YYZ - Senior Manager, Cybersecurity & GRC - FT (4929)

Cargojet

$110K — $130K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
  • 12+ years of progressive cybersecurity experience, including 5+ years in leadership roles.
  • Strong experience in cybersecurity strategy, governance, and risk management.
  • Experience managing SOC relationships and security operations.
  • Understanding of emerging cybersecurity risks related to AI and cloud technologies.
  • Ability to balance innovation with security and regulatory requirements.
  • Demonstrated skills in incident response and cyber resilience.

Responsibilities

  • Develop and execute a multi-year cybersecurity strategy aligned with business objectives.
  • Lead the Cybersecurity Governance, Risk & Compliance (GRC) program and executive reporting.
  • Oversee the cybersecurity strategy for secure AI adoption and emerging technologies.
  • Manage risks associated with AI technologies and establish security requirements.
  • Identify opportunities to leverage AI for enhancing cybersecurity operations.
  • Advise senior leadership on cybersecurity and technology risks.
  • Support executive-level reporting on cybersecurity posture and initiatives.

Benefits

  • Opportunities for professional development in a fast-paced environment.
  • Access to cutting-edge cybersecurity tools and technologies.
  • Participation in strategic decision-making at executive levels.
  • Comprehensive training programs to enhance skills and leadership capabilities.
Full Job Description


Primary Objective of the Position

The primary objective of this role is to provide strategic leadership for the organization's cybersecurity program by proactively monitoring emerging cybersecurity trends, technologies, and evolving threat landscapes. The role is responsible for establishing and advancing cybersecurity governance, risk management, compliance, and security initiatives to protect organizational assets, ensure regulatory compliance, and drive continuous improvement of the overall security posture.

This role serves as a trusted cybersecurity advisor to IT leadership and Executive Management, translating complex cybersecurity and technology risks into clear business priorities, strategic recommendations, and actionable plans. The position is responsible for leading the organization's cybersecurity strategy, governance, risk management, and compliance (GRC) program while providing oversight of security operations, incident response, cyber resilience, cloud security, third-party risk management, and the secure adoption of artificial intelligence (AI) and other emerging technologies. Through proactive risk management and strategic leadership, the role ensures the organization's cybersecurity posture remains resilient, compliant, and aligned with business objectives.

Job Duties:

  • Develop and execute a multi-year cybersecurity strategy, roadmap, and operating model aligned with business objectives and enterprise risk.
  • Lead the Cybersecurity Governance, Risk & Compliance (GRC) program, including risk assessments, risk registers, policies, controls, remediation, and executive reporting.
  • Lead cybersecurity strategy for the secure adoption of Artificial Intelligence (AI), Generative AI, machine learning, and other emerging technologies.
  • Assess and manage cybersecurity, privacy, data, and third-party risks associated with AI-enabled technologies and emerging technology platforms.
  • Establish security and governance requirements for the responsible use of AI and Generative AI, including data protection, access controls, model security, monitoring, and risk management.
  • Identify opportunities to leverage AI and automation to enhance threat detection, security monitoring, incident response, vulnerability management, and security operations.
  • Monitor emerging cyber threats and attack techniques involving AI and develop appropriate controls, detection capabilities, and response strategies.
  • Partner with technology, data, privacy, legal, and business teams to establish secure-by-design principles for AI and emerging technologies.
  • Advise CIO, IT leadership, executive management, and other senior stakeholders on cybersecurity and technology risk.
  • Support Executive and Board-level reporting on cybersecurity posture, risk, compliance, and strategic initiatives.
  • Lead cybersecurity compliance, audit, customer security assessments, and regulatory reviews.
  • Establish cybersecurity KPIs/KRIs and metrics to measure risk, control effectiveness, maturity, and program performance.
  • Develop cybersecurity priorities, budgets, business cases, and investment plans.
  • Provide executive oversight of cyber incident response, cyber resilience, tabletop exercises, and major incident reviews.
  • Oversee the performance of the outsourced Security Operations Center (SOC), including monitoring, detection, incident response, vulnerability management, and threat intelligence.
  • Lead third-party and supply-chain cybersecurity risk management, including vendor assessments and security requirements.
  • Provide cybersecurity governance and risk oversight for cloud, infrastructure, applications, data, identity, AI, and emerging technologies.
  • Partner with technology, business, Legal, Privacy, Risk, Internal Audit, Procurement, and external providers to embed security into business and technology decisions.
  • Lead, mentor, and develop cybersecurity team members and build a high-performing security organization.


Qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.
  • 12+ years of progressive cybersecurity/information security experience, including 5+ years in a leadership or management role.
  • Strong experience in cybersecurity strategy, GRC, enterprise risk management, and security assurance.
  • Experience overseeing SOC/MSSP relationships and cybersecurity operations.
  • Understanding of emerging cybersecurity risks associated with AI, cloud, automation, and evolving technology platforms.
  • Ability to balance innovation with security, privacy, regulatory, and enterprise risk requirements
  • Demonstrated experience with incident response, cyber resilience, and security program management.
  • Experience presenting cybersecurity risks and strategy to senior executives.
  • Experience supporting audits, regulatory reviews, customer security assessments, and compliance programs.
  • Experience with cloud security and cybersecurity architecture.
  • Experience developing cybersecurity budgets, business cases, metrics, and investment priorities.
  • Strong understanding of frameworks such as NIST, ISO 27001, CIS Controls, and SOC 2.


Preferred Certifications:

  • CISSP, CISM, CRISC, CCSP, GIAC, or other recognized cybersecurity, risk, audit, or information security certifications are considered an asset.


What Success Looks Like

  • Improved cybersecurity maturity and enterprise risk posture
  • Strong cybersecurity governance and executive visibility
  • Effective management and reduction of material cyber risks
  • Strong audit, compliance, and regulatory outcomes
  • Effective third-party cybersecurity risk management
  • Improved cyber incident preparedness and resilience
  • Successful execution of the cybersecurity strategy and roadmap
  • A strong, capable, and sustainable cybersecurity team


Important to Know:

Similar Jobs

More Jobs at Cargojet

More Information Technology Jobs

Find similar YYZ - Senior Manager, Cybersecurity & GRC - FT (4929) jobs: