1

Cyber Risk Management Jobs in Ottawa, ON (NOW HIRING)

Manager-PAM and Entra

Ottawa, ON · On-site

CA$112K - CA$162K/yr

... from cyber threats through advanced technologies and strategies. They work to identify ... risk assessments, bid management, proposal writing, and contract management. * Practice development ...

Own and evolve the QNX Cybersecurity Management System-your ideas will drive improvements. * Dive ... Lead Threat Analysis and Risk Assessment (TARA) activities, ensuring compliance with ISO 21434.

Senior Automation Developer

Ottawa, ON · On-site

CA$84K - CA$134K/yr

Offer broadexpertiseacrossvarioustechnical domains, withemphasis on cyber security. * Embed risk ... Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture {+ 8 ...

Showing results 21-35

Cyber Risk Management information

See Ottawa, ON salary details

$28.1K

$98.5K

$159.1K

How much do cyber risk management jobs pay per year?

As of Aug 22, 2026, the average yearly pay for cyber risk management in Ottawa, ON is $98,455.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,493.00 and $121,935.00 per year, depending on experience, location, and employer.

What is cyber risk management?

A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.

What are some common challenges faced in a cyber risk management role, and how are they typically addressed?

Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.

What are the key skills and qualifications needed to thrive in cyber risk management, and why are they important?

To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.

How much does a cyber risk management professional make?

Cyber risk management professionals typically earn a median annual salary ranging from $80,000 to $130,000, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity frameworks and risk assessment tools can earn higher salaries, often exceeding $150,000 annually.

What does a cyber risk management do?

A cyber risk management professional identifies, assesses, and prioritizes cybersecurity threats to an organization. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may hold certifications such as CISSP or CISM. Their work helps protect sensitive data and ensure business continuity in a constantly evolving threat landscape.

What are popular job titles related to Cyber Risk Management jobs in Ottawa, ON?

For Cyber Risk Management jobs in Ottawa, ON, the most frequently searched job titles are:

Infographic showing various Cyber Risk Management job openings in Ottawa, ON as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 84% Physical, 4% Hybrid, and 12% Remote job distribution, with an average salary of $98,455 per year, or $47.3 per hour.

Cybersecurity Operations Engineer

Hydro Ottawa

Ottawa, ON • On-site

Full-time

Posted 9 days ago


Job description

Please Note: If you are a current Hydro Ottawa employee with access to Workday, apply to this job via the Workday application.

At Hydro Ottawa, we empower the lives of the people in the communities we serve.

We help to power your professional growth at every step of your engineering career. For those starting out, we provide the training and skills needed to achieve your P.Eng. designation, and for established engineers, our structured framework offers a clear, transparent pathways to intermediate and senior levels. Wherever you are in your career, there's a path for growth ahead of you here.

As the electricity distributor to the Nation's Capital, our work powers the essential activities that make up our lives - at home, at work and at play. And as Ontario's largest municipally-owned producer of green power, we are leading the way to a greener tomorrow.

We are seeking a Cybersecurity Operations Engineer, a strategic thinker who can take initiatives from concept to completion and engineer the way to a smart energy future.

Are you ready to make a difference in our community?

JOB SUMMARY

The Cybersecurity Operations Engineer is responsible for the programmatic design, automation, and architectural integrity of Hydro Ottawa's cybersecurity infrastructure. Working within the Cybersecurity team to protect the organization's critical infrastructure and assets, this role leverages an engineering framework to design baseline system configurations, build automated integration pipelines, and orchestrate workflows to proactively prevent, detect, and manage cyber threats across corporate applications, identity systems, and infrastructure platforms.

Under the guidance of the Supervisor, Cybersecurity, the Cybersecurity Operations Engineer acts as the primary technical asset for cybersecurity systems architecture, incident response, automation activities, authentication policies, enterprise application interfacing, and day-to-day user support operations. The Cybersecurity Operations Engineer is responsible for evaluating, scripting, and supporting the development of all new system integrations, ticketing workflows, and related business processes to ensure advanced security controls, compliance baselines, and identity architectures are strictly incorporated across the corporate environment.

Additionally, the role serves as a core technical resource for confidential internal security investigations, regularly isolating and preserving digital forensic evidence relating to employee policy violations, data exfiltration, or labour relations breaches.

MAJOR RESPONSIBILITIES

  • Programmatically orchestrate, analyze and respond to security alerts by designing, identifying root causes and contributing factors, testing, and engineering automated playbooks to continuously harden infrastructure against future events and eliminate manual workflows.

  • Conduct confidential internal security investigations into potential policy violations, unauthorized access, and data exfiltration by personnel.

  • Regularly collect, analyze, and preserve digital forensic evidence required by Management for employee disciplinary actions, grievances, or formal labour relations proceedings.

  • Monitor internal employee system logs and network activities on a confidential basis to identify and report scrutiny irregularities or compliance breaches directly to Management.

  • Proactively monitor and analyze actionable threat intelligence from industry feeds and open-source intelligence (OSINT) to programmatically update detection rules, SIEM watchlists, and automated playbooks against emerging cyber threats.

  • Conduct exposure management across corporate systems to detect vulnerabilities, prioritize risk mitigation efforts, and guide other IT teams on architectural remediation.

  • Ensure strict alignment with corporate security frameworks through continuous validation of compliance baselines across internal endpoints, host infrastructure, and directory access permissions.

  • Address, respond to, and resolve incoming tickets within the corporate ticketing system, serving as a primary point of contact for security operations.

  • Provide advanced technical support and engineering guidance to internal units, resolving complex authentication blocks, systemic vulnerabilities, and integration constraints.

  • Act as the engineering liaison to the CSaaS Security Operations Center (SOC) to investigate security detections, manage data sources, and troubleshoot device connectivity.

  • Engineer, maintain, and secure core network trust infrastructure, by deploying automated solutions to manage trust certificates for internal resources (e.g., workstations, servers, websites).

  • Develop, write, and maintain custom scripts (e.g., PowerShell, Python, Bash) to automate repetitive security tasks, streamline log analysis, and optimize operational pipelines.

  • Architect, test, and implement secure integrations between new software applications, cloud environments, and existing core IT infrastructure.

  • Build, program, and maintain API integrations and automated pipelines to sync security tooling, directory services, and cloud platforms (e.g., Google Cloud, IBM).

  • Perform formal security compliance and architectural reviews on new system integrations, certifying that deployment configurations strictly follow secure designs and corporate frameworks.

  • Audit and review onboarded software assets and emerging tools to certify that all enterprise deployment pipelines align with established corporate policies and cybersecurity requirements.

  • Manage endpoint configuration and user policies by enforcing centralized and automated registry-level enforcement baselines.

  • Program and scale Identity and Access Management (IAM) environments, specifically configuring complex authentication policies, single sign-on (SSO), and automated identity governance.

  • Deploy, monitor, and maintain IdP authentication policies across the enterprise, managing user access and application-specific access rules.

  • Create analysis workflows and associated business processes to ensure cybersecurity needs and architectural designs are successfully incorporated in the practices and solutions of other corporate Divisions.

  • Participate in the technical development, planning and execution of new cybersecurity initiatives.

  • Perform other related duties as required.

EDUCATION AND EXPERIENCE

  • Undergraduate degree in Engineering from an accredited university

  • Professional Engineer, licensed or able to be licensed in the province of Ontario

  • Completion of-or the ability to obtain within two years-one or a combination of the following designations: CEH, OCSP, CISA, CISM, CISSP or GIAC certifications (i.e. GCIH, GPEN, etc.)

  • Experience in an electric utility engineering environment considered an asset

  • Experience in cloud security is considered an asset

  • Proficiency in scripting languages such as Python, Powershell considered an asset

  • Strong computer skills; proficient in the use of office productivity and collaboration tools, preferably Google Workspace, as well as different Microsoft tools

  • English essential, both oral and written; Bilingual (English/French) considered an asset

This is a management group opportunity and salary will be commensurate with qualifications.

Hydro Ottawa offers a Hybrid Work Model. Hybrid work is position specific, details of the hybrid model will be discussed with successful candidates.

Hydro Ottawa may use artificial intelligence ("AI") during the recruitment process to aid in the screening and selection of candidates.

Location:Ottawa, ON

This is a management group opportunity. The annual salary range for this position identified below depends on experience, education, and professional designation. The successful candidate will be offered a salary within this range based on their qualifications.

Pay Range Minimum:$89,420.99Pay Range Maximum:$134,130.81Posting End Date (if applicable):September 13, 2026

Hydro Ottawa is committed to establishing a qualified workforce that reflects the diverse population it serves and we encourage applications from all qualified individuals. We are also committed to preventing and removing barriers to employment for people with disabilities, and we invite you to inform us should you have any accessibility or accommodation needs.

Applicants must be legally entitled to work in Canada.