Talent.com
BDO
Senior Consultant, Cyber Risk Management & TransformationBDO • Oakville
Senior Consultant, Cyber Risk Management & Transformation

Senior Consultant, Cyber Risk Management & Transformation

BDO • Oakville
30+ days ago
Job type
  • Full-time
Job description

Putting people first, every day

BDO is a firm built on a foundation of positive relationships with our people and our clients. Each day, our professionals provide exceptional service, helping clients with advice and insight they can trust. In turn, we offer an award-winning environment that fosters a with a high priority on your personal and professional growth.

Your Opportunity

We are seeking a highly motivated Senior Consultant to join our Cyber Risk Management & Transformation practice. The successful candidate will support organizations in identifying, assessing, and managing cybersecurity, technology, and privacy risks while helping clients strengthen their overall security posture and meet regulatory and compliance requirements.

You will work alongside experienced cybersecurity professionals to help clients solve complex cybersecurity, privacy, risk, and compliance challenges. This role offers exposure to a broad range of industries, technologies, and strategic initiatives while providing opportunities for professional growth and leadership development. This role combines cybersecurity consulting, governance, risk and compliance (GRC), privacy, and strategic advisory services. The ideal candidate is a strong communicator who can engage with both technical teams and executive stakeholders, manage multiple client engagements, and deliver practical, risk-based recommendations.

Key Responsibilities

  • Lead cybersecurity risk assessments, maturity assessments, gap assessments, and control evaluations using frameworks such as NIST CSF, NIST 800-53, ISO 27001:2022, CIS Controls, SOC 2, FedRAMP, and StateRAMP.

  • Identify, assess, measure, and report on cybersecurity, technology, third-party, and privacy risks through security reviews, audits, evaluations, and risk assessments.

  • Develop cybersecurity roadmaps, remediation plans, and target-state operating models aligned with client business objectives and risk tolerance.

  • Assess the effectiveness of cybersecurity programs, governance structures, risk management processes, and technical controls across client environments.

  • Assess and recommend controls related to Identity and Access Management (IAM), Data Protection, Endpoint Security, Security Monitoring, Vulnerability Management, and Zero Trust Architecture.

  • Assist organizations with implementing and monitoring privacy programs to ensure compliance with regulations and standards such as PIPEDA, Quebec Law 25, GDPR, and other applicable privacy requirements.

  • Evaluate security and control requirements for new technologies, cloud implementations, digital transformation initiatives, and emerging technologies, including Artificial Intelligence (AI).

  • Conduct third-party and vendor security assessments and support supply chain risk management initiatives.

  • Assess incident response, business continuity, disaster recovery, and cyber resilience programs, providing recommendations to improve readiness and response capabilities.

  • Facilitate cybersecurity workshops, risk discussions, and stakeholder interviews.

  • Develop executive-level reports, presentations, dashboards, risk registers, and strategic recommendations for senior leadership and boards.

  • Research, pilot, and implement innovative cybersecurity and privacy solutions tailored to client objectives and business environments.

  • Provide strategic guidance on Governance, Risk, Compliance (GRC), Privacy, and Cybersecurity Program initiatives.

  • Identify opportunities to improve delivery efficiency, methodologies, and client outcomes.

  • Drive the successful completion of cybersecurity engagements while managing project plans, budgets, deliverable schedules, resources, and client expectations.

  • Support proposal development, business development initiatives, thought leadership, and client presentations.

How do we define success for your role?

  • You demonstrate BDO's core values through all aspect of your work: Integrity, Respect and Collaboration

  • You understand your stakeholder’s industry, challenges, and opportunities; stakeholders describe you as positive, professional, and delivering high-quality work

  • You identify, recommend, and are focused on effective service delivery to your stakeholders

  • You share in an inclusive and engaging work environment that develops, retains & attracts talent

  • You actively participate in the adoption of digital tools and strategies to drive an innovative workplace

  • You grow your expertise through learning and professional development

Your Experience and Education:

  • 5-8+ years of experience in cybersecurity, information security, IT risk management, privacy, governance, or cybersecurity consulting.

  • Strong understanding of industry frameworks and standards including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FedRAMP, and StateRAMP.

  • Experience conducting cybersecurity risk assessments, control reviews, maturity assessments, and compliance assessments.

  • Strong understanding of cybersecurity governance, risk management, and security control frameworks.

  • Experience assessing security controls across cloud, infrastructure, application, and data environments.

  • Excellent written, verbal, presentation, and stakeholder management skills.

  • Experience delivering client-facing consulting engagements and managing multiple concurrent projects.

  • Strong analytical, problem-solving, and project management capabilities.

