1

Cybersecurity Manager Jobs in Ontario (NOW HIRING)

A career within our Cyber Security practice will provide you with the opportunity to help our ... What you will do As a Manager you'll work as part of a team of problem solvers with extensive ...

Design and/or evaluate Cybersecurity Management Systems * Develop Cybersecurity policies, guidelines and procedures * Elaborate Risk assessment methodologies and apply these methodologies within ...

Architect - Cybersecurity Location: Krakow, Poland Type: Full-time employment Working Hours: Monday ... Continually communicate to project managers and owner * Participate in meetings and provide ...

Architect - Cybersecurity Location: Krakow, Poland (Hybrid) Type: Full-time employment Hybrid work ... Continually communicate to project managers and owner * Participate in meetings and provide ...

We are looking for a hands-on and strategic Cyber Security Engineer to join our Cyber Security team on a full-time, permanent basis, reporting to the Cyber Engineering Manager. In this role, you will ...

Cybersecurity Engineer

Toronto, ON · On-site

CA$80K - CA$105K/yr

A Mission We're looking for a skilled Cybersecurity Engineer to design and implement robust ... Proficiency in network security, encryption, and vulnerability management tools. * Experience with ...

A Mission We're looking for a skilled Cybersecurity Engineer to design and implement robust ... Proficiency in network security, encryption, and vulnerability management tools. * Experience with ...

Showing results 21-40

Cybersecurity Manager information

See Ontario salary details

$85.5K

$151.5K

$217.5K

How much do cybersecurity manager jobs pay per year?

As of Sep 6, 2026, the average yearly pay for cybersecurity manager in Ontario is $151,503.00, according to ZipRecruiter salary data. Most workers in this role earn between $122,500.00 and $168,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a cybersecurity manager?

To thrive as a Cybersecurity Manager, you need a deep understanding of information security principles, risk management, and network security, usually backed by a degree in computer science or a related field. Familiarity with security frameworks (such as NIST or ISO 27001), incident response tools, and certifications like CISSP or CISM is highly valued. Strong leadership, analytical thinking, and effective communication skills enable you to manage teams and convey complex threats to stakeholders. These skills are essential to protect organizational assets, ensure regulatory compliance, and respond swiftly to evolving cyber threats.

What are some of the main challenges cybersecurity managers face when leading a security team?

Cybersecurity Managers often encounter challenges such as balancing proactive threat mitigation with responding to real-time incidents, managing a diverse team with varying skill levels, and staying updated on rapidly evolving cyber threats. They must also effectively communicate risks and security needs to non-technical stakeholders and ensure compliance with industry regulations. Building collaboration between IT, development teams, and executive leadership is essential to create a unified security strategy.

What is the difference between Cybersecurity Manager vs Security Analyst?

AspectCybersecurity ManagerSecurity Analyst
CertificationsCISSP, CISM, CompTIA Security+CompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security teams, strategic planningMonitors security systems, analyzes threats
Employer & Industry UsageUsed in organizations with dedicated security teamsCommon in security operations centers (SOCs)

The main difference is that a Cybersecurity Manager focuses on managing security teams and developing security strategies, while a Security Analyst primarily monitors systems and responds to security incidents. Both roles require similar certifications but differ in responsibilities and scope within the cybersecurity field.

How much do cybersecurity managers earn?

Cybersecurity managers typically earn a median annual salary ranging from $100,000 to $150,000, depending on experience, certifications, and location. They often oversee security teams, implement security protocols, and use tools like firewalls and intrusion detection systems, with higher salaries for those with advanced certifications such as CISSP or CISM.

What does a cybersecurity manager do?

A cybersecurity manager oversees an organization’s security strategy, manages security teams, and implements policies to protect information systems from cyber threats. They analyze security risks, coordinate incident response, and often use tools like firewalls and intrusion detection systems, typically requiring certifications such as CISSP or CISM. Their role involves ensuring compliance with security standards and continuously improving security measures.

What are the most commonly searched types of Cybersecurity jobs in Ontario?

The most popular types of Cybersecurity jobs in Ontario are:

What are popular job titles related to Cybersecurity Manager jobs in Ontario?

For Cybersecurity Manager jobs in Ontario, the most frequently searched job titles are:

What cities in Ontario are hiring for Cybersecurity Manager jobs?

Cities in Ontario with the most Cybersecurity Manager job openings:

Infographic showing various Cybersecurity Manager job openings in Ontario as of August 2026, with employment types broken down into 80% Full Time, 19% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $151,503 per year, or $72.8 per hour.

Manager, Cyber Defence

KPMG

Toronto, ON

Full-time

Re-posted 11 days ago


Key responsibilities

  • Support and execute incident response projects, including operating system, cloud, network security, malware analysis, and digital forensics activities.

  • Perform digital forensic evidence collection, analysis, and investigation to identify indicators of compromise, root causes, attack vectors, and threat actors.

  • Create technical reports and provide recommendations to mitigate current attacks, remediate vulnerabilities, and improve client cybersecurity posture.


Job description

Overview

At KPMG in Canada, our people bring their unique perspectives to Canada’s most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference.

Are you a talented individual with a proven track record on executing project deliverables.  

Our Toronto team is looking for a highly motivated Cyber Security professional at a Manager level to join our team! As a member of KPMG Canada’s cross-functional Cyber team, you will be dedicated to the defense and protection of our client critical data, systems, and assets through cyber defense and incident response services.

A career within our Cyber Security practice will provide you with the opportunity to help our clients implement robust cybersecurity programs that protects against threats, propels digital and business transformation, and drives growth. As companies pivot toward a digital business model, exponentially more data is generated and shared among organizations, partners and customers. We play an integral role in helping our clients ensure they are protected by developing transformation strategies focused on security, efficiently integrate and manage new or existing technology systems to deliver continuous operational improvements and increase their cybersecurity investment, and detect, respond, and remediate threats.
KPMG’s Cyber team has received tremendous investment and has been identified as a transformational part of the firm to deliver growth over the next five years. This is an excellent opportunity for those that are looking to stay ahead of the curve and work in a firm with unparalleled career progression opportunities. 


What you will do

As a Manager you’ll work as part of a team of problem solvers with extensive consulting and industry experience, supporting our technical engagement team and leveraging your expertise on Incident Response projects and tasks. Specific responsibilities include but are not limited to:

  • Engage with a variety of clients on incident response engagements ranging and tasks from operating system security, cloud and network security, cryptography, software security, malware analysis, digital forensics for incident response activities, security operations, and emergent security intelligence;
  • Perform incident response and cyber investigations. These engagements will require urgent organization, configuring needed toolsets, and communication with the client;
  • Leverage forensic tools to on incident response collect, process and analyze computer based evidence (host and network based). Use end-point detection and response (EDR) tools to investigate, monitor and triage potentially compromised end-points;
  • Perform digital forensic evidence collection throughout the incident response phases, extensive log analysis and meta-data analysis;
  • Perform operating system and hard drive digital forensic evidence analysis;
  • Analyze results from tools and determine: indicators of compromise (IOCs), root cause of compromise, possible attack vectors, potential threat actors and the overall risk/threat the client is facing;
  • Provide recommendations and advise on steps to mitigate the current attack, present risks and remediate the potentially vulnerable environment and remove the ability of ongoing/future attacks;
  • Analyze results of assessment and create technical accurate and articulate reports in a business professional language, to be shared with technical stakeholder, executive stakeholders and potentially third parties;
  • Leverage out-of-the-box thinking to tackle and overcome complex client challenges;
  • Remain current on the threat landscape, including common and recent threats. Keep your team and clients informed on relevant threat and attack vectors on an on-going basis;
  • Contribute to the KPMG Incident Response team’s practice development by actively supporting a Cyber/Forensics lab, writing whitepapers, conducting and sharing research, actively assisting with business development opportunities.

What you bring to the role
  • Undergraduate degree in Computer Science, Information Technology, or related field;
  • Completion of at least one relevant certification such as GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Examiner (GCFE), EnCase Certified Examiner (EnCE), CCFP ISC(2) or similar;
  • 5+ years of experience with incident response, preferably in a consulting environment. Internal CSIRT experience will also be considered;
  • 5+ years of experience with forensic data collection with technical network, hard drive, and operating systems. Candidates should also have experience with collecting data from cloud platforms for investigations that involve SaaS and PaaS;
  • Experience working on consulting incident response engagements with clients, including post-incident reviews;
  • Cyber investigation and threat hunting experience;
  • Ability to identify and create IOCs (Indicators of Compromise) from performing forensic analysis activities, articulate IOC in technical formats, and present them to stakeholders;
  • Hands-on experience and working knowledge of at least one common industry leading or open-source forensic software application (e.g. EnCase, FTK, Autopsy, Magnet Axiom, Cellebrite, Magnet IEF/Axiom) and techniques to capture and process electronic data from computers, virtual machines, external media, networks and mobile data devices;
  • Hands on experience with the installation and configuration of End-Point Detection and Response tools, such as Carbon Black, Sentinel One, CrowdStrike Falcon or Elastic Stack;
  • Strong knowledge of common attack vectors, initial compromise, lateral movement, privilege escalation and data exfiltration techniques;
  • Knowledge of operating systems, networking, web protocol, and cloud architecture;
  • Ability to perform log, host and network-based traffic monitoring and analysis, across varying devices, platforms and formats;
  • Ability to perform hard drive digital forensics within the incident response phases, across various file and device formats, including Windows and Linux operating systems and mobile device.
  • Ability to fulfill regular on-call responsibilities, as part of a team, for urgent incident response activities.
  • Master's Degree within a specialization in Cyber Security, Digital Forensics or a related field is advantageous;
  • Completion of any additional Cyber Security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) or similar would be advantageous.;
  • Hands-on experience incident response and log analytics tools, such as Elastic, Log Stash and Kibana, Sumo Logic, Splunk, etc. Familiarity with multiple open-source tools for data and log analysis;
  • Reverse engineering experience on various types of malware, including ransomware, malicious droppers, trojans, customized and obfuscated malicious scripts and other types of malicious files will be advantageous;
  • Experience with forensic evidence handling and chain-of-custody procedures and knowledge of potential litigation requirements;
  • Experience with programming languages (C, C#) and scripting languages (e.g. Python and Go) and familiar with Bash and PowerShell;
  • Experience in other technical Cyber Security domains, such as Penetration Testing, Red Teaming, Security Operation Centre (SOC) or Blue Teaming;
  • Able to create solutions and modify your tools, plugins and scripts appropriately to problem at hand;
  • Knowledge of common threat actor TTPs (tools, techniques and procedures and how they relate to the stages of the MITRE ATT&CK® Framework.

KPMG Ontario Region Pay Range Information

The expected base salary range for this position is $110,000  to $160,000 and may be eligible for bonus awards. The determination of an applicant’s base salary within this range is based on the individual’s location, skills & competencies, and unique qualifications. In addition, KPMG offers a comprehensive and competitive Total Rewards program.

Providing you with the support you need to be at your best


Our Values, The KPMG Way

Integrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

Adjustments and accommodations throughout the recruitment process

At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG’s Employee Relations Service team by calling 1-888-466-4778.

AI Usage

Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG’s Trusted AI framework.

We believe technology should empower human judgment, not replace it. It’s one of the many ways we’re delivering on our vision of being a technology-first, people-driven firm.

Qualifications:
  • Undergraduate degree in Computer Science, Information Technology, or related field;
  • Completion of at least one relevant certification such as GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Examiner (GCFE), EnCase Certified Examiner (EnCE), CCFP ISC(2) or similar;
  • 5+ years of experience with incident response, preferably in a consulting environment. Internal CSIRT experience will also be considered;
  • 5+ years of experience with forensic data collection with technical network, hard drive, and operating systems. Candidates should also have experience with collecting data from cloud platforms for investigations that involve SaaS and PaaS;
  • Experience working on consulting incident response engagements with clients, including post-incident reviews;
  • Cyber investigation and threat hunting experience;
  • Ability to identify and create IOCs (Indicators of Compromise) from performing forensic analysis activities, articulate IOC in technical formats, and present them to stakeholders;
  • Hands-on experience and working knowledge of at least one common industry leading or open-source forensic software application (e.g. EnCase, FTK, Autopsy, Magnet Axiom, Cellebrite, Magnet IEF/Axiom) and techniques to capture and process electronic data from computers, virtual machines, external media, networks and mobile data devices;
  • Hands on experience with the installation and configuration of End-Point Detection and Response tools, such as Carbon Black, Sentinel One, CrowdStrike Falcon or Elastic Stack;
  • Strong knowledge of common attack vectors, initial compromise, lateral movement, privilege escalation and data exfiltration techniques;
  • Knowledge of operating systems, networking, web protocol, and cloud architecture;
  • Ability to perform log, host and network-based traffic monitoring and analysis, across varying devices, platforms and formats;
  • Ability to perform hard drive digital forensics within the incident response phases, across various file and device formats, including Windows and Linux operating systems and mobile device.
  • Ability to fulfill regular on-call responsibilities, as part of a team, for urgent incident response activities.
  • Master's Degree within a specialization in Cyber Security, Digital Forensics or a related field is advantageous;
  • Completion of any additional Cyber Security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) or similar would be advantageous.;
  • Hands-on experience incident response and log analytics tools, such as Elastic, Log Stash and Kibana, Sumo Logic, Splunk, etc. Familiarity with multiple open-source tools for data and log analysis;
  • Reverse engineering experience on various types of malware, including ransomware, malicious droppers, trojans, customized and obfuscated malicious scripts and other types of malicious files will be advantageous;
  • Experience with forensic evidence handling and chain-of-custody procedures and knowledge of potential litigation requirements;
  • Experience with programming languages (C, C#) and scripting languages (e.g. Python and Go) and familiar with Bash and PowerShell;
  • Experience in other technical Cyber Security domains, such as Penetration Testing, Red Teaming, Security Operation Centre (SOC) or Blue Teaming;
  • Able to create solutions and modify your tools, plugins and scripts appropriately to problem at hand;
  • Knowledge of common threat actor TTPs (tools, techniques and procedures and how ...