1

Ciso Jobs in Quebec (NOW HIRING)

Representer exo aupres des instances gouvernementales (Centre gouvernemental de cyberdefense, Transports Quebec, CCCS) sous la delegation du CISO. La liste des responsabilites et taches enumerees ...

You have a track record of building deep trust with stakeholders from the SOC analyst to the CISO. #LI-Remote Company Benefits and Perks: We believe that the best solutions are developed by teams who ...

Ciso information

See Quebec salary details

$150K

$194.6K

$265.5K

How much do ciso jobs pay per year?

As of Aug 18, 2026, the average yearly pay for ciso in Quebec is $194,648.00, according to ZipRecruiter salary data. Most workers in this role earn between $163,000.00 and $225,000.00 per year, depending on experience, location, and employer.

What does a CISO do?

A chief information security officer (CISO) is an executive who ensures that the information, communications, and computer infrastructure of a company or organization remain secure. In this position, you are responsible for the overall information security strategy of your employer. Your responsibilities focus on ensuring that security measures are sufficient throughout the organization and that they meet operational needs and address current cybersecurity threats. Your duties include making high-level decisions about security practices, threat response strategies, and liaising with law enforcement and investigative agencies if necessary. You also ensure compliance with information privacy regulations.

What are the key skills and qualifications needed to thrive as a CISO?

To thrive as a Chief Information Security Officer (CISO), you need deep expertise in information security, risk management, and regulatory compliance, typically supported by a degree in computer science or a related field and extensive experience in cybersecurity leadership. Familiarity with security frameworks (such as NIST, ISO 27001), incident response platforms, and certifications like CISSP or CISM are highly valued. Strong leadership, strategic thinking, and communication skills set top CISOs apart, enabling them to influence organizational culture and bridge gaps between technical and executive teams. These skills ensure effective protection of organizational assets, regulatory compliance, and resilience against evolving cyber threats.

What are the most common challenges faced by a CISO when aligning security initiatives with business objectives?

A CISO often faces the challenge of balancing robust security measures with the need for business agility and innovation. This includes translating technical risks into business terms that stakeholders understand and ensuring security initiatives support, rather than hinder, business goals. CISOs must also navigate competing priorities, manage limited resources, and foster a security-aware culture across departments. Regular collaboration with executive leadership and other business units is essential to align security strategies with organizational objectives and demonstrate the value of security investments.

What is the difference between Ciso vs Security Manager?

AspectCisoSecurity Manager
CredentialsOften requires CISSP, CISM, or CISA certificationsTypically holds CISSP, Security+, or similar certifications
Work EnvironmentStrategic, executive-level, overseeing entire security postureOperational, managing security teams and implementing policies
Employer & Industry UsageUsed in large organizations, corporations, and government agenciesCommon in mid-sized to large companies across various industries
Search & Comparison IntentFocuses on high-level security leadershipFocuses on day-to-day security operations

The Ciso (Chief Information Security Officer) is a senior executive responsible for the overall security strategy, while a Security Manager handles daily security operations and team management. Both roles require relevant certifications and are vital in organizational security, but they differ in scope and strategic focus.

How much is a CISO paid?

Chief Information Security Officers (CISOs) typically earn between $150,000 and $250,000 annually, with salaries varying based on company size, industry, location, and experience. Senior CISOs or those in large organizations can earn over $300,000, especially if they hold advanced certifications like CISSP or CISM and have extensive cybersecurity leadership experience.

Is a CISO a good career?

A Chief Information Security Officer (CISO) is a senior executive responsible for an organization's cybersecurity strategy and risk management. It is a high-level role that typically requires extensive experience in information security, leadership skills, and relevant certifications such as CISSP. The position offers strong career growth, high earning potential, and the opportunity to influence organizational security policies.

What are popular job titles related to Ciso jobs in Quebec?

For Ciso jobs in Quebec, the most frequently searched job titles are:

What job categories do people searching Ciso jobs in Quebec look for?

The top searched job categories for Ciso jobs in Quebec are:

Infographic showing various Ciso job openings in Quebec as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $194,648 per year, or $93.6 per hour.

