Your Opportunity We are seeking a highly motivated Senior Consultant to join our Cyber Risk Management & Transformation practice. The successful candidate will support organizations in identifying ...
Your Opportunity We are seeking a highly motivated Senior Consultant to join our Cyber Risk Management & Transformation practice. The successful candidate will support organizations in identifying ...
Cybersecurity Strategy and Transformation Senior Manager
CA$144K - CA$241K/yr
Provide thought leadership and direction for the cyber risk management practice. * Team with PwC colleagues in other practice areas in support of client needs for cyber risk management services.
Cybersecurity Strategy and Transformation Senior Manager
CA$144K - CA$241K/yr
Provide thought leadership and direction for the cyber risk management practice. * Team with PwC colleagues in other practice areas in support of client needs for cyber risk management services.
Manager Cyber Cloud Security and AI
Ottawa, ON · Hybrid
CA$116K - CA$166K/yr
Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data ... cyber resilience. * Team Leadership:Lead and mentor a team of cybersecurity professionals ...
Manager Cyber Cloud Security and AI
Ottawa, ON · Hybrid
CA$116K - CA$166K/yr
Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data ... cyber resilience. * Team Leadership:Lead and mentor a team of cybersecurity professionals ...
Senior Manager Cyber Cloud Security and AI
Ottawa, ON · On-site
CA$168K - CA$218K/yr
... from cyber threats through advanced technologies and strategies. They work to identify ... Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data ...
Senior Manager Cyber Cloud Security and AI
Ottawa, ON · On-site
CA$168K - CA$218K/yr
... from cyber threats through advanced technologies and strategies. They work to identify ... Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data ...
Commercial Account Executive
Ottawa, ON · On-site +1
... Cyber Risk, Errors & Omissions, Directors & Officers, Construction & Surety, and more. If you bring ... Build and maintain a knowledge base of coverage lines as well as risk management solutions and ...
Commercial Account Executive
Ottawa, ON · On-site +1
... Cyber Risk, Errors & Omissions, Directors & Officers, Construction & Surety, and more. If you bring ... Build and maintain a knowledge base of coverage lines as well as risk management solutions and ...
AVP Commercial Insurance
Ottawa, ON · On-site
... Cyber Risk, Errors & Omissions, Directors & Officers, Construction & Surety, and more. If you bring ... Build and maintain a knowledge base of coverage lines as well as risk management solutions and ...
AVP Commercial Insurance
Ottawa, ON · On-site
... Cyber Risk, Errors & Omissions, Directors & Officers, Construction & Surety, and more. If you bring ... Build and maintain a knowledge base of coverage lines as well as risk management solutions and ...
Own infrastructure risk register items and mitigation plans related to uptime, cyber risk, capacity ... Financial Management & Vendor Leadership * Manage annual operating budget and forecast for ...
Own infrastructure risk register items and mitigation plans related to uptime, cyber risk, capacity ... Financial Management & Vendor Leadership * Manage annual operating budget and forecast for ...
You will proactively identify and mitigate cyber risks, strengthen our security posture, oversee ... Risk Management and Threat Assessments: * Conduct ongoing enterprise-wide cybersecurity risk ...
Quick apply
You will proactively identify and mitigate cyber risks, strengthen our security posture, oversee ... Risk Management and Threat Assessments: * Conduct ongoing enterprise-wide cybersecurity risk ...
We manage our cyber risks and provide industry leading cyber governance, assurance and oversight to ... risk-based decisions to remain a best-in-class function. Within the CSA function, the purpose of ...
We manage our cyber risks and provide industry leading cyber governance, assurance and oversight to ... risk-based decisions to remain a best-in-class function. Within the CSA function, the purpose of ...
We manage our cyber risks and provide industry leading cyber governance, assurance and oversight to ... Review and respond to customer security risk assessments, questionnaires, Requests for Information ...
We manage our cyber risks and provide industry leading cyber governance, assurance and oversight to ... Review and respond to customer security risk assessments, questionnaires, Requests for Information ...
Apply advanced knowledge of Azure cloud security, policy management, automation, and workload ... Ability to assess cyber risk and propose effective mitigation strategies. * Strong communication ...
Apply advanced knowledge of Azure cloud security, policy management, automation, and workload ... Ability to assess cyber risk and propose effective mitigation strategies. * Strong communication ...
... Cyber Planning portfolios. Develop governance frameworks, implementation plans, transition strategies, risk registers, and project documentation. Ensure projects are delivered on time, within scope ...
... Cyber Planning portfolios. Develop governance frameworks, implementation plans, transition strategies, risk registers, and project documentation. Ensure projects are delivered on time, within scope ...
Cybersecurity Incident Manager
Ottawa, ON · Hybrid
CA$112K - CA$162K/yr
In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management, etc. * Knowledge of applications, databases, middleware to address ...
Cybersecurity Incident Manager
Ottawa, ON · Hybrid
CA$112K - CA$162K/yr
In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management, etc. * Knowledge of applications, databases, middleware to address ...
Bilingual Chief Information Security Officer (CISO)
Ottawa, ON · On-site
CA$160K - CA$200K/yr
... cyber resilience. Work Location: Hybrid - Ottawa, Ontario, Canada (Candidates must be located in ... management, and risk remediation Collaborate with executive leadership, business unit leaders, and ...
Bilingual Chief Information Security Officer (CISO)
Ottawa, ON · On-site
CA$160K - CA$200K/yr
... cyber resilience. Work Location: Hybrid - Ottawa, Ontario, Canada (Candidates must be located in ... management, and risk remediation Collaborate with executive leadership, business unit leaders, and ...
Sr. Manager, Trade Compliance
Hamilton, ON · On-site
... cyber domains in the interest of national security. Senior Manager, Trade Compliance Reference ... resources and risk management. * Collaborate with other business functions to integrate trade ...
Sr. Manager, Trade Compliance
Hamilton, ON · On-site
... cyber domains in the interest of national security. Senior Manager, Trade Compliance Reference ... resources and risk management. * Collaborate with other business functions to integrate trade ...
Sr. Manager, Trade Compliance
Hamilton, ON · On-site
... cyber domains in the interest of national security. Senior Manager, Trade Compliance Reference ... resources and risk management. * Collaborate with other business functions to integrate trade ...
Sr. Manager, Trade Compliance
Hamilton, ON · On-site
... cyber domains in the interest of national security. Senior Manager, Trade Compliance Reference ... resources and risk management. * Collaborate with other business functions to integrate trade ...
Understanding ofsecurity concepts such as cyber-attacks, threat vectors, risk management, and incident management. * Strong analytical and problem-solving skills with attention to detail. * Excellent ...
Understanding ofsecurity concepts such as cyber-attacks, threat vectors, risk management, and incident management. * Strong analytical and problem-solving skills with attention to detail. * Excellent ...
Contracts Sr. Specialist
Hamilton, ON · On-site
CA$100K - CA$120K/yr
... cyber domains in the interest of national security. Contracts Sr. Specialist Reference #39231 ... Work on large-scale, complex programs and align the necessary contract and risk management ...
Contracts Sr. Specialist
Hamilton, ON · On-site
CA$100K - CA$120K/yr
... cyber domains in the interest of national security. Contracts Sr. Specialist Reference #39231 ... Work on large-scale, complex programs and align the necessary contract and risk management ...
Contracts Sr. Specialist
Hamilton, ON · On-site
CA$100K - CA$120K/yr
... cyber domains in the interest of national security. Contracts Sr. Specialist Reference #39231 ... Work on large-scale, complex programs and align the necessary contract and risk management ...
Contracts Sr. Specialist
Hamilton, ON · On-site
CA$100K - CA$120K/yr
... cyber domains in the interest of national security. Contracts Sr. Specialist Reference #39231 ... Work on large-scale, complex programs and align the necessary contract and risk management ...
... training, cyber and infrastructure security, and program delivery. With nearly 60 years of ... NIST Risk Management Framework (SP 800-37) * NIST SP 800-53 / ITSG-33 (Medium baseline) * NIST SP ...
Quick apply
... training, cyber and infrastructure security, and program delivery. With nearly 60 years of ... NIST Risk Management Framework (SP 800-37) * NIST SP 800-53 / ITSG-33 (Medium baseline) * NIST SP ...
Cyber Risk Management information
See Ottawa, ON salary details
$28.1K - $40K
6% of jobs
$40K - $51.9K
6% of jobs
$51.9K - $63.8K
5% of jobs
$69.6K is the 25th percentile. Wages below this are outliers.
$63.8K - $75.7K
15% of jobs
$75.7K - $87.6K
11% of jobs
The median wage is $95.4K / yr.
$87.6K - $99.5K
11% of jobs
$99.5K - $111.5K
16% of jobs
$117.7K is the 75th percentile. Wages above this are outliers.
$111.5K - $123.4K
11% of jobs
$123.4K - $135.3K
4% of jobs
$135.3K - $147.2K
3% of jobs
$147.2K - $159.1K
13% of jobs
$28.1K
$98.5K
$159.1K
How much do cyber risk management jobs pay per year?
What is a Cyber Risk Management job?
A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.
Is SOC an entry level job?
What are the key skills and qualifications needed to thrive in the Cyber Risk Management position, and why are they important?
To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.
Can you make $500,000 a year in cyber security?
Can you make $200,000 in cyber security?
What are some common challenges faced in a Cyber Risk Management role, and how are they typically addressed?
Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.
What does a cyber risk manager do?

Full-time
PTO
Posted 24 days ago
Job description
Putting people first, every day
BDO is a firm built on a foundation of positive relationships with our people and our clients. Each day, our professionals provide exceptional service, helping clients with advice and insight they can trust. In turn, we offer an award-winning environment that fosters apeople-first culturewith a high priority on your personal and professional growth.
Your Opportunity
We are seeking a highly motivated Senior Consultant to join our Cyber Risk Management & Transformation practice. The successful candidate will support organizations in identifying, assessing, and managing cybersecurity, technology, and privacy risks while helping clients strengthen their overall security posture and meet regulatory and compliance requirements.
You will work alongside experienced cybersecurity professionals to help clients solve complex cybersecurity, privacy, risk, and compliance challenges. This role offers exposure to a broad range of industries, technologies, and strategic initiatives while providing opportunities for professional growth and leadership development. This role combines cybersecurity consulting, governance, risk and compliance (GRC), privacy, and strategic advisory services. The ideal candidate is a strong communicator who can engage with both technical teams and executive stakeholders, manage multiple client engagements, and deliver practical, risk-based recommendations.
Key Responsibilities
Lead cybersecurity risk assessments, maturity assessments, gap assessments, and control evaluations using frameworks such as NIST CSF, NIST 800-53, ISO 27001:2022, CIS Controls, SOC 2, FedRAMP, and StateRAMP.
Identify, assess, measure, and report on cybersecurity, technology, third-party, and privacy risks through security reviews, audits, evaluations, and risk assessments.
Develop cybersecurity roadmaps, remediation plans, and target-state operating models aligned with client business objectives and risk tolerance.
Assess the effectiveness of cybersecurity programs, governance structures, risk management processes, and technical controls across client environments.
Assess and recommend controls related to Identity and Access Management (IAM), Data Protection, Endpoint Security, Security Monitoring, Vulnerability Management, and Zero Trust Architecture.
Assist organizations with implementing and monitoring privacy programs to ensure compliance with regulations and standards such as PIPEDA, Quebec Law 25, GDPR, and other applicable privacy requirements.
Evaluate security and control requirements for new technologies, cloud implementations, digital transformation initiatives, and emerging technologies, including Artificial Intelligence (AI).
Conduct third-party and vendor security assessments and support supply chain risk management initiatives.
Assess incident response, business continuity, disaster recovery, and cyber resilience programs, providing recommendations to improve readiness and response capabilities.
Facilitate cybersecurity workshops, risk discussions, and stakeholder interviews.
Develop executive-level reports, presentations, dashboards, risk registers, and strategic recommendations for senior leadership and boards.
Research, pilot, and implement innovative cybersecurity and privacy solutions tailored to client objectives and business environments.
Provide strategic guidance on Governance, Risk, Compliance (GRC), Privacy, and Cybersecurity Program initiatives.
Identify opportunities to improve delivery efficiency, methodologies, and client outcomes.
Drive the successful completion of cybersecurity engagements while managing project plans, budgets, deliverable schedules, resources, and client expectations.
Support proposal development, business development initiatives, thought leadership, and client presentations.
How do we define success for your role?
You demonstrate BDO's core values through all aspect of your work: Integrity, Respect and Collaboration
You understand your stakeholder's industry, challenges, and opportunities; stakeholders describe you as positive, professional, and delivering high-quality work
You identify, recommend, and are focused on effective service delivery to your stakeholders
You share in an inclusive and engaging work environment that develops, retains & attracts talent
You actively participate in the adoption of digital tools and strategies to drive an innovative workplace
You grow your expertise through learning and professional development
Your Experience and Education:
5-8+ years of experience in cybersecurity, information security, IT risk management, privacy, governance, or cybersecurity consulting.
Strong understanding of industry frameworks and standards including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FedRAMP, and StateRAMP.
Experience conducting cybersecurity risk assessments, control reviews, maturity assessments, and compliance assessments.
Strong understanding of cybersecurity governance, risk management, and security control frameworks.
Experience assessing security controls across cloud, infrastructure, application, and data environments.
Excellent written, verbal, presentation, and stakeholder management skills.
Experience delivering client-facing consulting engagements and managing multiple concurrent projects.
Strong analytical, problem-solving, and project management capabilities.
Professional Certifications (One or More Preferred)
CISSP
CISM
CRISC
CISA
ISO 27001 Lead Implementer/Lead Auditor
PMP
Why BDO?
Our people-first approach to talent has earned us a spot among Canada's Top 100 Employers for 2026. This recognition is a milestone we're thrilled to add to our collection of awards for both experienced and student talent experiences.
At BDO, our people experience is guided by three core pillars-Do work with genuine care, Do what matters with purpose, and Do what's next - shaping how we support our people, serve our clients, and grow together.
Our firm is committed to providing an environment where you can be successful in the following ways:
- We enable you to engage with how we change and evolve, being a key contributor to the success and growth of BDO in Canada.
- We help you become a better professional within our services, industries, and markets with extensive opportunities for learning and development.
- We support your achievement of personal goals outside of the office and making an impact on your community.
- We foster a collaborative, inclusive environment where your ideas are valued, and you can do your best work with genuine care and purpose
- We encourage innovation and forward thinking, empowering you to embrace what's next and help shape the future of our firm
Giving back adds up:Where company meets community.BDO is actively involved in our communities by supporting local charity initiatives. We support staff with local and national events where you will be given the opportunity to contribute to your community.
Total rewards that matter: We pay for performance with competitive total cash compensation that recognizes and rewards your contribution. We provide comprehensive benefits from day one, and a flexible personal time off policy. We're committed to supporting your overall wellbeing and provide reimbursement for wellness initiatives that fit your lifestyle.
Everyone counts: We are committed to creating a workplace where employees can participate fully, contribute meaningfully and succeed without barriers. We are dedicated to fostering a workplace defined by respect, fairness, and a true sense of belonging for everyone. We recognize and celebrate the unique experiences, identities, and perspectives that each of us bring - and that these experiences strengthen how we work together. Our commitment extends to ensuring that our application process is both inclusive and accessible. If you require accommodation to complete the application process, please contact us.
Flexibility: All BDO personnel are expected to spend some of their time working in the office, at the client site, and virtually unless accommodations or alternative work arrangements are in place.
Our model is a blended approach designed to support the flexible needs of our people, the firm and our clients. It's about creating work experiences that meet everyone's needs and providing flexibility to adjust when, where and how we work to meet the expectations of our role.
Code of Conduct: Our Code of Conduct sets clear standards for how we conduct business. It reflects our shared values and commitments and includes guiding principles to help us make ethical decisions and maintain trust with each other, our clients, and the public.
BDO may use artificial intelligence enabled tools to support certain aspects of the recruitment process. While these tools assist our teams, our use of AI does not replace human decision making, and all employment-related outcomes are made by BDO personnel.
More information on BDO Canada's Privacy Policy can be found here:
Privacy Policy | BDO Canada
Ready to make your mark at BDO? Click "Apply now" to send your up-to-date resume to one of our Talent Acquisition Specialists.
To explore other opportunities at BDO, check out ourcareers page.