Talent.com
Information Security Risk Manager
Information Security Risk ManagerPantheon Systems • Toronto, Ontario, Canada
No longer accepting applications
Information Security Risk Manager

Information Security Risk Manager

Pantheon Systems • Toronto, Ontario, Canada
30+ days ago
Job type
  • Full-time
Job description

About Pantheon

Pantheon WebOps Platform powers the open web running more than 300000 sites in the cloud for customers including Google Princeton Salesloft and Doctors Without Borders. Every day thousands of developers and marketers create iterate and scale WordPress and Drupal sites to reach billions of people globally. Pantheons multitenant container-based platform enables organizations to manage all of their websites from a single dashboard. Organizations including Clorox and the United Nations drive results through accelerated development and real-time publishing using Pantheons collaborative workflows.

The Role

Drive technical risk excellence across Pantheon as a key member of our Governance Risk and Compliance (GRC) team. Youll collaborate with teams throughout the organization to transform security risk initiatives into sustainable programs that support our business growth compliance requirements and security objectives. By combining your risk expertise with program management skills youll help shape the future of Pantheons GRC strategy while solving complex challenges critical to Pantheons continued growth and success.

About The Team

Our GRC team serves as the second line of defense and works closely with Information Security IT Product Engineering Legal and other departments to ensure comprehensive risk management across Pantheon. We create and maintain processes that identify assess and mitigate risk. The GRC team plays a vital role in supporting Pantheons commitment to delivering a secure reliable and available platform for our customers.

Remote Canada-based

We are only considering candidates based in Canada for this position with a preference for those located in Vancouver BC or Toronto ON

What You Need to Succeed :

  • Define the Risk Management Methodology : The Risk Manager is responsible for creating and documenting Pantheons overall approach to risk. This includes defining the criteria for what constitutes an acceptable level of risk (risk appetite) how to score the likelihood and impact of a risk and how to ultimately treat those risks. This ensures everyone in the organization is on the same page and using a consistent process.
  • Lead the Risk Assessment Process : This is the most crucial part. The Risk Manager orchestrates and guides the process of identifying analyzing and evaluating all information security risks. This individual ensures that all assetsfrom data and software to physical devices and intellectual propertyare considered. The Risk Manager works with different departments to identify potential threats and vulnerabilities.
  • Develop the Risk Treatment Plan (RTP) : Once risks are identified and assessed the Risk Manager develops the formal plan for how to address each one. ISO 27001 gives four main options for risk treatment :
  • Modify : Implementing controls to reduce the risk. This is the most common option.
  • Retain : Accepting the risk because it falls within the acceptable risk appetite.
  • Avoid : Stopping the activity that causes the risk.
  • Transfer : Shifting the risk to a third party for example through cyber insurance or outsourcing.

The Risk Manager documents these treatment option decisions and ensures each risk has a designated risk owner who is accountable for its treatment.

  • Create the Statement of Applicability (SoA) : This is a critical document for ISO 27001 certification. The Risk Manager is responsible for compiling the SoA which details all the controls from ISO 27002 that Pantheon has selected to mitigate its identified risks. The SoA also includes justifications for any controls that were deemed unnecessary and not included.
  • Monitor and Report : The Risk Manager continuously monitors the effectiveness of the implemented controls and the overall risk environment. The individual provides regular reports to the Director of GRC on Pantheons risk posture any new or emerging threats and the status of the risk treatment plan. This ensures that the ISO 27001 Information Security Management System (ISMS) is always evolving to meet new challenges.
  • Maintain Risk-Related Documentation : A significant part of the Risk Managers job is maintaining all the necessary documentation including the risk register the risk treatment plan and the statement of applicability. This is essential for a smooth audit process.
  • What You Bring to the Table

  • Risk Management Expertise : 6 years of a strong background in formal risk management frameworks such as ISO 27001 NIST SP 800-53 or FedRAMP
  • RIsk Registers Experience : Experienced in implementing and maintaining comprehensive risk registers and control inventories.
  • Communication & Collaboration : The ability to effectively and proactively work across teams (Information Security IT Product Engineering Legal etc.) to gather information and ensure buy-in.
  • Analytical Skills : The ability to analyze data and make informed decisions about risk prioritization and treatment.
  • GRCs Role : An understanding of GRCs role within broader security and risk management contexts.
  • GRC Tool Proficiency : Experience with GRC platforms (especially Vanta or OneTrust) can be a huge plus as they can streamline documentation evidence collection and reporting.
  • Certifications : Certifications like CRISC (Certified in Risk and Information Systems Control) or ISO 27001 Lead Implementer are highly valuable as they demonstrate a proven understanding of the domain.
  • What We Offer

    We have all the usual perks and benefits but what we can really offer you is a fantastic work environment powered by an amazing team.

  • Industry competitive compensation and equity plan
  • Paid Time Off (PTO) Paid Sick Leave (PSL) and 11 Paid Company Holidays
  • Full medical coverage (Extended health care dental vision)
  • In-office workspace (Vancouver)
  • Top-of-line equipment
  • Monthly allowance for wellness reading and access to LinkedIn Learning for continued development
  • Events and activities both team-based and company wide that inspire educate and cultivate
  • The Canadian base salary range for this position is between 00 CAD per year. This position also offers a performance bonus dependent on company performance. Our salary ranges are determined by role level and location.

    Pantheon is an equal opportunity / affirmative action employer and we welcome applications from all backgrounds regardless of race color religion sex national origin ancestry age marital status sexual orientation gender identity veteran status disability or any other classification protected by law. Pantheon complies with federal and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If you need a reasonable accommodation due to a disability for any part of the interview process please contact Pursuant to local and federal regulations Pantheon will consider qualified applicants with arrest and conviction records for employment.

    To review the Employee and Applicants Privacy Policy click here .

    Required Experience :

    Manager

    Key Skills

    International Development,EMC,JavaScript,Import & Export,Airlines,Asp.Net MVC

    Employment Type : Full Time

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    Manager Information Security • Toronto, Ontario, Canada

    Similar jobs
    Director of Cyber Security - Retail

    Director of Cyber Security - Retail

    Hamilton Barnes Associates Limited • Toronto, Canada
    Full-time
    Ready to take the next step in your career? A multi‑million dollar Canadian retailer is seeking for a Director of Cyber Security to join the rapidly expanding team. Founded in 1992, the company has ...Show more
    Last updated: 30+ days ago • Promoted
    Security Analyst

    Security Analyst

    Hire DigITalent • Aurora, ON, Canada
    Full-time
    Security Monitoring & Incident Response.Partner closely with a managed security service / SOC provider to oversee threat monitoring, investigations, incident response activities, and security rep...Show more
    Last updated: 9 days ago • Promoted
    Manager, Risk Management

    Manager, Risk Management

    Manulife Insurance Malaysia • Toronto, ON, Canada
    Full-time
    Nous utilisons des • •pour fournir des statistiques qui nous aident à vous offrir la meilleure expérience sur note site.Vous y trouverez des renseignements sur les témoins, ou vous pouvez les désac...Show more
    Last updated: 30+ days ago • Promoted
    Manager, Cyber Risk Management

    Manager, Cyber Risk Management

    McCain Foods • Toronto, ON, Canada
    Full-time
    Manager, Cyber Risk Management.Manager, Cyber Risk Management.At McCain, we believe in meaningful technology – using digital technology not just for innovation, but to make a difference globally.Jo...Show more
    Last updated: 30+ days ago • Promoted
    Lead Information Security Engineer : Security Strategy & Operations

    Lead Information Security Engineer : Security Strategy & Operations

    Mastercard • Toronto, Canada
    Full-time
    A leading global payments technology company in Toronto seeks a Lead Information Security Engineer.The ideal candidate will excel in managing security operations, with expertise in incident, vulner...Show more
    Last updated: 3 days ago • Promoted
    Manager Operational Resilience - markham

    Manager Operational Resilience - markham

    Tundra Technical Solutions • markham, on, ca
    Full-time
    Manager Operational Resilience.Location : Oakville, ON (Hybrid).The Manager, Operational Resilience is responsible for leading a small team that supports the AVP, Enterprise Risk Management by devel...Show more
    Last updated: 4 hours ago • Promoted • New!
    Manager, Technology Risk Management

    Manager, Technology Risk Management

    KPMG LLP Canada • Toronto, ON, Canada
    Full-time
    At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause : turning insight into opportunity for clients and communities around the world.Our Technology Risk ...Show more
    Last updated: 30+ days ago • Promoted
    Cloud Infrastructure Project Manager

    Cloud Infrastructure Project Manager

    Swoon • Greater Toronto Area, Canada
    Full-time
    Cloud Infrastructure Project Manager.Scarborough, ON (Remote role with occasional onsite availability required).IT / Cloud / Risk & Reputation. T4) OR $75-80 / hour (Incorporated).We are looking for a...Show more
    Last updated: 6 hours ago • Promoted • New!
    Director - Product Management - Value Added Services

    Director - Product Management - Value Added Services

    Xplore Inc. • Markham, ON, Canada
    Full-time
    Canada’s fibre, 5G and satellite broadband company for rural living.Xplore is committed to the relentless pursuit of an improved broadband experience for all Canadians. Xplore is building a world-cl...Show more
    Last updated: 14 days ago • Promoted
    InfoSec Manager : ISO 27001 & Cloud Security Lead

    InfoSec Manager : ISO 27001 & Cloud Security Lead

    Jefferson Capital Systems, LLC • Toronto, Canada
    Full-time
    A financial services company is seeking an Information Cybersecurity Manager to oversee daily operations in the IT / Info Sec department. Key responsibilities include maintaining IT Security initiativ...Show more
    Last updated: 2 days ago • Promoted
    Manager, Enterprise Risk Management

    Manager, Enterprise Risk Management

    Teranet Inc. • Toronto, ON, Canada
    Full-time
    Manager, Enterprise Risk Management.Teranet is Canada’s leader in the delivery and transformation of statutory registry services with extensive expertise in land and commercial registries.We also m...Show more
    Last updated: less than 1 hour ago • Promoted • New!
    Risk Manager

    Risk Manager

    Entuitive • Toronto, ON, Canada
    Full-time
    The ideal candidate will possess a strong background in risk management principles and practices, an understanding of engineering design practices, and a passion for delivering projects that meet b...Show more
    Last updated: 10 days ago • Promoted
    Audit Manager II, Financial Risk

    Audit Manager II, Financial Risk

    Vaco by Highspring • Aurora, Ontario, Canada
    Permanent
    Our client is one of the world's leading global financial services companies.They are looking for an experienced Audit Manager to join their Financial Risk audit team!. Opportunity to join a high-pe...Show more
    Last updated: 11 hours ago • Promoted • New!
    Change Management Lead

    Change Management Lead

    freelance.ca • Richmond Hill, Canada
    Full-time
    New Value Solutions, a national IT consulting company, is seeking a Change Management Lead.The successful candidate will design and implement a scalable, repeatable change management structure to s...Show more
    Last updated: 30+ days ago • Promoted
    Risk Management Specialist

    Risk Management Specialist

    The Talent Company • Markham, ON, Canada
    Full-time
    Why You Will Love This Organization.Our client is a long-established Canadian subsidiary of a global organization, recognized as a leader in heating, cooling, and ventilation technologies as well a...Show more
    Last updated: 8 days ago • Promoted
    Security Concierge Supervisor

    Security Concierge Supervisor

    FirstService Residential • Markham, ON, Canada
    Full-time
    As a Security Concierge Supervisor, you’ll be responsible for assisting residents by providing information and services as needed. This role requires someone that is self-motivated, outgoing, ...Show more
    Last updated: 9 days ago • Promoted
    Health and Safety Advisor

    Health and Safety Advisor

    Ramudden • Gormley, ON, Canada
    Full-time
    Through a network of various brands and businesses, we offer a wide range of services designed to enhance road safety, streamline traffic management, and support critical infrastructure projects.Fr...Show more
    Last updated: 3 days ago • Promoted
    Product Manager, Cloud Application Security

    Product Manager, Cloud Application Security

    Data Theorem • Toronto, ON, CA
    Full-time
    Quick Apply
    Your Career Data Theorem focuses on preventing application security (AppSec) data breaches.The main areas of security specialty include : API, Cloud, Mobile, Web, and Software Supply Chain.We are se...Show more
    Last updated: 30+ days ago