Senior Manager, Cybersecurity Governance and Risk Management

Liquor Control Board of Ontario

$96K — $178K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity, information security, IT risk management, or related fields.
  • Experience in performing security reviews and risk assessments for technology solutions.
  • Familiarity with security frameworks such as NIST, COBIT, ISO 31000/27001, and CIS.
  • Knowledge of cloud environments including Azure, AWS, and Google.
  • Proficiency in implementing and enforcing cyber controls, policies, and procedures.
  • Experience in governance domains such as GRC, IAM, Security Architecture, and Data Protection.
  • Professional certifications: CRISC, CISA, CISM, or CISSP.

Responsibilities

  • Develop and manage the LCBO's IT Risk and Security Management Framework.
  • Conduct regular threat risk assessments and recommend mitigation strategies.
  • Manage information security compliance program to meet requirements.
  • Create cybersecurity governance documents in line with best practices.
  • Lead the Third-Party Risk Management program and promote a risk-aware culture.
  • Oversee tabletop exercises to improve organizational response to cyber threats.
  • Report on cybersecurity risks to the Executive Core team.

Benefits

  • Health and Dental Benefits
  • Access to Employee & Family Assistance Program
  • Defined Benefit Pension
  • Discounts on products and services via Workperks.
Full Job Description
Location Address:
100 Queens Quay East, 9th Floor, Toronto

Number of Openings:
1

Pay:

$96,244.00 - $178,668.00

Job Posting Description:

Senior Manager,

Governance & Risk Management

This is an onsite role [#LI-Onsite]

Are you passionate about overseeing cyber risk management and developing a team of cybersecurity professionals? Reporting to the Director, Cybersecurity, you will develop and operate the LCBO's information security program and manage cybersecurity governance and risk activities. The senior manager ensures our cybersecurity policies, standards, and procedures are in place and followed while implementing risk assessments and providing oversight and challenge to third-party security service providers.

You will also partner with the security architecture practice and lead the development and management of the security training and awareness program while also supporting the reporting function to the Core executive team and Board-level communications. Finally, you will conduct security risk assessments as they relate to all projects that are funneled through the IT Division, including supporting RFP responses.

If you have strong cybersecurity experience and enjoy leading a team, then this is the role for you!

About the Role

Develop an IT Risk and Security Management Framework
  • Be a trusted advisor across all LCBO divisions to identify data and technology-based risks, giving partners expert and realistic analysis to inform their decision-making process.
  • Conduct regular threat risk assessments (TRA) to identify cybersecurity risks and recommend mitigation strategies. Maintain the TRA process and associated artefacts.
  • Evaluate the adequacy of the security controls for our information and technology systems.
  • Manage the LCBO-wide information security compliance program, ensuring IT activities and procedures meet defined requirements.
  • Develop cybersecurity governance documents (policies, standards, baselines, and guidelines) in compliance with relevant legislation and best practices.
  • Conduct cybersecurity assessments of third-party vendors and partners to ensure adherence to LCBO's cybersecurity policies.
  • Lead the Third-Party Risk Management program, assign resources to facilitate TPRM across LCBO, and promote awareness and a culture of risk management across the enterprise.
  • Continuously improve risk management practices and organizational readiness to respond to evolving cyber threats.
  • Oversee enterprise-wide tabletop exercises, identify gaps, and track the associated lessons learned and next steps.
  • Manage the executive security risk dashboard, highlighting material risks, trends, and required actions.
  • Report and communicate with Executive Core team regarding our risk posture.
  • Provide oversight of Managed Security Service Provider services supporting GRC and TPRM and develop metrics to ensure adequate service delivery.


Risk Assessment and Control Assurance
  • Recommend cybersecurity improvements and identify risk and control requirements for upgrades and/or new technologies to enhance the security posture.
  • Provide practical, risk-based recommendations to address cybersecurity problems in a cost-effective manner.
  • Provide security risk and control guidance in support of new technology deployments and projects to improve overall enterprise security.
  • Participate in security risk and control reviews for enterprise architecture and technology initiatives.
  • Provide risk and control oversight for the deployment, integration, and configuration of cybersecurity solutions.


People Management
  • Lead the daily activities, priorities, and development of the Governance and Risk Management team.
  • Provide oversight of GRC and TPRM services delivered by the MSSP, using KPIs and KRIs to monitor performance and drive continuous improvement.
  • Manage vendor relationships and contract responsibilities for the GRC and TPRM service stream in support of a strong cybersecurity posture.


Lead the Enterprise Security Training & Awareness Program
  • Promote a high level of corporate cybersecurity awareness, including the administration of end-user cybersecurity courses and periodic phishing simulations.
  • Lead the security awareness program through phishing exercises, simulations, and targeted training designed to reinforce secure behaviours across the enterprise.
  • Report on phishing simulation results, highlighting progress, trends, and opportunities to improve secure behaviours.
  • Educate LCBO enterprise on social engineering attacks through printed posters, simulations, in-person roadshows at head-office, warehouses, and regional offices as applicable, and training campaigns.
  • Recognize and celebrate employees who report phishing attempts, while addressing repeat risk through targeted coaching and escalation to the appropriate people leader when required.


About You
  • 5+ years' experience in any combination of cybersecurity or information security, information technology, or IT risk management.
  • Experience conducting security reviews / risk assessments on new and existing technology solutions.
  • Knowledge of security and Risk frameworks such as NIST RMF/CSF, COBIT, ISO 31000/27001, CIS.
  • Knowledge of Cloud environments such as Azure, AWS, and Google
  • Experience implementing and governing cyber controls, policies, and procedures.
  • Experience within the following security domains: GRC, IAM, Security Architecture Governance, Data Protection.
  • Experience with Payment Card Industry (PCI-DSS) compliance.
  • Professional certification such as CRISC, CISA, CISM, CISSP
  • Understanding of relevant Ontario provincial and Canadian Federal information security and information privacy legislation


We offer a comprehensive suite of benefits including:
  • Health/Dental Benefits
  • Access to an Employee & Family Assistance Program
  • a Defined Benefit Pension
  • Discounts on products and services via Workperks.


Work Hours:
36.25

Union / Non-Union:
Non-Union

Job Posting End Date:
September 16, 2026

Similar Jobs

More Jobs at Liquor Control Board of Ontario

More Information Technology Jobs

Find similar Senior Manager, Cybersecurity Governance and Risk Management jobs: