Your MissionAs a Cybersecurity Risk Manager, your mission is to lead and mature the cybersecurity risk management program by identifying, assessing, treating, monitoring and communicating cybersecurity risks that may impact CAE's operations, technologies and business objectives.
Your Role & Main Responsibilities- Lead and mature the cybersecurity risk management program, including risk identification, assessment, treatment, monitoring and reporting.
- Maintain the enterprise cybersecurity risk register and ensure risks, issues, exceptions and mitigation plans are documented, tracked and regularly reviewed.
- Conduct cybersecurity risk assessments for projects, technologies, third parties and business initiatives, and provide practical risk-based recommendations.
- Partner with business and technology stakeholders to define risk treatment plans, clarify ownership, track remediation progress and support risk acceptance decisions.
- Prepare clear risk reporting, dashboards and executive summaries to support informed decision-making by cybersecurity leadership and governance committees.
- Support the development and continuous improvement of risk methodologies, scoring models, control expectations and governance processes aligned with industry frameworks.
- Monitor key risk indicators, emerging threats and control gaps, and translate them into actionable insights for stakeholders.
- Advise project teams on cybersecurity risk requirements and ensure risks are identified early, assessed consistently and managed throughout the project lifecycle.
- Contribute to risk awareness, governance routines and performance indicators that strengthen the Governance, Risk and Compliance function.
Your QualificationsSoft skills
- Want to be in a performing team
- Show Initiative & leadership
- Be customer orientated
- Display a sense of collaboration (teamwork) & interpersonal skills
- Ability to influence
Technical skills
- Bilingualism (French and English) is required
- A minimum of seven (7) years experience in IT Security or Cybersecurity
- In-depth knowledge and experience in IT Security and Telecommunications
- In-depth knowledge risk analysis methodologies and security standards (e.g. ISO, NIST)
- Industry-recognized certification (CISSP, CISA, CIRISC, CISM) would be considered an asset
- Knowledge about threat modeling methodology
- Aerospace industry knowledge would be considered an asset
At CAE, connecting with people is very important. If you have any questions on this career opportunity, please do not hesitate to contact Didier Avignon, Talent Acquisition Specialist and ([redacted]) or Rémi Beauregard, Head of Cybersecurity Governance, Risk and Compliance ([redacted]).
Position Type Regular