1

Information Security Manager Jobs in Quebec (NOW HIRING)

About the team you are joining You will be joining the Information Security team within the Information & Data (I&D) Division, reporting to the Manager Aviation Information Security under the Head ...

Cybersecurity Director

Quebec, QC · On-site +1

CA$138K - CA$173K/yr

Manage a team of information security and cybersecurity professionals by providing leadership, coaching, support, and fostering a culture of security awareness. Ensure the team has the necessary ...

CA$70 - CA$75/hr

... management, encryption, traceability, and secure logging * Ensure the security of internally ... The official title "Expert IT Security Developer" is broader than the actual role, which is ...

Develop and champion information security architecture roadmaps aligned with industry-leading ... Additional Information: Position Type: Management Job Status: Regular - Full Time Job Location:

... secret management, encryption, traceability, and secure logging \n * Ensure the security of ... The official title "Expert IT Security Developer" is broader than the actual role, which is ...

Resolve conflicts in collaboration with management; * Control access to the premises, including ... Additional Information We thank all applicants for their interest; however, only those whose ...

next page

Showing results 1-20

Information Security Manager information

What is an information security manager?

The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

What does an information security manager do?

An Information Security Manager is responsible for overseeing an organization's information security program, ensuring that sensitive data is protected from threats such as cyberattacks and unauthorized access. They develop and implement security policies, conduct risk assessments, and manage teams to respond to security incidents. Information Security Managers also ensure compliance with relevant laws and regulations and regularly educate staff on best security practices. Their role is critical in maintaining the confidentiality, integrity, and availability of information assets.

What are some common challenges information security managers face when implementing new security protocols within an organization?

Information Security Managers often encounter resistance to change from staff when introducing new security protocols, as these measures can sometimes disrupt established workflows. Balancing security requirements with business needs is also a frequent challenge, requiring negotiation and effective communication across departments. Additionally, staying ahead of constantly evolving threats and ensuring that all team members are properly trained can be demanding, but overcoming these challenges is crucial for maintaining a robust security posture.

What is the difference between Information Security Manager vs Security Analyst?

AspectInformation Security ManagerSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with dedicated security teams across industriesCommon in IT departments, security operations centers

The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What are popular job titles related to Information Security Manager jobs in Quebec?

For Information Security Manager jobs in Quebec, the most frequently searched job titles are:

What job categories do people searching Information Security Manager jobs in Quebec look for?

The top searched job categories for Information Security Manager jobs in Quebec are:

What cities in Quebec are hiring for Information Security Manager jobs?

Cities in Quebec with the most Information Security Manager job openings:

Infographic showing various Information Security Manager job openings in Quebec as of August 2026, with employment types broken down into 100% Full Time. Highlights an 71% In-person, and 29% Remote job distribution.

Information Security Officer

Societe Generale

Montreal, QC • On-site

Full-time

Re-posted 16 days ago


Job description

The Vulnerability Management Lead is responsible for the AMER region's vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of running an effective vulnerability & / or configuration management program including dynamically responding to emerging threats in the financial services industry.

The role also calls for strong technical analysis and process improvement skills and the ability to present to senior management on the state of, and proposals to improve, the program.

Working knowledge of cybersecurity and risk assessment frameworks (e.g., NIST) and regulations applicable to the financial services industry (e.g., NYDFS 500, FINRA, SEC) is preferred.

The Vulnerability Management Lead is a member of the Cyber Threat Defense (CTD) team within the AMER Data and Cyber Security (ISR) department and reports to the Director of CTD. This position requires strong collaboration across GBSU and GTS departments in the Americas and globally with SG CERT, ISR and GTS teams.

ESSENTIAL JOB FUNCTIONS

Vulnerability & Configuration Management

  • Lead the AMER vulnerability & configuration management programs - Act as the main point of contact and expert in Vulnerability Management and configuration management; including overseeing the risk of zero-day vulnerabilities, oversee patching/remediation and risk acceptance of vulnerabilities where appropriate.

  • Oversee the discovery, evaluation, and implementation of vulnerability scanning, patch and configuration review, penetration testing.

  • Present operating and steering committees for projects to senior management on a quarterly basis.

  • Develop and oversee annual roadmaps of initiatives to align with overall InfoSec and business objectives/strategy.

  • Develop and manage detailed vulnerability reviews and assessments, and patching and configuration reviews: (1) Assess potential damage of security flaws and assist in the implementation of corrective actions; (2) Identify, document, and report security issues and concerns to management; and (3) Monitor corrective actions and recommending cost-effective preventive measures to preclude recurrences.

  • Review and sign-off on all recommendations on possible improvements resulting from the work performed as part of projects.

  • Draft and publish communications for management as new threats emerge.

  • Improve the reporting framework that will provide regular metrics and statistics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing shortages, etc.; report security metrics and statistics to the CISO and other key stakeholders such as the COO, CIO, and CTO.

LANGUAGE: 

Ability to communicate in English, both orally and in writing, is a requirement as the person in this position will need to collaborate regularly with colleagues and partners in the United States. 

KNOWLEDGE AND EXPERIENCE

       5-10 years related information security experience, in particular hands-on experience in vulnerability management.

       Excellent communications skills, both verbal and written. Comfortable presenting to all levels from technical to senior (C-level).

  • Proficiency with MS Office suite of productivity tools is required.
  • Strong analytical, problem solving, and process improvement skills are required.
  • Experience with Qualys, Windows Defender or equivalent tools to manage vulnerabilities, patching and configurations if preferred.
  • Solid understanding of common security best practices and risk assessment is preferred.

EDUCATION/CERTIFICATIONS

  • Bachelor's degree or equivalent business experience in Cybersecurity, Computer Science, or Business Management is required.
  • CISSP, CCSP, CISM, GSEC, CEH, or related security certification(s) is highly preferred.