Talent.com
Current External
Senior Manager, Information Security Risk and GovernanceCurrent External • Toronto, Ontario, Canada
Senior Manager, Information Security Risk and Governance

Senior Manager, Information Security Risk and Governance

Current External • Toronto, Ontario, Canada
30+ days ago
Salary
CA$100,712.00 yearly
Job type
  • Full-time
Job description

Role impact:

The Senior Manager Information Security Risk & Governance leads the Information Security Risk Management and Governance programs. Their main objective is to manage and continue the development of both programs to enhance and communicate the value of the Information Security (IS) practice in reducing related risks to CF.

In addition this role is expected to work with technology and business stakeholders to identify Information Security risks conduct risk assessments recommend risks mitigation strategies and monitor identified risks throughout its lifecycle. They also develop maintain and report on Key Performance Indicators (KPIs) Key Risk Indicators (KRIs) Service Level Agreements (SLAs) and other documentation related to the Information Security program.

What you will deliver:

  • Own and manage the Risk & Governance program within the D&T Department
  • Understand and manage Information Security risks pertinent to the organizations business goals and work with various departments to identify measure monitor and report on risk based on information assets
  • Partner with senior leadership team to obtain approvals for treatment of risk
  • Develop document and communicate risk mitigation strategies to risk owners; document and monitor the implementation of security controls and adjust risk rating accordingly
  • Develop maintain and report on KRIs KPIs and SLAs related to Information Security program.
  • Research implement and operate risk and governance technology tools and processes to enhance the effectiveness of the practice
  • Develop new Information Security policies; ensure all existing policies and related documents are up to date
  • Liaise with auditors and support the internal and external audit processes including the collection of requested artifacts review and prioritization of findings and recommendations.
  • Stay abreast of and actively seek out information on emerging trends in Information Security risks and threat vectors; apply new techniques in-line with overall Information Security objectives and risk tolerance of the organization
  • Work with internal stakeholders to develop strategies and implementation plans to enforce Information Security requirements and address identified risks
  • Identifies requirements and conducts business impact analyses for threats risks and vulnerabilities for the Security Operations team to execute vulnerability assessments penetration tests and security audits
  • Primary author for risk and governance reports to highlight risk posture of the organization mitigations and recommendations

What your strengths are:

  • Ability to discuss with clarity risk and governance matters with non-technical stakeholders.
  • Ability to analyze a large complex interlinked environment of data communications and information systems where the technology is changing as well as the types of threats and vulnerabilities.
  • Excel at problem-solving with a deep understanding of computer security and applicable laws and regulations.
  • Understand business goals and operations and align risk mitigation recommendations with overall strategy and budget.
  • Proven ability to conduct research into Information Security controls and technologies as required.
  • Ability to work independently setting goals prioritize and execute tasks in a high-pressure environment.
  • Excellent written oral and interpersonal communication skills.
  • Ability to collaborate effectively with other leaders
  • Ability to provide effective coaching to direct reports

What you need to succeed:

  • Post-secondary degree in Computer Science or equivalent combination of education and experience that satisfy the requirements of the position.
  • Minimum 8 years of progressive responsibilities in developing and supporting Information Security risks management and governance programs; out of them 3 years in a management role.
  • Excellent knowledge of security technologies which are commonly used in enterprises to protect information systems including on premise Cloud and Mobile.
  • Working knowledge of Information Security and Risk Management frameworks like ISO27001/2 ISO27005 NIST CSF and NIST 800-30
  • Understanding of legal and regulatory compliance standards and requirements like PCI-DSS and PIPEDA
  • CISSP CISA CRISC and other security certifications are a strong asset.

Starting base salary for this job level may range from $100712 - $125920. The actual base salary offered will consider several factors including but not limited to the role experiences skills & qualifications location market and internal considerations; with this context CF reserves the right to pay above this range.

Cadillac Fairview offers a competitive total rewards package in addition to base pay which includes a performance based incentive plan a comprehensive pension and benefits plan paid time off including vacation wellbeing & volunteer days and support for continued growth and development.

Why you should join us:

At Cadillac Fairview we have been transforming communities for over 50 years. We are so much more than our properties. We are building leaders at all levels. We offer the challenge of interesting work a great organizational culture the opportunity to collaborate with the best in the business and support for your growth and development. We reward values-based behavior and superior results with a competitive rewards package that includes best-in-class benefits and pension. Imagine a place where you can make a difference!

At CF our everyday actions and critical business decisions are guided by our CF Values. Achieving results is naturally important for us and we achieve results through behaviours that are consistent with our CF Values.

Are you someone who believes in our values

  • Aim Higher we strive to exceed expectations
  • Own Your Expertise we empower ourselves and each other
  • Collaborate Effectively we bring the right people together to get the right results
  • Engage with Empathy we objectively consider the needs of others
  • Embrace Change we drive learn from and adapt to change

At CF youll join a diverse community and award-winning team where your talent and commitment to excellence are welcomed valued and respected.

