We are seeking a Senior Consultant to support the delivery of enterprise cybersecurity assessments. This role combines cybersecurity advisory, structured assessment, stakeholder engagement, analytical judgment, and executive reporting. The successful candidate will independently own assigned cybersecurity domains, assess the maturity of relevant capabilities, and translate complex technical and operational information into clear findings and practical improvement recommendations.
The opportunity The Senior Consultant will work with large, complex organizations to evaluate how effectively cybersecurity capabilities are designed, implemented, governed, measured, automated, and sustained. The role is broader than compliance mapping or control testing. It requires the ability to understand how people, process, technology, governance, and risk considerations work together across an enterprise cybersecurity program.
This job posting relates to an existing vacancy within our organization.
Key responsibilities- Own assigned cybersecurity domains through assessment planning, artifact requests, document review, stakeholder workshops, maturity analysis, quality review, and reporting.
- Translate framework outcomes and other industry guidance into practical, capability-based assessment criteria appropriate to the client environment.
- Review policies, standards, procedures, operating models, architectures, inventories, metrics, reports, and technical documentation to understand the current state.
- Plan and facilitate interviews and workshops with cybersecurity leaders, architects, engineers, risk teams, and control or capability owners.
- Ask targeted follow-up questions, appropriately challenge unsupported statements, and identify where further validation is required.
- Synthesize stakeholder input, artifacts, metrics, and technical context into consistent and defensible maturity conclusions.
- Draft concise current-state observations, maturity rationales, opportunities for improvement, risk implications, and practical recommendations.
- Connect detailed domain findings to broader themes, business impacts, target-state considerations, and prioritized improvement actions.
- Prepare clear, executive-ready materials and support presentations to client leadership.
- Guide Consultants, review draft analyses and workpapers, maintain consistency across domains, and escalate issues early.
- Contribute to the refinement of assessment methodologies, capability libraries, reporting approaches, and reusable intellectual property.
To qualify for the role you must have- Hands-on experience delivering cybersecurity maturity, capability, risk, controls, assurance, or transformation assessments.
- Demonstrated ability to independently lead a workstream or assessment domain from information gathering through final reporting.
- Working knowledge of common cyber and IT frameworks, with the ability to explain how framework outcomes apply to real cybersecurity capabilities and operating environments.
- Broad understanding across multiple cybersecurity domains, with meaningful depth in at least two or three areas.
- Experience facilitating stakeholder interviews or workshops and communicating with both technical practitioners and senior leaders.
- Strong analytical judgment, including the ability to form supportable conclusions from incomplete, varied, or conflicting information.
- Excellent written communication skills, including findings, recommendations, presentations, and executive summaries.
- Ability to manage multiple domains, stakeholders, and deliverables while maintaining quality and consistency.
- Experience coaching junior team members and reviewing their work.
Ideally, you'll also have- Experience applying NIST CSF 2.0, including Functions, Categories, Subcategories, Current Profiles, and Target Profiles.
- Familiarity with NIST SP 800-53, CIS Controls, ISO/IEC 27001 and 27002, COBIT, CRI Profile, CSA CCM, or related cyber-risk frameworks.
- Experience in banking, insurance, payments, or another highly regulated and federated enterprise environment.
- Familiarity with Canadian financial-services expectations such as OSFI B-13 or other relevant regulatory guidance.
- Experience developing maturity models, target states, cyber roadmaps, benchmarking insights, or transformation recommendations.
- Relevant cybersecurity or risk certification such as CISSP, CISM, CRISC, CISA, ISO 27001, CCSP, or equivalent credential. Certifications are considered supporting qualifications rather than a substitute for practical delivery experience.
Cybersecurity domain coverageCandidates are not expected to be specialists in every domain. The strongest profiles will demonstrate depth in selected areas and working fluency across several others.
Domain groupingIllustrative areasGovernance and riskCyber governance, policy and standards, security metrics, second-line cyber risk, third-party risk, privacy
Identity and dataIAM, PAM, customer identity, data protection, data security, cryptography
Applications and engineeringApplication security, API security, DevSecOps, secure software development, cloud security, AI security
Infrastructure and operationsNetwork security, endpoint security, vulnerability management, configuration management, asset management
Detection and resilienceSecurity operations, threat management, incident response, insider risk, forensics, disaster recovery, business continuity
What we look forWe're interested in intellectually curious people with a genuine passion for cybersecurity. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.
What we offer youThe EY benefits package is designed to support your physical, emotional, financial, and social wellbeing. Our extensive benefits include comprehensive medical, dental, and prescription drug coverage, as well as mental health benefits, a robust Employee Assistance Program and group savings plans to promote your overall wellbeing. We offer generous time off, including personal days, vacation days, and additional firm-wide holidays, along with the option to purchase extra vacation days. Employees can take advantage of EY's exclusive learning programs tailored just for them. We also provide internal opportunities for career development and advancement, enabling you to grow within the firm. Get involved in meaningful volunteering through EY Ripples and make a positive impact in the community.
EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
- Toronto/Calgary/Vancouver/Edmonton/Montreal: $90,000 to 136,000 per year
Are you ready to shape your future with confidence? Apply today.
To help create the best experience during the recruitment process, please describe any accommodations you may need.