Cybersecurity Risk Manager strengthening risk governance for Kinaxis, a global supply-chain orchestration software company. Evaluating cloud, product, third-party, and AI-enabled cybersecurity risks.
Responsibilities
Lead end-to-end execution of cybersecurity risk identification, assessment, prioritization, and treatment planning across enterprise systems and services
Ensure consistent application of risk frameworks and methodologies aligned to enterprise governance and regulatory expectations
Oversee control evaluation, residual risk analysis, and risk acceptance recommendations
Maintain a complete, accurate, and decision-ready cybersecurity risk register
Deliver management-ready risk reporting and insights to support decision-making, prioritization, and escalation
Strengthen data quality, metrics, and reporting practices
Align cybersecurity risk practices with FedRAMP, SOC, ISO 27001, and related regulatory and assurance requirements
Translate regulatory expectations into risk management practices, remediation plans, and governance controls
Support continuous monitoring and evidence readiness for audits and certifications
Evaluate risks associated with cloud environments, third-party services, and AI-enabled capabilities
Contribute to AI risk governance practices, including assessment criteria, controls, and reporting mechanisms
Monitor emerging cybersecurity, AI, and regulatory developments
Provide technical leadership and quality oversight across risk assessment activities and outputs
Influence engineering, product, legal, and compliance stakeholders to ensure risks are understood, owned, and addressed
Drive continuous improvement of processes, tooling, and automation to enhance risk program maturity
Requirements
University degree or equivalent practical experience in Information Security, Computer Science, or a related field
5–7 years of progressive experience in cybersecurity risk, IT risk, audit, or compliance
Strong knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and SOC 2 frameworks
Ability to operationalize risk frameworks into scalable processes, metrics, and reporting
Strong analytical and influencing skills
Ability to translate technical risk into business decision insights
Experience with GRC platforms, audit evidence, and workflow automation
Demonstrated commitment to continuous learning
Strong desire to stay current on generative and agentic AI and their cybersecurity implications
Preferred certifications include CRISC, CISSP, CISM, CISA, or equivalent
Experience with cloud security and regulated SaaS/cloud environments, including FedRAMP readiness, is preferred
Familiarity with AI risk management concepts, including NIST AI and ISO/IEC 42001, is preferred
Experience applying AI, automation, analytics, or GRC workflow improvements is preferred
Experience with privacy, data protection, GDPR, CCPA, NIS2, or other applicable security and compliance obligations is preferred
Benefits
Flexible vacation and Kinaxis Days (company-wide days off)
Flexible work options
Physical and mental well-being programs
Regularly scheduled virtual fitness classes
Mentorship programs, training, and career development
Recognition programs and referral rewards
Hackathons
Accommodations upon request throughout the recruitment process
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.