CF isan equal opportunity employerand is committed to creating a diverse and inclusive environment. If you need reasonable accommodation during the recruitment assessment and/or selection process please notify your CF contact or email


Required Experience:

Senior Manager


Employment Type : Full-Time
Experience: years
Vacancy: 1
Monthly Salary Salary: 100712 - 125920
Create a job alert for this search

Senior Manager, Information Security Risk and Governance • Toronto, Ontario, Canada

Similar jobs

Manager Of Information Security - $112,583 - $162,125 A Year

MorningstarEast York, Canada
Full-time

Manages information security compliance and privacy across the organization, leading a team and ensuring adherence to policies and regulations.Focuses on risk management, audits, and reporting. Show more

 • Promoted

Senior Threat Risk Architect – InfoSec & Risk

Rubicon PathToronto, ON, CA
Full-time

A leading security consultancy in Toronto is seeking a Senior Security Specialist to assess threats and implement security measures.The ideal candidate will have expertise in security architecture ... Show more

 • Promoted

Senior Manager - IT Governance Risk and Control

Enercare Inc.Markham, ON, CA
Full-time

Canada’s largest home and commercial services companies servicing over one million customers across Ontario, Manitoba, Saskatchewan, Alberta, British Columbia, Quebec and New Brunswick.Enercare is ... Show more

 • Promoted

Information Security Governance Analyst

Ontario Medical AssociationToronto, ON, CA
Full-time

Advance the cybersecurity landscape as an Information Security Governance Analyst.Focus on compliance oversight, risk management strategies, and security improvements in a flexible hybrid environme... Show more

 • Promoted

Strategic Information Security Architect

ColliersToronto, ON, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Manulife Senior Information Risk Position

ManulifeToronto, Canada
Full-time

Role involves safeguarding business initiatives, emerging technologies, and cloud solutions by embedding security and risk management principles.Responsibilities include risk assessments, identifyi... Show more

 • Promoted

Manager, IT Governance, Risk and Compliance

Pet Valumarkham, on, Canada
Full-time +1

Manager, IT Governance, Risk and ComplianceApplyremote type: Hybridlocations: 0001 – Markham Officetime type: Full timeposted on: Posted Todayjob requisition id: R25751Hybrid: Markham, On... Show more

 • Promoted

Senior Cybersecurity Manager Transforming Public Transport Security

ALSTOM GruppeToronto, ON, CA
Full-time

Become a pivotal force in transportation safety as a Senior Cybersecurity Manager.Utilize your expertise in cybersecurity and system management in a hybrid work setting.This strategic role requires... Show more

 • Promoted

Privacy Governance Senior Manager Role

OpenTextRichmond Hill, York Region, CA
Full-time

Shape the future of privacy compliance as a Senior Manager in Privacy Governance at OpenText.Drive revenue enablement and maintain rigorous security standards in a collaborative setting.You will le... Show more

 • Promoted

Senior Manager, Technology Risk Governance & Compliance

Corus EntertainmentToronto, ON, CA
Full-time

Risk Governance and Compliance.Toronto, ON (Hybrid, 2‑3 days in office).This role has a broad mandate, supporting both the Head of Enterprise Risk Management and the Head of Cybersecurity and Techn... Show more

 • Promoted

Senior Consultant in Information Security

Control Gap Inc.Toronto, ON, CA
Full-time

Make an impact as a Senior Consultant at CyberGuard Advantage, focusing on cybersecurity and compliance.Deliver insights into risk management and strengthen clients’ security postures.As a Senior I... Show more

 • Promoted

Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development CorporationToronto, ON, CA
Full-time

Security Incident Response Manager.This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats.T... Show more

 • Promoted

Senior Manager, Information Security - C$95,000 - C$142,400 A Year

MeridianEast York, Canada
Full-time

The Senior Manager will lead the cybersecurity team, implement the Cyber Security Strategy, and manage incident response. Show more

 • Promoted

Senior Manager, Information Security - C$108,800 - C$163,200 A Year

TdEast York, Canada
Full-time

Lead Privileged Access Management Governance Team.Develop security solutions, manage compliance, and oversee privileged accounts.Requires extensive cybersecurity experience. Show more

 • Promoted

Senior Associate, Information Security

Publicis Groupe Holdings B.VToronto, ON, CA
Full-time

The Senior Associate, Information Security is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendor... Show more

 • Promoted

Senior Manager, Information Security Risk & Governance

Onico Solutionsrichmond hill, york region, Canada
Permanent

Senior Manager, Information Security Risk & Governance.The Senior Manager, Information Security Risk & Governance leads the Information Security Risk Management and Governance programs.Their main o... Show more

 • Promoted

Information Security Manager

Insight GlobalToronto, Ontario, Canada
Full-time

Demonstrated history of technical leadership and strategic thinking in security roles.Extensive experience leading and managing complex security investigations and threat hunting engagements.Bachel... Show more

 • Promoted

Senior Leader, Cyber Risk Management

Capcotoronto, on, Canada
Full-time

As a Senior Leader within Capco’s Cyber Risk Management practice, you will be driving the growth, delivery, and innovation of our cybersecurity and technology risk services across the financial ser... Show more

 • Promoted

Senior Manager, Technology Risk — Drive Growth & Client Impact

EYToronto, ON, CA
Full-time

A leading consulting firm is seeking a Senior Manager in Edmonton to enhance client trust in their information systems while expanding business development in the technology risk space.The successf... Show more

 • Promoted

Senior Manager Cyber Cloud Security and AI

PwC South Africatoronto, on, Canada
Full-time

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies.They work to identify vulnerabilities, develop secure systems, ... Show more