Information Security Manager, Mergers & Acquisitions (Montreal)

Information Security Manager, Mergers & Acquisitions (Montreal)

01 Aug
|
Socket.dev
|
Montreal

01 Aug

Socket.dev

Montreal

WHAT IF YOU COULD REDEFINE WHAT'S POSSIBLE? WITH US, YOU CAN.

With us, you can. You want Purpose. Growth. Opportunity. People who get it.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth of engineering, advisory and science‑basedexpertise, our global minds unite to power local solutions.We are pathfinders and impact makers.We are Visioneers.We are WSP

THE OPPORTUNITY

Drive Secure Growth Through Strategic TransformationPlay a pivotal role in shaping secure business growth as an Information SecurityManager, Mergers & Acquisitions. In this role, you will lead critical securitydue diligence, risk evaluation, and integration efforts across acquisitions,divestitures, and joint ventures—ensuring every transaction aligns with WSP’ssecurity framework and risk posture.You’ll collaborate with Corporate Development, Legal, IT, and executivestakeholders to assess, advise, and integrate security practices within afast-paced, deal-driven environment, directly influencing the success andresilience of strategic business initiatives across Canada.

YOUR IMPACT

- Lead information security due diligence activities for mergers, acquisitions,and divestitures.
- Perform pre-acquisition security risk assessments, including evaluation ofpolicies, controls, technologies, and cyber maturity.
- Identify key security risks, liabilities, and remediation requirements,including regulatory, contractual, and operational risks.
- Work with security penetration testing vendors to coordinate, track, andevaluate penetration testing activities, as well as remediation schedules.
- Coordinate breach assessment activities in line with transaction schedules.
- Provide clear, actionable risk reports and executive-level summaries tosupport transaction decision-making.
- Support deal teams in defining security-related representations, warranties,and contractual requirements.
- Work with M&A; Operations to develop and maintain security integrationplaybooks and frameworks aligned with WSP standards.
- Define Day 1 security expectations as well as day 30/60/90 securityintegration plans where necessary, including identity, network, endpoint,data protection, and monitoring controls.
- Coordinate the execution of security integration activities across IT,infrastructure, and business teams.
- Ensure alignment of acquired entities to WSP’s security policies, standards,and ISO27001-aligned ISMS.
- Track and report on integration progress, risks,



and remediation activities.
- Ensure M&A; activities are aligned with WSP’s Information Security Governanceframework and risk management processes.
- Act as the primary security advisor for M&A; initiatives, providing guidanceon risk acceptance, mitigation strategies, and prioritization.
- Maintain documentation and audit trail supporting due diligence decisions andintegration activities.
- Participate in governance forums and provide updates on transaction-relatedsecurity risks and status.
- Develop strong working relationships with Corporate Development, Legal, IT,and regional business leadership.
- Act as the central coordination point for all security-related M&Aactivities.;
- Communicate complex security risks and integration strategies clearly to bothtechnical and non-technical stakeholders.
- Support client-facing or third-party interactions where required duringtransactions.
- Assess third-party and inherited vendor risks associated with acquiredentities.
- Ensure appropriate risk treatment plans are defined and executed forhigh/critical risks.
- Align acquired third-party relationships with WSP’s third-party cyber riskmanagement framework.
- Develop and enhance M&A; security assessment methodologies, tools, andtemplates.
- Contribute to the evolution of WSP’s security standards, policies, andplaybooks based on lessons learned.
- Identify opportunities to streamline and automate assessment and integrationprocesses.
- Support awareness and training initiatives related to M&A; security risksacross the organization.

THE SKILLS THAT SET YOU APART

- Bachelor’s degree in Information Technology, Computer Science, Business, RiskManagement, or a related field (or equivalent experience).
- 4–8 years of experience in information security, IT risk, or cybersecurity,including at least 2 years supporting M&A; security due diligence orintegration.
- Proven experience leading security risk assessments, control evaluations, andcompliance activities.
- Strong project management skills with the ability to lead multiple concurrentworkstreams end-to-end independently.
- Working knowledge of ISO 27001,



NIST CSF, and CIS Controls.
- Broad expertise across core security domains including IAM, network andendpoint security, data protection, vulnerability management, and monitoring.
- Experience in third-party/vendor risk management and security assessmentmethodologies.
- Strong communication, stakeholder engagement, and analytical skills with theability to operate in fast-paced environments.

WHY CHOOSE WSP?

- Proudly Canadian – we are a Top 100 Employer in Canada for 2026.
- A global community of brilliant minds – your next idea, mentor, or opportunityis always within reach.
- Limitless opportunities start here. Whether it’s across the country or aroundthe globe, we help you tailor your role to match your ambition — because yourgrowth drives ours.
- Flexible work, real balance – we recognize the importance of balance in ourlives and encourage you to prioritize the balance in yours.

#WeAreWSP

COMPENSATION

AB, BC, NT, NU, SK & YT: $135,200 - $179,100

MB & ON: $123,300 - $169,800

NB, NL, NS, PE & QC: $122,100 - $162,200

Disclosure

The final salary awarded for this role may vary from the above range based onseveral factors including, but not limited to, relevant education,qualifications, certifications, experience, skills, seniority, geographiclocation, performance, and business or organizational needs. The wage rangeprovided in this job posting may be subject to change for business purposes.

PLEASE NOTE:

Health and Safety is a core paramount value of WSP. Given the importance ofkeeping one another safe it is expected that you comply with our Health, Safety& Environment (HSE) policy at all times as well as client HSE policies whenworking at client locations. Full details herehttps://www.wsp.com/en-ca/corporate/ca/health-safety

Some safety-sensitive positions involve fieldwork and may include work in avariety of environmental conditions, such as remote or isolated areas, workingalone, and in inclement weather (within protected and reasonable limits).

WSP welcomes and encourages applications from people with disabilities.

Accommodations are available on request for candidates taking part in allaspects of the selection process.

WSP is committed to the principles of employment equity. Only the candidatesselected will be contacted.

WSP does not accept unsolicited resumes from agencies. Full details herehttps://www.wsp.com/en-ca/careers/notice-to-staffing-agencies

📌 Information Security Manager, Mergers & Acquisitions (Montreal)
🏢 Socket.dev
📍 Montreal

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security manager, mergers & acquisitions (montreal) / montreal

Subscribe to this job alert:

Get the latest job offers by email for: information security manager, mergers & acquisitions (montreal) / montreal