Kinaxis

Cybersecurity Risk Manager

Kinaxis$110K — $130K *
US-AnywhereRemote in Canada
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • University degree or equivalent in Information Security, Computer Science, or related field
  • 5-7 years in cybersecurity risk, IT risk, audit, or compliance
  • Strong knowledge of NIST CSF, NIST SP 800 53, ISO 27001, SOC 2 frameworks
  • Ability to operationalize risk frameworks into scalable processes, metrics, and reporting
  • Strong analytical and influencing skills to translate technical risk into business insights

Responsibilities

  • Lead execution of cybersecurity risk identification, assessment, and planning
  • Ensure application of risk frameworks aligned with governance and regulatory expectations
  • Oversee control evaluations and ensure clarity in risk acceptance recommendations
  • Maintain an accurate and decision-ready cybersecurity risk register
  • Deliver management-ready risk reporting for informed decision-making
  • Align cybersecurity practices to regulatory frameworks like FedRAMP and SOC
  • Contribute to governance practices for AI risk management and monitor emerging developments

Benefits

  • Flexible vacation and company-wide off days
  • Flexible work options
  • Physical and mental well-being programs
  • Virtual fitness classes
  • Mentorship and career development opportunities
  • Recognition programs and referral rewards
  • Participation in hackathons
Full Job Description

Location

Ottawa and Toronto, Canada - Hybrid

Other Canadian and USA locations - Remote

About the team

The Cybersecurity Risk Manager is accountable for the execution, quality, and continuous improvement of the enterprise cybersecurity risk management program. This role ensures that cybersecurity risks across cloud, product, third0party, and AI-enabled capabilities are consistently identified, assessed, governed, and translated into decision0ready insights and actionable remediation outcomes. This role does not include direct people management responsibilities, but it does require cross-functional influence.

 

The role also incorporates FedRAMP readiness and emerging AI risk management considerations into the broader cybersecurity risk program, ensuring cloud, product, third-party, and AI-enabled risks are evaluated consistently and translated into actionable remediation, reporting, and governance outcomes.

Vacancy Status

This is an existing job vacancy

What you will do

Cybersecurity Risk Program Execution

  • Lead the end0to0end execution of cybersecurity risk identification, assessment, prioritization, and treatment planning across enterprise systems and services
  • Ensure consistent application of risk frameworks and methodologies aligned to enterprise governance and regulatory expectations
  • Oversee control evaluation, residual risk analysis, and risk acceptance recommendations, ensuring clear rationale and alignment to risk appetite

Risk Governance and Reporting

  • Maintain a complete, accurate, and decision0ready cybersecurity risk register with clear ownership, status, and evidence
  • Deliver management0ready risk reporting and insights that enable informed decision0making, prioritization, and escalation
  • Strengthen data quality, metrics, and reporting practices to improve visibility into enterprise risk posture

Regulatory and Compliance Alignment

  • Align cybersecurity risk practices to regulatory and assurance requirements including FedRAMP, SOC, ISO 27001, and related frameworks
  • Translate regulatory expectations into actionable risk management practices, remediation plans, and governance controls
  • Support continuous monitoring and evidence readiness for audit and certification requirements

Emerging Risk Domains

  • Evaluate risks associated with cloud environments, third0party services, and AI-enabled capabilities
  • Contribute to AI risk governance practices, including assessment criteria, controls, and reporting mechanisms
  • Monitor emerging cybersecurity, AI, and regulatory developments and integrate relevant changes into the risk program

Technical Leadership and Influence

  • Provide technical leadership and quality oversight across risk assessment activities and outputs
  • Influence cross-functional stakeholders (engineering, product, legal, compliance) to ensure risks are understood, owned, and effectively addressed
  • Drive continuous improvement of processes, tooling, and automation to enhance risk program maturity

What we are looking for

Primary Skills and Qualifications

  • University degree or equivalent practical experience in Information Security, Computer Science, or related field
  • 5 67 years of progressive experience in cybersecurity risk, IT risk, audit, or compliance
  • Strong knowledge of risk and control frameworks (NIST CSF, NIST SP 800 53, ISO 27001, SOC 2)
  • Demonstrated ability to operationalize risk frameworks into scalable processes, metrics, and reporting

Role-Specific Skills and Experience

  • Strong analytical and influencing skills, with ability to translate technical risk into business decision insights
  • Experience working with GRC platforms, audit evidence, and workflow automation

Continuous Learning

  • A demonstrated commitment to continuous learning, with a strong desire to stay current on rapid advancements in AI, particularly in generative and agentic AI, and their implications for cybersecurity

Nice to Have

  • Professional certifications such as CRISC, CISSP, CISM, CISA, or equivalent.
  • Experience with cloud security and regulated SaaS/cloud environments, including FedRAMP readiness
  • Familiarity with AI risk management concepts, including governance, privacy, and emerging regulatory expectations (NIST AI, ISO/IEC 42001)
  • Practical experience applying AI, automation, analytics, or GRC workflow improvements to strengthen cybersecurity risk analysis, reporting, or evidence management.
  • Experience with privacy, data protection, or regulatory requirements such as GDPR, CCPA, NIS2, or other applicable security and compliance obligations.

#Senior

Work With Impact: Our platform directly helps companies power the world0s supply chains. We see the results of what we do out in the world every day, when we see store shelves stocked, when medications are available for our loved ones, and so much more.

Work with Fortune 500 Brands: Companies across industries trust us to help them take control of their integrated business planning and digital supply chain. Some of our customers include Lockheed Martin, Unilever, P&G, ExxonMobil, Cisco and more.

Social Responsibility at Kinaxis: Our Diversity, Equity, and Inclusion Committee weighs in on hiring practices, talent assessment training materials, and mandatory training on unconscious bias and inclusion fundamentals. Sustainability is key to what we do and we0re committed to a long-term net-zero operations strategy. We are involved in our communities and support causes where we can make the most impact.

People matter at Kinaxis and here are some of the perks and benefits we offer, which may vary by location and employee:

  • Flexible vacation and Kinaxis Days (company-wide days off)
  • Flexible work options
  • Physical and mental well-being programs
  • Regularly scheduled virtual fitness classes
  • Mentorship programs, training, and career development
  • Recognition programs and referral rewards
  • Hackathons

About Kinaxis

Kinaxis is a Canadian software company that provides cloud-based supply chain management solutions. The company's flagship product, RapidResponse, provides companies with supply chain planning and analytics capabilities. Kinaxis was founded in 1995 and is headquartered in Ottawa, Ontario. The company serves customers in a variety of industries, including automotive, high tech, and life sciences.
Learn more about Kinaxis
Size
2,000 employees
Industry
Founded
1995

Similar Jobs

More Jobs at Kinaxis

More Information Technology Jobs

Find similar Cybersecurity Risk Manager jobs: