Description:
The Senior Manager, Cybersecurity provides leadership and oversight for CCS’s cybersecurity program, ensuring the organization effectively manages cyber risk, security governance, compliance, and assurance activities. The role leads the cybersecurity team, establishes and maintains security policies and standards, oversees risk assessments, audits, vulnerability management, and third-party security reviews, and provides strategic guidance on security architecture and emerging threats. Working closely with Technology Operations and business leaders, the position helps strengthen CCS’s overall security posture, supports informed risk-based decision-making, and ensures cybersecurity practices are embedded across organizational initiatives.
What You’ll Be Doing
- Lead the cybersecurity team and operating model
- Lead, coach, and develop the cybersecurity team, including performance management, capability development, and workforce planning.
- Assign and prioritize team work to support effective delivery of operational, governance, and strategic cybersecurity activities.
- Support recruitment, onboarding, and role development for cybersecurity team members.
- Set team objectives and align team activities with departmental priorities and organizational goals.
- Oversee planning and coordination of cybersecurity initiatives and ongoing operational work.
- Maintain and improve the cybersecurity operating model to support clear accountability, effective execution, and cross-functional collaboration.
- Own cybersecurity governance, risk, audit, compliance and assurance processes
- Lead the development, maintenance, and update of cybersecurity policies, standards, and related governance artefacts including AI governance.
- Define and oversee governance processes for risk acceptance, compliance requirements, and third-party risk management, including assessment standards, risk treatment expectations, and remediation tracking.
- Lead security audits and assurance activities, including evidence management and action tracking to completion.
- Provide oversight and leadership for vulnerability management and governance, including remediation tracking and follow-through with accountable stakeholders.
- Establish and maintain a recurring reporting cadence for leadership on risk posture, control effectiveness, key trends, and cybersecurity program progress.
- Strategic oversight and cross-functional security leadership
- Review, approve, and socialize security reference architecture and design patterns.
- Provide security guidance for new and changing technology solutions in alignment with approved security reference architecture and design patterns.
- Monitor and manage shadow IT risk in partnership with Technology Operations and business owners.
- Build and maintain effective working relationships with internal stakeholders to strengthen security practices and support organizational priorities.
- Other
- Foster a high-performance culture that leverages the unique talents and strengths of each member while encouraging their growth and development.
- Champion CCS as a hero in the face of cancer.
- Contribute to our culture of diversity, inclusion, belonging and equity (DIBE) by ensuring that all staff feel represented, valued, and heard across all aspects of their identity, including gender, age, religion, ethnicity, nationality, race, and sexuality.
- Other duties as assigned.
Qualifications
- Diploma or bachelor’s degree in computer science, information technology, cybersecurity, or related field.
- Relevant certifications such as CISSP, CISM, CRISC, GIAC, or equivalent would be considered assets.
- 5+ years – extensive job-related experience in progressively more senior positions.
- Demonstrated experience in cybersecurity governance, risk management, assurance, or compliance activities.
- Proven people leadership experience, including coaching, mentoring, and team development.
- Experience developing, implementing, and maintaining policies, standards, and related governance frameworks.
- Experience overseeing audits, vulnerability management, and third-party risk management processes.
- Strong stakeholder management skills with the ability to effectively coordinate cross-functional initiatives in a complex technology environment.
- Experience reporting cybersecurity risks, priorities, and recommendations to senior leadership using a risk-based approach.
- Bilingualism (French/English) is highly preferred, with French being an asset due to the organization’s nationwide operations and the need for effective communication across various regions.
- Others may apply.
- For roles based in Quebec, French is required. Knowledge of another language may be required depending on job responsibilities and business needs.