Cybersecurity Risk Manager strengthening risk governance for Kinaxis, a global supply-chain orchestration software company. Evaluating cloud, product, third-party, and AI-enabled cybersecurity risks.
Responsibilities
Lead end-to-end execution of cybersecurity risk identification, assessment, prioritization, and treatment planning across enterprise systems and services
Ensure consistent application of risk frameworks and methodologies aligned to enterprise governance and regulatory expectations
Oversee control evaluation, residual risk analysis, and risk acceptance recommendations
Maintain a complete, accurate, and decision-ready cybersecurity risk register
Deliver management-ready risk reporting and insights to support decision-making, prioritization, and escalation
Strengthen data quality, metrics, and reporting practices
Align cybersecurity risk practices with FedRAMP, SOC, ISO 27001, and related regulatory and assurance requirements
Translate regulatory expectations into risk management practices, remediation plans, and governance controls
Support continuous monitoring and evidence readiness for audits and certifications
Evaluate risks associated with cloud environments, third-party services, and AI-enabled capabilities
Contribute to AI risk governance practices, including assessment criteria, controls, and reporting mechanisms
Monitor emerging cybersecurity, AI, and regulatory developments
Provide technical leadership and quality oversight across risk assessment activities and outputs
Influence engineering, product, legal, and compliance stakeholders to ensure risks are understood, owned, and addressed
Drive continuous improvement of processes, tooling, and automation to enhance risk program maturity
Requirements
University degree or equivalent practical experience in Information Security, Computer Science, or a related field
5–7 years of progressive experience in cybersecurity risk, IT risk, audit, or compliance
Strong knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2 frameworks
Ability to operationalize risk frameworks into scalable processes, metrics, and reporting
Strong analytical and influencing skills
Ability to translate technical risk into business decision insights
Experience with GRC platforms, audit evidence, and workflow automation
Demonstrated commitment to continuous learning
Strong desire to stay current on generative and agentic AI and their cybersecurity implications
Preferred certifications include CRISC, CISSP, CISM, CISA, or equivalent
Experience with cloud security and regulated SaaS/cloud environments, including FedRAMP readiness, is preferred
Familiarity with AI risk management concepts, including NIST AI and ISO/IEC 42001, is preferred
Experience applying AI, automation, analytics, or GRC workflow improvements is preferred
Experience with privacy, data protection, GDPR, CCPA, NIS2, or other applicable security and compliance obligations is preferred
Benefits
Flexible vacation and Kinaxis Days (company-wide days off)
Flexible work options
Physical and mental well-being programs
Regularly scheduled virtual fitness classes
Mentorship programs, training, and career development
Recognition programs and referral rewards
Hackathons
Accommodations upon request throughout the recruitment process
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.