The Manager, Cybersecurity Governance leads the design, implementation, and ongoing maturity of Toromont's cybersecurity governance, risk, and compliance program across IT and OT/ICS environments. The role provides cyber risk and regulatory expertise, ensuring frameworks, controls, and audit obligations are met while translating technical risk into clear, business focused reporting for senior leadership.
The Manager oversees a team of Governance Analysts and partners closely with JSOC, IAM, Legal, Privacy, Compliance, and Internal Audit across Toromont's national operations to strengthen enterprise cyber governance and risk management.
Compensation$103,625 - $129,533
The listed base salary is just one component of our total rewards package, and performance-based or discretionary bonuses may be available.
As a Manager, Cybersecurity Governance, YOU will experience:- Working within one of the safest organizations in the industry where your safety and well-being are our most important priority
- Working for the best in class equipment dealer and with the premium Caterpillar brand
- Opportunities to continuously Learn, Grow and Develop with our Toromont team through our internal Training teams that are geared for your success
- Competitive total rewards including: wages, benefits, and premiums (as eligible)
- An opportunity for flexible work schedules and opportunities across multiple locations across Eastern Canada
In a typical day, YOU will:- Lead and mature Toromont's Cybersecurity GRC framework across IT and OT/ICS, aligned to NIST, ISO 27001, COBIT, and emerging AI/agentic-risk governance.
- Drive enterprise cyber risk identification, assessment, prioritization, and tracking; deliver AI-enabled dashboards and control-monitoring metrics.
- Own cybersecurity policy development and maintenance; serve as primary contact for internal/external/regulatory audits, including ICFR cyber controls.
- Lead security awareness training, phishing simulations, and facilitate cyber tabletop and simulation exercises across IT and OT/ICS.
- Produce executive-level dashboards and presentations on cyber risk posture, control maturity, and audit status; support leadership communications and planning.
- Manage cybersecurity governance initiatives and projects from planning through execution, ensuring effective collaboration across JSOC, IAM, Technology, and business unit teams.
- Lead and mentor Cybersecurity Governance Analysts; partner with JSOC, IAM, Legal, Privacy, Compliance, and Internal Audit; monitor evolving regulatory requirements.
Must-haves for this role:- 12+ years of progressive cybersecurity, risk, or governance experience, 6+ years of team leadership
- A bachelor's degree in Business Administration, Information Technology, Computer Science, or Engineering (or equivalent experience)
- Preferred certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor/Implementer.
Artificial Intelligence (AI)
Please note that our hiring processes involve the use of artificial intelligence (AI) tools to assist with screening, assessing, or selecting candidates; all final decisions are reviewed by our Talent Acquisition team to ensure fairness and compliance with applicable laws