1

Cyber Risk Manager Jobs in Toronto, ON (NOW HIRING)

Our constantly evolving offerings lead the market in cyber, equipment breakdown, renewable energy, technology services, engineering-based risk management and inspection services. We bring technical ...

... Party Risk Management (TPRM). The successful candidate will be responsible for being a key ... Contribute to cross-service opportunities within multiple areas of the firm including Cyber ...

Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Governance, Methodology, and PMO * Establish Agile SDLC, program governance, RAID, and executive ...

Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Advisory, Enablement, and Change Management * Advise on regulations and frameworks; create ...

Relevant areas include technology and cyber risk management, third-party risk management, operational resilience, incident reporting, data protection, governance, and internal control effectiveness.

Showing results 21-40

Cyber Risk Manager information

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What are popular job titles related to Cyber Risk Manager jobs in Toronto, ON?

For Cyber Risk Manager jobs in Toronto, ON, the most frequently searched job titles are:

Infographic showing various Cyber Risk Manager job openings in Toronto, ON as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 81% Physical, 4% Hybrid, and 15% Remote job distribution.

Senior Manager, Cybersecurity Governance and Risk Management

Toronto, ON • On-site

CA$96K - CA$178K/yr

Full-time

Medical, Dental, Retirement

Posted 11 days ago


Job description

Location Address:

100 Queens Quay East, 9th Floor, Toronto

Number of Openings:

1

Pay:

$96,244.00 - $178,668.00


Job Posting Description:

Senior Manager,

Governance & Risk Management

This is an onsite role [#LI-Onsite]

Are you passionate about overseeing cyber risk management and developing a team of cybersecurity professionals? Reporting to the Director, Cybersecurity, you will develop and operate the LCBO's information security program and manage cybersecurity governance and risk activities. The senior manager ensures our cybersecurity policies, standards, and procedures are in place and followed while implementing risk assessments and providing oversight and challenge to third-party security service providers.

You will also partner with the security architecture practice and lead the development and management of the security training and awareness program while also supporting the reporting function to the Core executive team and Board-level communications. Finally, you will conduct security risk assessments as they relate to all projects that are funneled through the IT Division, including supporting RFP responses.

If you have strong cybersecurity experience and enjoy leading a team, then this is the role for you!

About the Role

Develop an IT Risk and Security Management Framework

  • Be a trusted advisor across all LCBO divisions to identify data and technology-based risks, giving partners expert and realistic analysis to inform their decision-making process.
  • Conduct regular threat risk assessments (TRA) to identify cybersecurity risks and recommend mitigation strategies. Maintain the TRA process and associated artefacts.
  • Evaluate the adequacy of the security controls for our information and technology systems.
  • Manage the LCBO-wide information security compliance program, ensuring IT activities and procedures meet defined requirements.
  • Develop cybersecurity governance documents (policies, standards, baselines, and guidelines) in compliance with relevant legislation and best practices.
  • Conduct cybersecurity assessments of third-party vendors and partners to ensure adherence to LCBO's cybersecurity policies.
  • Lead the Third-Party Risk Management program, assign resources to facilitate TPRM across LCBO, and promote awareness and a culture of risk management across the enterprise.
  • Continuously improve risk management practices and organizational readiness to respond to evolving cyber threats.
  • Oversee enterprise-wide tabletop exercises, identify gaps, and track the associated lessons learned and next steps.
  • Manage the executive security risk dashboard, highlighting material risks, trends, and required actions.
  • Report and communicate with Executive Core team regarding our risk posture.
  • Provide oversight of Managed Security Service Provider services supporting GRC and TPRM and develop metrics to ensure adequate service delivery.

Risk Assessment and Control Assurance

  • Recommend cybersecurity improvements and identify risk and control requirements for upgrades and/or new technologies to enhance the security posture.
  • Provide practical, risk-based recommendations to address cybersecurity problems in a cost-effective manner.
  • Provide security risk and control guidance in support of new technology deployments and projects to improve overall enterprise security.
  • Participate in security risk and control reviews for enterprise architecture and technology initiatives.
  • Provide risk and control oversight for the deployment, integration, and configuration of cybersecurity solutions.

People Management

  • Lead the daily activities, priorities, and development of the Governance and Risk Management team.
  • Provide oversight of GRC and TPRM services delivered by the MSSP, using KPIs and KRIs to monitor performance and drive continuous improvement.
  • Manage vendor relationships and contract responsibilities for the GRC and TPRM service stream in support of a strong cybersecurity posture.

Lead the Enterprise Security Training & Awareness Program

  • Promote a high level of corporate cybersecurity awareness, including the administration of end-user cybersecurity courses and periodic phishing simulations.
  • Lead the security awareness program through phishing exercises, simulations, and targeted training designed to reinforce secure behaviours across the enterprise.
  • Report on phishing simulation results, highlighting progress, trends, and opportunities to improve secure behaviours.
  • Educate LCBO enterprise on social engineering attacks through printed posters, simulations, in-person roadshows at head-office, warehouses, and regional offices as applicable, and training campaigns.
  • Recognize and celebrate employees who report phishing attempts, while addressing repeat risk through targeted coaching and escalation to the appropriate people leader when required.

About You

  • 5+ years' experience in any combination of cybersecurity or information security, information technology, or IT risk management.
  • Experience conducting security reviews / risk assessments on new and existing technology solutions.
  • Knowledge of security and Risk frameworks such as NIST RMF/CSF, COBIT, ISO 31000/27001, CIS.
  • Knowledge of Cloud environments such as Azure, AWS, and Google
  • Experience implementing and governing cyber controls, policies, and procedures.
  • Experience within the following security domains: GRC, IAM, Security Architecture Governance, Data Protection.
  • Experience with Payment Card Industry (PCI-DSS) compliance.
  • Professional certification such as CRISC, CISA, CISM, CISSP
  • Understanding of relevant Ontario provincial and Canadian Federal information security and information privacy legislation

We offer a comprehensive suite of benefits including:

  • Health/Dental Benefits
  • Access to an Employee & Family Assistance Program
  • a Defined Benefit Pension
  • Discounts on products and services via Workperks.

There is a world of opportunities at the LCBO...

Join an organization where you can be challenged while achieving your true potential. A place where you can make a positive impact supporting Ontario business and communities. Discover a safe, healthy, diverse, inclusive, and accountable workplace where your wellbeing is our top priority. At the LCBO, your contributions are respected and valued. Be part of our journey as we invest in people and technology to transform an organization. There really is a world of opportunities at the LCBO.

We foster a culture of inclusion and belonging, so everyone feels valued, respected, and heard. The LCBO is an equal opportunity employer and committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility of Ontarians with Disabilities Act. If contacted for an interview or employment opportunity, please advise if you require an accommodation.

Please submit your resume via Workday by 11:59pm on the deadline date. We appreciate your interest and advise that only those selected for an interview will be contacted.

Your personal information is being collected under the authority of the Liquor Control Board of Ontario Act, 2019, SO 2019, c 15, Sch 21, Section 3 and in compliance with the Freedom of Information and Protection of Privacy Act for the purpose of processing your job application. When you select "Easy Apply", your personal information will be collected through LinkedIn and shared with the LCBO in accordance with the LinkedIn User Agreement.

If you wish to apply without sharing your personal information with LinkedIn, please visit the LCBO Careers website. If you have any questions regarding the LCBO's collection and use of personal information, please refer to the LCBO Customer Privacy Notice, or contact the Freedom of Information and Privacy Office at:

Freedom of Information and Privacy Office

100 Queens Quay East, 9th Floor

Toronto, Ontario M5E 0C7

Telephone: 416 864-2462

E-mail: foi.privacy@lcbo.com

Work Hours:

36.25

Union / Non-Union:

Non-Union

Job Posting End Date:

September 16, 2026

The LCBO is an equal opportunity employer and committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act.