Manager, IT, GRC and Security (Toronto)

Manager, IT, GRC and Security (Toronto)

02 Sep
|
Canadian Standards Association
|
Toronto

02 Sep

Canadian Standards Association

Toronto

Employment Status

Regular

Time Type

Full time

BUILDING A WORLD CLASS TEAM STARTS WITH YOU

At the heart of CSA Group is a vision: making the world a better, safer, more sustainable place. It's been part of our mission for nearly one hundred years: from the first engineering standard for railway bridges developed in 1919, to more than 3,500 standards, codes & related products today.

Headquartered in Canada, with a global footprint of more than 30 labs and offices across Europe, Asia and North America, CSA Group tests, inspects and certifies a wide range of products - from every day househould items to leading edge technology-to meet exacting requirements for safety, performance and environmental impact.

Our employees take pride in making a difference in people's lives through the work that we do. We're looking for people like you to help make it happen.

Job Summary

CSA Group has an immediate chance for a Manager, IT Governance, Risk & Compliance to lead the development, delivery, and continuous improvement of CSA Group's technology governance, risk and compliance framework, and the assurance and resilience activities that evidence its effectiveness. This role owns the technology policy, standard, procedure, and control framework; leads technology and cybersecurity risk assessment, treatment, and reporting; oversees compliance with internal policies, contractual obligations, customer requirements, and applicable regulatory and privacy requirements; and coordinates internal and external audits through to remediation of findings. The role also leads security assurance and third-party risk activities, governs the enterprise disaster recovery and technology resilience program, and ensures cybersecurity incident response plans and escalation paths are documented, tested, and understood.

While technology delivery teams design, build, and operate security controls day-to-day, this role defines the control requirements those teams must meet, independently validates that controls are implemented and operating effectively, tracks remediation to closure, and reports residual risk to the IT Leadership Team and executive leadership.

Responsibilities

- Leads the enterprise IT governance and compliance program, and develops, maintains, and periodically reviews technology policies, standards, procedures, and control frameworks aligned to recognized frameworks and CSA's risk appetite.
- Maintains the control library, mapping controls to policy, framework, contractual, customer, and regulatory obligations to avoid duplicate testing, and validates through assurance activity that controls are implemented and operating effectively.
- Facilitates technology and cybersecurity risk assessments across the technology estate, projects, and third parties, and maintains the risk register, ensuring mitigation and remediation plans are tracked to closure.
- Operates the risk acceptance and control exception process, and provides risk input into project charters, architecture decisions, change management, and technology investment decisions.
- Oversees compliance with internal policies, contractual obligations, customer requirements, and regulatory and privacy requirements, and plans and executes IT self-assessments and control testing.
- Coordinates internal and external audits and certification or attestation activity,



including scoping, evidence collection, management responses, and remediation of findings, and maintains the compliance calendar and evidence repository.
- Oversees security assessments of applications, systems, cloud services, and vendors, and leads the penetration testing and security assurance program, including provider selection, finding triage, and retest verification.
- Leads third-party and supply chain security risk management, including due diligence, criticality tiering, ongoing monitoring, and secure offboarding.
- Manages customer security questionnaires, due diligence requests, and customer-led audits, and reviews customer and vendor contracts for alignment with IT policies and the governance framework.
- Governs the enterprise disaster recovery and technology resilience program, ensures plans and RTO/RPO objectives are established and validated through testing, and reports on status and gaps to ITLT and executive leadership.
- Ensures cybersecurity incident response plans, playbooks, and escalation paths are documented, exercised, and understood, and coordinates governance, reporting, and post-incident corrective action for significant incidents.
- Governs the reporting and remediation performance of vulnerability management, security monitoring, and threat management activities performed by delivery teams.
- Builds organizational cybersecurity awareness and owns the security awareness and training program, including phishing simulation and role-based training.
- Establishes priorities, delivery plans, and performance expectations for the governance, risk, compliance, and assurance program, and directs assigned resources and third-party assessors who do not report to the role.
- Manages GRC and assurance budgets, vendor relationships, and contracts, and holds managed security service providers and cyber assurance partners accountable to agreed scope and service levels.
- Serves as a trusted advisor to technology leadership and business stakeholders, and presents cybersecurity and risk status, trends, and significant issues to ITLT and executive leadership in business language.
- Provides coaching, technical direction, and development support to the GRC Senior Associate and other staff performing governance, risk, and compliance work.
- Completes special projects and reports as required.

Education & Experience

- University degree in Computer Science, Information Technology, Cybersecurity, Engineering, or Business. Master's degree considered an asset.
- Ten-plus (10+) years of progressive experience in cybersecurity, information security, technology risk, governance, compliance, or technology operations, including three to five (3-5) years leading a governance, risk, compliance, or security assurance program.
- Experience leading enterprise security governance and risk programs within complex, multi-national, and regulated environments.
- Experience managing audits, risk programs, security assessments,



and technology governance initiatives, including planning, execution, reporting, and remediation.
- Experience coordinating the response to cybersecurity incidents, including stakeholder reporting, notification assessment, and tracking of corrective actions to closure.
- Experience governing disaster recovery and business continuity programs, including test planning, validation, and corrective action tracking.
- Experience with vendor due diligence, contract security and privacy schedules, and customer security due diligence and questionnaire response.

Skills

- Working expertise in ISO/IEC 27001 and 27002, the NIST Cybersecurity Framework, NIST SP 800-53, COBIT, CIS Controls, and SOC 2 Trust Services Criteria, with the ability to map and rationalize controls across them.
- Working knowledge of privacy and data protection requirements relevant to a global organization (PIPEDA, Quebec Law 25, EU/UK GDPR, applicable US state privacy legislation) sufficient to assess technology impact and work with Legal and Privacy.
- Knowledge of security control implementation across infrastructure, applications, identity, cloud platforms (Microsoft Azure and Microsoft 365), and third-party services, sufficient to challenge control design and validate operating effectiveness.
- Experience with GRC, risk register, policy management, and evidence automation tooling, and with vulnerability and compliance reporting.
- Familiarity with accreditation and conformity assessment requirements applicable to a testing, inspection, and certification body (ISO/IEC 17025, 17020, 17065) considered an asset.
- Excellent problem resolution, influencing, and negotiation skills, with a demonstrated ability to drive outcomes through teams that do not report to the role.
- Excellent written and oral communication skills, including the ability to present technical risk to executive audiences in business terms.
- Must demonstrate good judgment, sound decision-making, and discretion in handling confidential information, including audit findings, control weaknesses, and incident detail.
- Accreditations considered an asset: CISSP, CISM, CRISC, CISA, ISO/IEC 27001 Lead Implementer or Lead Auditor, CGEIT, COBIT, or related risk, governance, or cybersecurity certifications.
- Must be willing to travel to CSA Group locations for assessments, audits, testing, and stakeholder engagement.

This is a hybrid position requiring regular in-person attendance and punctuality in accordance with Company policies. Additionally, the ability to interact well with other employees and work overtime, as necessary, is required. The typical hiring range for this position is $116,230 - $152,555, however, based on a variety of considerations (such as education, licenses, certifications and/or experience,) CSA Group reserves the right to flexibility outside of the stated range.

CSA Group is an Equal Opportunity Employer and is committed to diversity, equity, and inclusion. We prohibit discrimination and harassment of any kind based on any grounds stipulated by applicable laws. We are an organization where opportunities are based on skills and abilities, and differences are respected and valued. Please contact us at [email protected] if you require accommodation in the interview process.

📌 Manager, IT, GRC and Security (Toronto)
🏢 Canadian Standards Association
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager, it, grc and security (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: manager, it, grc and security (toronto) / toronto