Senior Manager Cybersecurity - Governance Risk and Compliance
Professional Staffing · Greater Toronto Area, Canada
Apply & track with Apply EdgeWe are seeking an experienced Senior Manager, Cybersecurity – Governance, Risk & Compliance (GRC) to provide strategic leadership across the organization's cybersecurity program.This role will lead the development and advancement of the organization's cybersecurity strategy, governance, risk management, compliance, and security initiatives, ensuring organizational assets are protected, regulatory and industry requirements are met, and the overall security posture continues to mature.The Senior Manager will serve as a trusted cybersecurity advisor to IT leadership, Executive Management, and senior business stakeholders, translating complex cybersecurity and technology risks into clear business priorities, strategic recommendations, and actionable plans.The role will provide broad oversight across GRC, security operations, incident response, cyber resilience, cloud security, third-party risk, and the secure adoption of AI and emerging technologies.Key ResponsibilitiesCybersecurity Strategy & LeadershipDevelop and execute a multi-year cybersecurity strategy, roadmap, and operating model aligned with business objectives and enterprise risk.Establish cybersecurity priorities, investment plans, budgets, and business cases.Define cybersecurity KPIs and KRIs to measure risk, control effectiveness, program maturity, and overall performance.Continuously monitor emerging threats, technologies, vulnerabilities, and changes in the cybersecurity landscape.Identify opportunities to strengthen the organization's overall security maturity and resilience.Governance, Risk & ComplianceLead the organization's Cybersecurity GRC program, including:Enterprise cybersecurity risk assessmentsRisk registersPolicies and standardsControl frameworksRisk remediationCompliance monitoringExecutive reportingEstablish and maintain effective cybersecurity governance structures, policies, standards, and procedures.Lead cybersecurity audits, regulatory reviews, customer security assessments, and compliance initiatives.Provide oversight of cybersecurity controls and ensure identified gaps are appropriately remediated.Maintain alignment with recognized frameworks and standards including NIST, ISO 27001, CIS Controls, and SOC 2.AI & Emerging Technology SecurityLead cybersecurity strategy and governance for the secure adoption of Artificial Intelligence, Generative AI, machine learning, automation, and other emerging technologies.Assess cybersecurity, privacy, data, and third-party risks associated with AI-enabled technologies and emerging platforms.Establish governance requirements for responsible AI and Generative AI use, including:Data protectionAccess controlsModel securityMonitoringRisk managementPartner with Technology, Data, Privacy, Legal, and business teams to establish secure-by-design principles for AI and emerging technologies.Identify opportunities to use AI and automation to enhance threat detection, security monitoring, incident response, vulnerability management, and security operations.Monitor emerging cyber threats involving AI and develop appropriate controls, detection capabilities, and response strategies.Executive Advisory & ReportingServe as a trusted cybersecurity advisor to the CIO, IT leadership, Executive Management, and senior business stakeholders.Translate technical cybersecurity risks into clear business impacts, priorities, and recommendations.Prepare and present cybersecurity risk, compliance, maturity, and strategic updates to Executive Management and the Board.Provide leadership with actionable recommendations regarding cybersecurity investments and risk priorities.Security Operations & Cyber ResilienceProvide executive oversight of cybersecurity incident response, cyber resilience, tabletop exercises, and major incident reviews.Oversee the performance of outsourced Security Operations Center (SOC)/MSSP providers.Provide governance and oversight across:Security monitoringThreat detectionIncident responseVulnerability managementThreat intelligenceEnsure appropriate processes are in place to prepare for, respond to, and recover from significant cyber incidents.Third-Party & Supply Chain RiskLead third-party and supply-chain cybersecurity risk management.Establish security requirements and assessment processes for vendors and strategic partners.Review and assess cybersecurity risks associated with critical third parties and service providers.Partner with Procurement, Legal, Risk, and business stakeholders to embed cybersecurity requirements into vendor management and contracting processes.Enterprise Security GovernanceProvide cybersecurity governance and risk oversight across:Cloud environmentsInfrastructureApplicationsDataIdentity and access managementAI and emerging technologiesEnterprise technology architecturePartner with Technology, Business, Legal, Privacy, Risk, Internal Audit, Procurement, and external providers to embed cybersecurity into business and technology decisions.Team LeadershipLead, mentor, and develop cybersecurity professionals.Build a high-performing, collaborative, and sustainable cybersecurity organization.Establish clear objectives, accountability, and professional development opportunities for team members.Qualifications & ExperienceBachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.12+ years of progressive cybersecurity/information security experience, including at least 5 years in a leadership or management capacity.Strong experience in:Cybersecurity strategyGovernance, Risk & ComplianceEnterprise risk managementSecurity assuranceSecurity program managementDemonstrated experience overseeing SOC/MSSP relationships and cybersecurity operations.Strong understanding of cybersecurity risks associated with AI, cloud, automation, and emerging technologies.Experience balancing innovation with security, privacy, regulatory, and enterprise risk requirements.Demonstrated experience in incident response, cyber resilience, and security program management.Experience presenting cybersecurity strategy and risk to senior executives and/or Boards.Experience supporting audits, regulatory reviews, customer security assessments, and cybersecurity compliance programs.Experience with cloud security and cybersecurity architecture.Experience developing cybersecurity budgets, business cases, KPIs/KRIs, and investment priorities.Strong knowledge of recognized cybersecurity frameworks, including NIST, ISO 27001, CIS Controls, and SOC 2.Preferred CertificationsOne or more of the following certifications would be considered an asset:CISSPCISMCRISCCCSPGIACOther recognized cybersecurity, information security, risk, or audit certificationsWhat Success Looks LikeSuccess in this role will be demonstrated through:Increased cybersecurity maturity and improved enterprise risk postureStrong cybersecurity governance and executive visibilityEffective identification, prioritization, and reduction of material cyber risksStrong audit, compliance, and regulatory outcomesEffective third-party and supply-chain cybersecurity risk managementImproved cyber incident preparedness, response, and resilienceSuccessful execution of the cybersecurity strategy and roadmapResponsible and secure adoption of AI and emerging technologiesA strong, capable, and sustainable cybersecurity teamCandidates must be eligible to work in Canada I would like to thank all the candidates in advance. Please do stay connected on LinkedIn for future opportunities. Shortlisted candidates will be contacted .This position reflects a current vacancy with one of our clients. Our Recruiters combine their expertise and AI-enabled technology in the recruitment process.