Security Program Manager (Canada)

Security Program Manager (Canada)

30 Sep
|
KPG99
|
Canada

30 Sep

KPG99

Canada

Role : Security Risk & AppSec Program Manager

Location : Toronto, Canada (remote role)

Contract : 6-12 Months

Interview : Video

Manager, Security Risk & AppSec Programs to lead and scale enterprise vulnerability management, security risk governance, and application security initiatives across multiple business units.

This is a high-impact, hands-on leadership role focused on reducing enterprise risk, improving remediation velocity, and embedding security into engineering workflows. You will partner closely with Engineering, DevOps, Product, and GRC teams to operationalize security programs and mature our security posture across the organization.

If you are execution-oriented, collaborative, and passionate about measurable risk reduction, this role offers the opportunity to shape enterprise-wide security maturity.

Required Experience

- 8+ years of experience in Information Security (Vulnerability Management, Application Security, Security Risk or GRC).
- Experience managing enterprise vulnerability programs.
- Hands-on experience with SAST, DAST, cloud security, and related tooling.
- Strong understanding of ISO 27001, SOC 2, and audit processes.
- Experience working closely with Engineering and DevOps teams.
- Strong communication and stakeholder management skills.

Nice to Have

- Experience in multi-entity or acquisition-driven organizations.
- Familiarity with CI/CD pipelines and DevOps practices.
- Experience driving automation in risk or vulnerability workflows.
- Relevant certifications (CISSP, CISM, CRISC, CSSLP, etc.).

Lead Enterprise Vulnerability Management





- Own and operate the enterprise vulnerability management program.
- Aggregate and prioritize vulnerabilities from multiple tools (SAST, DAST, CSPM, DSPM, container and infrastructure scanning, third-party risk tools).
- Establish remediation SLAs and drive accountability across business units.
- Lead recurring vulnerability review meetings with Engineering and DevOps teams.
- Deliver structured monthly vulnerability reporting across business units, including aging, trends, and SLA adherence.
- Reduce Mean Time to Remediate (MTTR) and improve enterprise risk visibility.

Build & Scale Application Security Programs

- Design and operationalize a scalable AppSec program.
- Drive adoption of Secure SDLC (SSDLC) practices.
- Lead rollout and integration of SAST/DAST and related tooling into development pipelines.
- Develop AppSec playbooks and ensure sustainable handoff to engineering teams.
- Improve signal-to-noise ratio across multiple security tools through structured triage and prioritization.

Security Tool Operationalization & Automation

- Lead implementation and operationalization of security tools across business units.




- Ensure effective integration of tools into CI/CD pipelines and engineering workflows.
- Improve time-to-value and adoption of security tooling.
- Identify and implement automation opportunities for vulnerability triage, risk scoring, reporting, and remediation tracking.
- Transition security initiatives from implementation phase to sustained BU-level ownership.

Cross-Functional Collaboration & DevSecOps Enablement

- Partner with Engineering, DevOps, Product, and BU leaders to embed security into the software development lifecycle.
- Lead monthly DevSecOps syncs to review risk posture and remediation progress.
- Translate technical findings into explicit business impact for stakeholders.
- Develop dashboards, KPIs, and scorecards to drive transparency and accountability.
- Strengthen security culture and shared ownership across teams.

Strengthen Risk Governance & Compliance

- Maintain and mature business unit-level risk registers.
- Support ISO 27001, SOC 2, HIPAA, and related audit readiness initiatives.
- Improve executive-level risk reporting and security visibility.
- Support onboarding of newly acquired entities into the security and GRC framework.

Program Maturity & Continuous Improvement

- Advance security maturity from reactive to proactive practices.
- Conduct security maturity assessments across business units.
- Standardize processes, documentation, and reporting frameworks.
- Deliver annual enterprise risk and remediation reporting.
- Recommend future roadmap initiatives for tooling, automation, and process optimization.

📌 Security Program Manager (Canada)
🏢 KPG99
📍 Canada

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security program manager (canada) / canada

Subscribe to this job alert:

Get the latest job offers by email for: security program manager (canada) / canada