Directeur du CSIRT/CSIRT Director

SITA Switzerland Sarl

Montreal, QC • On-site

Full-time

Re-posted 21 days ago


Job description

Overview
WELCOME TO SITA

At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.

You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward—we’re proud to be recognized as a Great Place to Work® by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow.

Are you ready to love your job?

The adventure begins right here, with you, at SITA.

ABOUT THE ROLE & TEAM

The CSIRT Director is a cybersecurity leader responsible for the complete ownership, strategy, and operational execution of the organization's enterprise Computer Security Incident Response Team (CSIRT).

The CSIRT Director operates at the strategic, operational, and tactical levels simultaneously, serving as the single point of accountability for all related cybersecurity response functions. This leader directs a globally distributed team across three operations center locations in Montreal (Canada), Cairo (Egypt), and Singapore, ensuring continuous, follow-the-sun security operations coverage.

This role reports directly to the Chief Information Security Officer (CISO) and serves as a key member of the cybersecurity leadership team, providing executive-level guidance on threat posture, incident trends, and operational risk.

WHAT YOU WILL DO
  • Continuous Threat Exposure Management (CTEM) - Directs the organization's proactive exposure reduction program. This includes attack surface management, vulnerability prioritization, red team / purple team program oversight, penetration testing governance, and the coordination of remediation workflows with IT and engineering stakeholders.
  • Cyber Threat Intelligence (CTI) - Commands the intelligence function responsible for producing finished, operationalized threat intelligence. This includes strategic intelligence briefings to CISO and Board, tactical intelligence feeds into detection platforms, threat actor tracking, sector-specific threat analysis (transportation/aviation/border security), and third-party intelligence partnerships.
  • Incident Response (IR) - Owns the full incident response lifecycle. Accountable for IR planning and playbook governance, crisis management and executive communication during significant incidents, forensic capability oversight, tabletop exercise program, regulatory breach notification coordination, and post-incident reviews (PIRs).
  • Security Operations (SecOps) Collaboration - Direct and optimize resources across global SOC locations (Montreal, Cairo, Singapore), ensuring consistent standards, 24/7/365 coverage through a followthesun operating model, and resilient business continuity with defined failover capabilities. Drive collaboration and intelligence sharing across sites while managing MSSP and thirdparty partners to ensure performance, accountability, and unified global operations.
  • Strategic Leadership & Governance - Define and lead a multiyear global CSIRT strategy, serving as the single point of accountability for threat exposure, intelligence, and incident response while aligning capabilities to business risk and industry frameworks. Own executive reporting, budget planning, and the establishment of clear SLAs and KPIs to ensure a mature, scalable, and effective cybersecurity operations program.
  • People Leadership & Talent Development - Lead, develop, and retain a highperforming global cybersecurity operations team across CTEM, CTI, and Incident Response, fostering an inclusive, highaccountability culture that enables collaboration across regions and time zones. Establish clear career pathways, performance management, and succession planning while overseeing staffing models, shift coverage, and oncall operations across all SOC locations.
  • Executive & Stakeholder Engagement - Act as the primary liaison to the CISO, delivering executive and boardlevel insights on security operations, threat posture, and incident response effectiveness. Partner crossfunctionally with architecture, engineering, GRC, legal, and IT teams, and represent CSIRT in audits, regulatory reviews, and customer security engagements.