Professional Certifications (One or More Preferred)

  • CISSP

  • CISM

  • CRISC

  • CISA

  • ISO 27001 Lead Implementer/Lead Auditor

  • PMP

Create a job alert for this search

Senior Consultant, Cyber Risk Management & Transformation • Oakville

Similar jobs

Senior Offensive Security Consultant & Red Team Lead

CDW CanadaVaughan, York Region, CA
Full-time

A leading technology solutions provider in Vaughan, Ontario is seeking a Cyber Security Consultant to conduct penetration testing and provide clients with security insights.Candidates should have o... Show more

 • Promoted

Senior Risk Analyst, Operational Resilience - $64,000 - $106,000 A Year

Canadian Tire Services LimitedOakville, Canada
Full-time

What youu2019ll do:We are seeking a highly skilled and experienced individual to join our team as a Senior Analyst, Operational Resilience, reporting to the Manager, Operational Resilience.As a Sen... Show more

 • Promoted

Mid-Senior Risk & IT Analytics Consultant

TechDoQuestMississauga
Full-time

A leading technology firm is seeking a mid-senior level IT Analyst based in Mississauga to lead risk management initiatives.The role involves comprehensive risk assessments and communication with c... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumMississauga, Peel Region, CA
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Head of Risk - Remote

BitfinexMississauga, Peel Region, CA
Remote
Full-time

Be among the first 25 applicants.Inspired by Bitcoin's vision of financial freedom, we are committed to empowering individuals to transact and connect seamlessly across the globe.From the early day... Show more

 • Promoted

Remote Senior Digital Banking Transformation Architect

LumenaltaMississauga, Peel Region, CA
Remote
Full-time

A fintech consulting company is seeking a Senior Strategist with strong digital banking and fintech experience to lead strategic discovery and guide platform architecture decisions.This role involv... Show more

 • Promoted

Senior Cyber Security Architect - Enterprise Risk & TRA

ResonaiteMississauga, Peel Region, CA
Full-time

A cybersecurity consulting firm is seeking a Senior Cyber Security Architect in Mississauga to provide enterprise-level security architecture leadership.The ideal candidate will possess 8-12 years ... Show more

 • Promoted

Senior DFIR Consultant for Complex Cybersecurity Investigations

New Value SolutionsMississauga, Peel Region, CA
Full-time

Become a pivotal force in cybersecurity as a Senior DFIR Consultant.Lead forensic investigations and incident responses in a contract capacity across enterprise systems.This senior role requires yo... Show more

 • Promoted

Remote Change Lead — Cybersecurity Transformation

ARAGA SOLUTIONSMississauga, Peel Region, CA
Remote
Full-time

A technology solutions provider is seeking a Change Manager to develop and implement a change management strategy focused on cybersecurity modernization.The role involves stakeholder engagement, st... Show more

 • Promoted

Remote GRC & Cybersecurity Compliance Consultant

MalleumMississauga, Peel Region, CA
Remote
Full-time

A leading cybersecurity consultancy in Montreal is seeking a Governance, Risk & Compliance Consultant.The role requires 5-8 years of experience in IT security and risk management, with a deep under... Show more

 • Promoted

Remote Implementation Consultant - Compliance (FinTech ICM)

ConfluenceMississauga, Peel Region, CA
Remote
Full-time

A leading technology firm is seeking an experienced Implementation Consultant - Compliance to support clients in the FinTech space.This role focuses on Investment Compliance Monitoring and involves... Show more

 • Promoted

Senior OT Cybersecurity Leader — ICS Strategy & Risk

BBA ConsultantsVaughan, York Region, CA
Full-time

A leading consulting engineering firm in Vaughan is seeking a Senior OT Cybersecurity Leader to enhance its industrial control systems cybersecurity team.This role involves managing client relation... Show more

 • Promoted

Cybersecurity Consultant – Azure & AI Governance

ConcentrixMississauga, Peel Region, CA
Full-time

Cybersecurity Consultant – Azure & AI Governance.Microsoft ecosystem to advise enterprise customers and lead strategic AI security initiatives.Lead customer workshops to assess AI readiness, focusi... Show more

 • Promoted

Director, IT Organizational Change Management

McKessonMississauga, Peel Region, CA
Full-time

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl... Show more

 • Promoted

Senior Manager, Technology Risk — Drive Growth & Client Impact

EYMississauga, Peel Region, CA
Full-time

A leading consulting firm is seeking a Senior Manager in Edmonton to enhance client trust in their information systems while expanding business development in the technology risk space.The successf... Show more

 • Promoted

Organizational Change Management Lead

AspiringITMississauga
Full-time

We are looking for an Organizational Change Management Lead for our client in GTA.Candidate must have 8+ years of proven experience in a relevant field.The role is hybrid with 2-3 days in office.Co... Show more

 • Promoted • New!

Strategic Digital Transformation Architect

PivotreeMississauga
Full-time

A digital transformation services company in Mississauga seeks an experienced Solution Architect.In this role, you will design technology solutions that facilitate business changes for clients.You ... Show more

 • Promoted • New!

Market Risk Specialist

Open Systems TechnologiesMississauga
Full-time

Global Markets provides world-class solutions that are as diverse as the needs of the corporates, institutions, governments, and individual investors we serve in 160 countries and territories.The b... Show more

 • Promoted

Senior Manager- Technology Risk - Assurance

EYMississauga, Peel Region, CA
Full-time

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you.And we’re counting on your u... Show more

 • Promoted

Senior Cyber Security Analyst - GRC

Metro Supply ChainMississauga
Full-time

Senior Cybersecurity Analyst – Governance, Risk, and Compliance (GRC).Responsible for implementing, and maintaining a firm-wide information security governance program designed to help ensure the S... Show more