1

Information Security Manager Jobs in Quebec (NOW HIRING)

Job Summary Reporting directly to the Chief Information Officer (CIO), the Information Security Manager leads the operational execution of the organization's information security program. This role ...

Job Summary Reporting directly to the Chief Information Officer (CIO), the Information Security Manager leads the operational execution of the organization's information security program. This role ...

Reporting directly to the Chief Information Officer (CIO), the Information Security Manager leads the operational execution of the organization's information security program. This role involves ...

$122.10 - $169.80/hr

Information Security Manager, Mergers & Acquisitions The Opportunity Drive Secure Growth Through Strategic Transformation Play a pivotal role in shaping secure business growth as an Information ...

New

Introduce improvements to IT and information security operating methods * Optimize tools within internal technology ecosystem * Act as a lead and reference for level 1 support * Maintain SOC 2 ...

$120 - $150/hr

Your main role will be to support the maturation of the IT risk management and compliance system in order to address the organization's key challenges: implementing a security management system in ...

Cybersecurity Director

Quebec, QC · On-site

$138.90 - $173.60/hr

Manage a team of information security and cybersecurity professionals by providing leadership, coaching, support, and fostering a culture of security awareness. Ensure the team has the necessary ...

next page

Showing results 1-20

Information Security Manager information

What are some common challenges Information Security Managers face when implementing new security protocols within an organization?

Information Security Managers often encounter resistance to change from staff when introducing new security protocols, as these measures can sometimes disrupt established workflows. Balancing security requirements with business needs is also a frequent challenge, requiring negotiation and effective communication across departments. Additionally, staying ahead of constantly evolving threats and ensuring that all team members are properly trained can be demanding, but overcoming these challenges is crucial for maintaining a robust security posture.

What are the key skills and qualifications needed to thrive as an Information Security Manager, and why are they important?

To thrive as an Information Security Manager, you need a strong understanding of cybersecurity principles, risk management, and regulatory compliance, typically backed by a relevant degree and professional certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) systems, vulnerability assessment tools, and incident response frameworks is essential. Leadership, strategic thinking, and excellent communication skills help you effectively manage teams and convey complex security concepts to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring regulatory compliance, and maintaining business continuity.

What is the difference between Information Security Manager vs Security Analyst?

AspectInformation Security ManagerSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with dedicated security teams across industriesCommon in IT departments, security operations centers

The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.

What does an Information Security Manager do?

An Information Security Manager is responsible for overseeing an organization's information security program, ensuring that sensitive data is protected from threats such as cyberattacks and unauthorized access. They develop and implement security policies, conduct risk assessments, and manage teams to respond to security incidents. Information Security Managers also ensure compliance with relevant laws and regulations and regularly educate staff on best security practices. Their role is critical in maintaining the confidentiality, integrity, and availability of information assets.

What Is an Information Security Manager?

The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

What are popular job titles related to Information Security Manager jobs in Quebec? For Information Security Manager jobs in Quebec, the most frequently searched job titles are:
What cities in Quebec are hiring for Information Security Manager jobs? Cities in Quebec with the most Information Security Manager job openings:
Infographic showing various Information Security Manager job openings in Quebec as of July 2026, with employment types broken down into 1% As Needed, 75% Full Time, 21% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

Information Security Manager

Optel Group

Quebec, QC • On-site

$90 - $120/hr

Other

Posted 13 days ago


Job description

Job Summary

Reporting directly to the Chief Information Officer (CIO), the Information Security Manager leads the operational execution of the organization's information security program. This role involves managing security functions, implementing strategy, overseeing technologies, and leading Governance, Risk Management, and Compliance (GRC) activities, with a strong focus on cloud/SaaS environments. The role demands close collaboration with IT, Development, Sales, Legal, Compliance, and other core business functions. It requires the ability to represent the company's security posture effectively to external/internal clients and auditors. This individual serves as the primary operational leader for security, advising the CIO, driving initiatives, and acting as a key security liaison both internally and externally.

Key Responsibilities
  1. Security Operations & Program Management
    • Lead and manage core security functions (SecOps, Vulnerability Management, Incident Response).
    • Drive key security programs (Security Awareness, DLP, IAM).
    • Oversee administration and optimization of security tools (SIEM, EDR, DLP, etc.).
  2. Governance, Risk Management & Compliance (GRC)
    • Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management.
    • Manage the information security risk register, conduct regular risk assessments (incl. SaaS/cloud), propose mitigations, and track remediation.
    • Ensure compliance with relevant laws, regulations (e.g., CERT‑In directives, DPDP Act), standards (ISO 27001, SOC 2, etc.), and contractual obligations.
    • Lead security audit preparation (internal/external) and manage responses/remediation efforts.
    • Develop, implement, socialize, and enforce information security policies and standards.
  3. SaaS & Cloud Security
    • Develop, implement, and manage security controls, configurations, and processes for SaaS applications.
    • Conduct security and risk assessments for new and existing SaaS solutions.
    • Provide security guidance for the adoption and secure configuration of SaaS applications.
  4. Collaboration & Engagement
    • Cross‑Functional Partnership: Foster strong working relationships across departments, including IT (infrastructure, applications, firewall team), Development, Sales, Legal, Compliance, and other core business functions to integrate security practices effectively.
    • Development Collaboration: Work closely with development teams on Secure SDLC practices (secure coding, threat modeling, AppSec testing).
    • Sales Partnership: Provide security expertise to Sales during the sales cycle.
    • Client‑Facing Security: Represent the company's security posture externally, responding to client questionnaires (RFIs/RFPs) and participating in security discussions.
  5. Strategy Execution & Advisory
    • Support the CIO in developing and refining the security strategy.
    • Translate strategy into actionable plans and lead execution, particularly around GRC and operations.
    • Act as the primary security advisor to the CIO on operational security, GRC status, risk posture, and cloud/SaaS security.
    • Prepare security reports, metrics (including GRC metrics), and briefings for the CIO.
  6. Incident Response & Leadership
    • Lead security incident response coordination.
    • Provide technical leadership on security architecture and secure configurations.
    • Manage security vendor relationships and provide input/manage the security budget.
    • Lead and mentor any direct or indirect security team members.
Required Qualifications
  • Experience: 8‑10+ years of progressive experience in Information Security across multiple domains.
  • GRC Expertise: Strong understanding and practical experience with Governance, Risk Management, and Compliance (GRC) principles and frameworks (e.g., implementing controls based on NIST/ISO, managing risk registers, policy lifecycle management, supporting audits such as SOC 2 or ISO 27001).
  • SaaS Security Expertise: Demonstrated experience in securing SaaS applications (controls, configuration, risk assessment). Understanding of identity federation.
  • Collaboration Skills: Proven ability to collaborate effectively with technical (Development, IT) and business/support functions (Sales, Legal, Compliance). Experience with DevSecOps principles desirable.
  • Client‑Facing Communication: Excellent client‑facing communication, presentation, and interpersonal skills. Ability to represent security posture confidently externally.
  • Business Acumen: Ability to understand business processes and translate technical security concepts into business/risk terms.
  • Leadership: Proven experience leading security operations, projects, or teams.
  • Technical Expertise: Deep understanding of core security principles, technologies, frameworks. Broad knowledge of cloud security, endpoint security, IAM, SIEM, vulnerability management, network security concepts.
  • Risk Management: Solid experience with security risk assessment methodologies.
  • Execution Focus: Demonstrated ability to manage security operations and GRC processes effectively.
  • Education: Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience.
Preferred Qualifications
  • Master’s degree in Cybersecurity or related field.
  • Certifications: CISSP, CISM, CRISC, CISA.
  • Experience completing industry‑standard security questionnaires (e.g., SIG, CAIQ VSAQ).
  • Experience reporting directly to senior leadership.
  • Experience managing security vendors.
  • Knowledge of specific Indian, European and American data protection laws and cybersecurity regulations.
#J-18808-Ljbffr