BDO Canada LLP

Senior Manager, Information Security

BDO Canada LLP$132K — $182K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
  • Over 10 years of experience in IT security or risk management, with at least 2 years of leadership experience.
  • Experience in handling regulatory or compliance programs, especially in multi-country contexts.
  • Preferred certifications include CISSP, CISM, CRISC, CISA, or CGEIT.
  • Proficiency in GRC tools and cloud security, alongside knowledge of identity/access management.

Responsibilities

  • Build and mentor a high-performing governance, risk, and compliance (GRC) team.
  • Identify, assess, and manage IT-related risks, developing resolution plans.
  • Coordinate internal and third-party audits, ensuring effective corrective actions.
  • Develop and enforce IT security policies and guidelines in alignment with regulations.
  • Conduct security assessments of vendors and partners for compliance.
  • Oversee the deployment and optimization of GRC platforms for improved monitoring.
  • Implement cybersecurity awareness programs and conduct training for staff and management.
  • Serve as a trusted advisor on IT risk and compliance strategies for executive leadership.

Benefits

  • Opportunities for professional development and continuous growth.
  • Collaborative cross-functional work environment.
  • Access to advanced GRC tools and technologies.
  • Mentorship from experienced leaders in the cybersecurity field.
  • Contributions toward operational resilience and regulatory compliance efforts.
Full Job Description

Your Opportunity

The Senior Manager, Information Security leads the organization’s cybersecurity governance, risk management, and compliance programs, ensuring security policies, regulatory requirements, and industry best practices are effectively implemented.

The Senior Manager, Information Security is responsible for developing, managing, and executing IT security governance, risk, and compliance strategy.  This includes overseeing risk assessments, audits, vendor security evaluations, policy enforcement, and leading a team of security analysts or specialists

This role is cross-functional, collaborating with IT, Risk, Legal, Compliance, and business teams to maintain compliance with frameworks like ISO 27001, NIST, SOC 2, and applicable privacy regulations such as GDPR and HIPAA

This role is ideal for a seasoned cybersecurity professional with deep GRC experience, capable of driving cybersecurity programs that ensure operational resilience, regulatory compliance, and enterprise risk mitigation while leading and mentoring a high-performing team.

Key Responsibilities

  • Leadership & Team Management: Build, mentor, and manage a high-performing GRC team, tracking objectives and key results (OKRs) and fostering a culture of continuous development.
  • Risk Management: Identify, assess, and monitor IT-related risks, evaluate risk exceptions, and oversee tactical and strategic resolution plans.
  • Compliance & Auditing: Plan and coordinate internal audits, third-party audits, and regulatory assessments; ensure corrective actions are implemented effectively.
  • Policy Development: Develop, update, and enforce IT security policies, standards, procedures, and guidelines aligned with changing regulations and business requirements.
  • Vendor and Third-Party Risk: Conduct security assessments of vendors, partners, and cloud providers to ensure regulatory and contractual compliance.
  • Governance & Frameworks Implementation: Oversee GRC platform deployment and configuration to automate control monitoring, reporting, and continuous improvement.
  • Awareness & Training: Implement cybersecurity awareness programs and deliver end-user or management training on security and compliance expectations.
  • Strategic Advisory: Serve as a trusted advisor for IT risk and compliance strategy, engaging with executive leadership and stakeholders to ensure alignment with enterprise goals.

Required Qualifications

  • Education: Bachelor’s degree in Information Technology, Cybersecurity, Information Security, Computer Science, or a related field.
  • Experience: 10+ years in IT security or risk management with 2+ years leading teams managing regulatory or compliance programs. Experience in technology risk consulting, IT audits, and multi-country compliance programs is highly valued.
  • Certifications: CISSP, CISM, CRISC, CISA, or CGEIT preferred.
  • Technical Skills: Proficiency in GRC tools, familiarity with identity/access management (LDAP/AD, SAML, OIDC), cloud security, and integration with SIEM, vulnerability management, and ITSM platforms
  • Soft Skills: Strong leadership, communication, stakeholder engagement, problem-solving, and decision-making abilities. Ability to translate complex compliance requirements into actionable strategies.

The expected range of compensation for this role is $132,000 to $182,000 annually.


#LI-SA1

About BDO Canada LLP

BDO Canada LLP is a leading accounting and advisory firm that provides a wide range of services to clients across Canada. The firm offers audit and assurance, tax, advisory, and consulting services to clients in various industries, including manufacturing, retail, real estate, and technology. BDO Canada LLP is part of the global BDO network, which operates in over 160 countries and employs over 80,000 people. The firm is committed to providing exceptional client service and helping clients achieve their business objectives.
Learn more about BDO Canada LLP
Size
4,000 employees
Industry

Similar Jobs

More Jobs at BDO Canada LLP

More Information Technology Jobs

Find similar Senior Manager, Information Security jobs: