1

Cyber Security Risk Management Jobs in Ontario (NOW HIRING)

Lead internal and external technology risk, cybersecurity, and ITGC audits, including stakeholder coordination, assurance requests, response management, and deliverable quality review. * Drive ...

... Risk Management (IRM). This role will provide technical and functional leadership to ensure scalable, secure, and sustainable solutions that align with enterprise governance, cybersecurity, risk, and ...

Cybersecurity Risk Assessment and Mitigation * Threat Intelligence and Trend Analysis * Analytical Thinking and Structured Problem Solving * Investigation and Case Management * Clear Written and ...

Showing results 21-40

Cyber Security Risk Management information

See Ontario salary details

$28K

$118K

$171K

How much do cyber security risk management jobs pay per year?

As of Aug 18, 2026, the average yearly pay for cyber security risk management in Ontario is $118,029.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,500.00 and $140,500.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Ontario?

For Cyber Security Risk Management jobs in Ontario, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Ontario look for?

The top searched job categories for Cyber Security Risk Management jobs in Ontario are:

What cities in Ontario are hiring for Cyber Security Risk Management jobs?

Cities in Ontario with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 20% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $118,029 per year, or $56.7 per hour.

CA$101K - CA$130K/yr

Full-time

Posted 7 days ago


Job description

51721 - Toronto - Regular Not Applicable/Optional

Hiring Salary Range: $101,150.00-130,900.00 / year

Hydro One is proud to be the largest electricity transmission and distribution provider in Ontario, serving nearly  1.5 million customers. We have a long history in the industry with our roots dating back over 110 years to 1906. Since then, we have worked to grow and evolve to meet the changing needs of our customers and communities across Ontario. Today, we’re focused on providing exceptional customer service and ensuring we are building safe communities where we live, work and play.

It’s an exciting time to join the team at Hydro One!

Job Function:

The Senior Cybersecurity Specialist, GRC Risk Management is a senior advisor responsible for cyber risk management across IT, OT, cloud, AI, and emerging technologies. The role partners with business, technology, compliance, and security architecture stakeholders to identify, assess, and manage cybersecurity risks, ensure regulatory and security compliance, and provide risk-based guidance for technology initiatives and architecture decisions.

Key responsibilities include leading cyber risk assessments, governance and compliance activities, security architecture reviews, control testing, risk treatment planning, identity governance, and executive reporting. A key focus of the role is leveraging security engineering and automation solutions to modernize GRC processes, streamline evidence collection and reporting, improve cyber risk visibility, and enhance operations. The role supports compliance with OEB, NERC-CIP, and other cybersecurity frameworks while delivering actionable risk insights that enable business and executive decision-making.

Job Description

The Senior IT Security Specialist will work within the OT Cybersecurity Technology & Operations team as a Defender Of Energy, protecting Hydro One Networks against Cyber Attacks and proactively assessing existing cybersecurity controls & cyber defenses.

Join a diverse team of experienced Cybersecurity practitioners, and act as a subject matter expert for Information Security with the Lines of Business (LOB)

  • Focus on Cyber Risk Management as it relates to Information Technology (IT) and Operations Technology (OT) systems
  • Translate technical cyber & information security requirements into business actions. Preserve and apply the security governance framework (based on NIST) for the LOBs.
  • Work with different, potentially conflicting requirements (legal, regulatory, industry standards, security strategy) to distil realistic security requirements supporting the business strategy
  • Conduct research to maintain and expand knowledge on the latest cyber security technologies and standards, as well as the threat and vulnerability landscape for Industrial Control Systems (ICS) in general, and the Electrical sector in Ontario

You are an experienced Cyber Risk Management professional with extensive knowledge and experience in architecture of the following domains and their application to IT (and preferably OT) environments:

  • Identity and Access Management
  • Threat, Risk and Compliance
  • Vulnerability Management
  • Security Operations
  • Security Governance and Policies
  • Security Architecture

Specific Accountabilities may include:

  • Represent the Cyber Risk Management team as an advisor and expert Cyber Security SME to support the overall security program.
  • Seek industry trends and organizational knowledge to understand and implement effective risk management practices.
  • Provide recommendations for security architecture for all technology projects, new platforms – on premise or cloud-based and ensure alignment of technology solutions to established frameworks and security standards.
  • Provide consultation to operational teams as a risk-focused senior cyber security advisor on security-related initiatives, solution selection, security architecture and security assessments
  • Provide risk management insights through an ongoing process of gathering, analyzing and prioritizing actionable risk messages; develop content to support communication of the messages and enable technology teams to consume and apply the messages to their respective areas.
  • Contribute to the continuous improvement of processes and maturity of cyber risk management program.
  • Manage various stakeholders across levels (including executives) and engage in resolution of risk issues.
  • Build and manage effective relationships with key stakeholders, team members, and other business, functional and support groups. Collaborate with senior leaders to ensure alignment of Cyber Security initiatives.
  • Support responses to various regulatory requests and audits
  • Support the compliance sustainment and continuous improvement efforts associated with Hydro One’s NERC CIP compliance program.  Review NERC CIP related security incidents for systemic problems and opportunities for process improvements.

Requisite Experience and Skills:

  • Extensive experience of strategic development of standards, Cyber Security Risk Identification and Mitigation techniques
  • Demonstrable experience in an advisor/consultant capacity representing Information Security
  • 10+ years of information security experience in risk management and information security
  • Strong knowledge of NIST SP800-53 and NIST Cyber Security Framework
  • Sound understanding of the Ontario Cyber Security Framework
  • Familiarity with Risk Management Frameworks (ISO 27005, NIST 800-30/39 or ISF IRAM2 )
  • Demonstrated understanding of relevant standards and regulatory requirements (NERC CIP, Bill C-198, PCI, PIPEDA, etc.).
  • Familiarity with scenario-based risk analysis using common threat modelling techniques
  • Knowledge of current trends in the cyber security industry
  • Knowledge of unique threats to the energy sector and its role within Canadian critical infrastructure
  • Excellent interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management
  • Excellent organization/project planning, time and organizational change skills across multiple functional groups and departments
  • Knowledge of metrics programs and security dashboard creation
  • Post-secondary education in Computer Science or related field, or equivalent work experience
  • One or more of CISSP, CRISC, CISM or other relevant certifications would be an asset


At Hydro One we understand that the success and strength of our business rests with our people. When we develop their skills, we are investing in both their success and ours. To secure the best talent, we seek to create a workforce that reflects the diverse populations of the communities where we live and work and to create a culture based on safety, innovation and inclusiveness.

We are honoured to be recognized by Forbes in its list of Canada’s Best Employers for 2026.

Thank you for considering a career with Hydro One, we welcome applications from all qualified candidates. If you are having difficulty using our online application system and you need an accommodation due to a disability, please email careers@hydroone.com. Hydro One will provide reasonable accommodation for qualified individuals with disabilities in the job application process.

Please note this email is only for accommodation requests. Resumes sent to this email address will not be considered.

"Employer of the year 2026"

Deadline: August 24, 2026 

The base salary for this role considers a variety of factors, including candidates' knowledge, skills, experience, education, and any applicable collective agreement requirements for union-represented positions. Hydro One provides an extensive offering of programs to promote a culture of safety, wellbeing, inclusivity, and sustainability to enable our employees to be the best version of themselves. For management roles, compensation is based on the principle of pay-for performance compensation philosophy, and the amount of annual adjustments and incentive payments depends on how well you and the company perform (subject to plan terms). We encourage open dialogue about compensation with our Talent Acquisition Team, who can provide more detailed information specific to this role.

This posting is for an existing vacancy. 

Hydro One uses AI tools to assist in the screening and assessing candidates for this role. Our use of AI does not replace human decision-making.

In the event you are experiencing difficulties applying to this job please consult our help page here.

We thank all applicants for their interest in a career at Hydro One; however, only those candidates who are selected for an interview will be contacted.