Qualifications
WHO YOU ARE 
  • 15+ years of progressive experience in cybersecurity, with at least 7+ years in a senior leadership role with direct accountability for security operations.
  • 5+ years of direct experience managing large, geographically distributed Security Operations Centers (SOCs) — including multi-site, multi-shift, 24/7/365 operations.
  • Bachelor's degree in computer science, Information Systems, Information Security, or a related discipline; or equivalent professional experience.
  • Active professional certification in at least one of the following: CISSP, CISM, CISA, GIAC GSOM, GIAC GCIH, or equivalent.
  • Proven experience managing global teams across multiple time zones and cultures, with a track record of building cohesive, high-performing distributed teams. With demonstrated ownership of an Incident Response Function and Team.
  • Demonstrated ownership of two or more of the following functions: SOC, CTEM / Vulnerability Management, Cyber Threat Intelligence,
  • Strong command of the MITRE ATT&CK framework, NIST CSF, and incident response methodologies (SANS PICERL, NIST 800-61).
  • Executive-level communication skills — ability to translate complex technical threats into business risk language for CISO, C-suite, and Board audiences.
NICE TO HAVE
  • Experience in the aviation, transportation, border security, or critical national infrastructure sectors.
  • Hands-on background in threat hunting, malware analysis, digital forensics, or red team operations.
  • Experience leading or overseeing a CTEM/BAS (Breach and Attack Simulation) program.
  • Familiarity with security platforms including Elastic/Splunk SIEM, CrowdStrike/SentinelOne EDR, ServiceNow SecOps, Recorded Future or Mandiant Advantage CTI platforms.
  • Proficiency in DevSecOps and cloud security principles (AWS, Azure, GCP) in the context of SOC monitoring.
  • Experience with NIST 800-53, ISO 27001, PCI DSS, and SOC 2 compliance environments.
  • Master's degree or Executive Education in Cybersecurity, Business Administration, or Risk Management.
WHAT WE OFFER

We’re all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We’re really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

 Flex Day: Make your workday suit your life and plans.

 Flex Location: Take up to 30 days a year to work from any location in the world. 

Employee Wellbeing: We’ve got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health – a personalized platform that supports a range of wellbeing needs.

Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.

 Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. 

SITA is an Equal Opportunity Employer and values a diverse workforce. In support of our Employment Equity Program, women, aboriginal people, members of visible minorities, and/or persons with disabilities are encouraged to apply and self-identify in the application process. 

Qualifications:WHO YOU ARE 
  • 15+ years of progressive experience in cybersecurity, with at least 7+ years in a senior leadership role with direct accountability for security operations.
  • 5+ years of direct experience managing large, geographically distributed Security Operations Centers (SOCs) — including multi-site, multi-shift, 24/7/365 operations.
  • Bachelor's degree in computer science, Information Systems, Information Security, or a related discipline; or equivalent professional experience.
  • Active professional certification in at least one of the following: CISSP, CISM, CISA, GIAC GSOM, GIAC GCIH, or equivalent.
  • Proven experience managing global teams across multiple time zones and cultures, with a track record of building cohesive, high-performing distributed teams. With demonstrated ownership of an Incident Response Function and Team.
  • Demonstrated ownership of two or more of the following functions: SOC, CTEM / Vulnerability Management, Cyber Threat Intelligence,
  • Strong command of the MITRE ATT&CK framework, NIST CSF, and incident response methodologies (SANS PICERL, NIST 800-61).
  • Executive-level communication skills — ability to translate complex technical threats into business risk language for CISO, C-suite, and Board audiences.
NICE TO HAVE
  • Experience in the aviation, transportation, border security, or critical national infrastructure sectors.
  • Hands-on background in threat hunting, malware analysis, digital forensics, or red team operations.
  • Experience leading or overseeing a CTEM/BAS (Breach and Attack Simulation) program.
  • Familiarity with security platforms including Elastic/Splunk SIEM, CrowdStrike/SentinelOne EDR, ServiceNow SecOps, Recorded Future or Mandiant Advantage CTI platforms.
  • Proficiency in DevSecOps and cloud security principles (AWS, Azure, GCP) in the context of SOC monitoring.
  • Experience with NIST 800-53, ISO 27001, PCI DSS, and SOC 2 compliance environments.
  • Master's degree or Executive Education in Cybersecurity, Business Administration, or Risk Management.
WHAT WE OFFER

We’re all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We’re really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

 Flex Day: Make your workday suit your life and plans.

 Flex Location: Take up to 30 days a year to work from any location in the world. 

Employee Wellbeing: We’ve got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health – a personalized platform that supports a range of wellbeing needs.

Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.

 Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. 

SITA is an Equal Opportunity Employer and values a diverse workforce. In support of our Employment Equity Program, women, aboriginal people, members of visible minorities, and/or persons with disabilities are encouraged to apply and self-identify in the application process. 

Education:UNAVAILABLEEmployment Type: FULL_TIME