practices and compliance expectations.
Strategic Support & Collaboration (20%)
- Support the Director of IT with cybersecurity reviews of new and emerging technology initiatives, including identifying risks, documenting mitigation measures, and tracking follow-up actions.
- Act as a primary point of contact for lower-tier municipalities on routine cybersecurity matters, coordinating responses and escalating issues to the Director of IT as required.
- Support the Director of IT in regional and provincial cybersecurity forums (e.g., EOITC, MISA), including contributing to discussions, tracking action items, and maintaining supporting documentation for audits and cyber insurance renewals.
- Contribute to cybersecurity information-sharing initiatives and bring forward relevant insights, trends, and lessons learned from external partners for internal review and consideration.
Awareness, Training, & Culture (20%)
- Administer the cybersecurity awareness platform and manage user training assignments.
- Plan and deliver phishing simulations; record results and escalate trends.
- Create concise and engaging user guidance (cyber tips, posters, intranet content).
- Organize and coordinate annual cyber awareness campaigns, including Cyber Security Awareness Month activities.
*Note: All activities are expected to be performed in a safe manner, in accordance with the Occupational Health and Safety Act and its Regulations, along with Corporate Safety policies, procedures and programs. In addition, all necessary personal protective equipment must be used and maintained in good condition.
DECISION MAKING AND INDEPENDENCE
a) 3 examples of the types of decisions that are made or issues/situations that are dealt with on a regular basis and how judgement is used to resolve them:
- Review scan results and apply judgment to determine which vulnerabilities require urgent remediation versus routine patching.
- Assess security alerts to decide whether they are false positives, minor incidents to resolve, or issues requiring escalation.
- Evaluate privileged accounts and MFA compliance, using judgment to remediate straightforward issues and escalate exceptions.
b) 3 examples of situation or problems that are referred to the supervisor for direction or resolution:
- Escalate ransomware, data breaches, or other high-severity incidents to the Director of IT for leadership of the response.
- Refer cases where security policies conflict with operational needs or require formal risk acceptance.
- Seek direction on complex projects such as ERP replacements or cloud migrations where security considerations impact procurement or design decisions.
REQUIRED TRAINING
Orientation which includes:
- All Corporate Policies/Procedures
- WHMIS GHS Training
- Respect in the Workplace
- MOL Worker H & S Training
- AODA
Additional training required:
- Various software related procedural guides and manuals.
MINIMUM QUALIFICATIONS
a) Education
- Post-secondary education in Computer Science, Information Technology, Cybersecurity, or a related field; an equivalent combination of education and relevant work experience may be considered.
- Industry-recognized certifications are strongly preferred, such as:
- CompTIA Security+
- Microsoft Security Operations Analyst (SC-200) or related Microsoft 365/Entra certifications.
- Certified Ethical Hacker (CEH) or CompTIA CySA+
- CISSP
- Valid G class licence and reliable personal vehicle.
b) Experience
- 3–4 years of progressive experience in information technology with a focus on cybersecurity operations, monitoring, or incident response.
- Hands-on experience with vulnerability management, patching, and endpoint protection tools (e.g., Microsoft Defender, Qualys, Nessus, etc).
- Practical exposure to Microsoft 365 security features (e.g., Conditional Access, MFA, security reporting, Entra ID/Intune).
- Experience administering or supporting a cybersecurity awareness platform and conducting phishing simulations.
- Familiarity with risk management practices, policy compliance, and security frameworks relevant to the public sector (e.g., NIST CSF, CIS Controls, MFIPPA).
- Previous experience in a municipal government, public sector, or other highly regulated environment is considered an asset.
c) Knowledge/Skill/Ability
- Knowledge of cybersecurity principles, threat vectors, risk management practices, and incident response frameworks (e.g., IMS, NIST CSF, CIS Controls).
- Understanding of Microsoft 365/Entra security tools, endpoint protection platforms, vulnerability scanning, and patch management processes.
- Familiarity with relevant municipal and public sector regulations such as MFIPPA, PHIPA, Bill 194, and cyber insurance requirements.
- Skill in analyzing security events, distinguishing between false positives and legitimate incidents, and applying sound judgment in escalation.
- Skill in developing user-friendly security awareness content and delivering phishing simulations or training campaigns.
- Ability to work collaboratively with IT staff, municipal partners, and external vendors to resolve security issues and implement best practices.
- Ability to communicate clearly and effectively, both verbally and in writing, with technical and non-technical audiences.
- Ability to manage multiple tasks, prioritize competing demands, and maintain attention to detail in a fast-paced environment.
POSITION CLASSIFICATION
Position Title: Cybersecurity Analyst
Department: IT
Work Location: Administration Office
Reports to (Direct): Director of IT
Position(s) Supervised Directly: None
Position(s) Supervised Indirectly: N/A
Effective Date: February 2026
Revision Date:
Hourly Range: $42.17 – $49.33
Hours Per Week: 40