Manager, IT, GRC and Security

4 days ago

Toronto, ON, Canada Canadian Standards Association Full-time €116,000 - €153,000/year
Employment Status: Regular Time Type: Full time BUILDING A WORLD CLASS TEAM STARTS WITH YOU At the heart of CSA Group is a vision: making the world a better, safer, more sustainable place. It's been part of our mission for nearly one hundred years: from the first engineering standard for railway bridges developed in 1919, to more than 3,500 standards, codes & related products today. Headquartered in Canada, with a global footprint of more than 30 labs and offices across Europe, Asia and North America, CSA Group tests, inspects and certifies a wide range of products
- from every day househould items to leading edge technology-to meet exacting requirements for safety, performance and environmental impact. Our employees take pride in making a difference in people's lives through the work that we do. We're looking for people like you to help make it happen. Job Summary CSA Group has an immediate opportunity for a Manager, IT Governance, Risk & Compliance to lead the development, delivery, and continuous improvement of CSA Group's technology governance, risk and compliance framework, and the assurance and resilience activities that evidence its effectiveness. This role owns the technology policy, standard, procedure, and control framework; leads technology and cybersecurity risk assessment, treatment, and reporting; oversees compliance with internal policies, contractual obligations, customer requirements, and applicable regulatory and privacy requirements; and coordinates internal and external audits through to remediation of findings. The role also leads security assurance and third-party risk activities, governs the enterprise disaster recovery and technology resilience program, and ensures cybersecurity incident response plans and escalation paths are documented, tested, and understood. While technology delivery teams design, build, and operate security controls day-to-day, this role defines the control requirements those teams must meet, independently validates that controls are implemented and operating effectively, tracks remediation to closure, and reports residual risk to the IT Leadership Team and executive leadership. Responsibilities Leads the enterprise IT governance and compliance program, and develops, maintains, and periodically reviews technology policies, standards, procedures, and control frameworks aligned to recognized frameworks and CSA's risk appetite. Maintains the control library, mapping controls to policy, framework, contractual, customer, and regulatory obligations to avoid duplicate testing, and validates through assurance activity that controls are implemented and operating effectively. Facilitates technology and cybersecurity risk assessments across the technology estate, projects, and third parties, and maintains the risk register, ensuring mitigation and remediation plans are tracked to closure. Operates the risk acceptance and control exception process, and provides risk input into project charters, architecture decisions, change management, and technology investment decisions. Oversees compliance with internal policies, contractual obligations, customer requirements, and regulatory and privacy requirements, and plans and executes IT self-assessments and control testing. Coordinates internal and external audits and certification or attestation activity, including scoping, evidence collection, management responses, and remediation of findings, and maintains the compliance calendar and evidence repository. Oversees security assessments of applications, systems, cloud services, and vendors, and leads the penetration testing and security assurance program, including provider selection, finding triage, and retest verification. Leads third-party and supply chain security risk management, including due diligence, criticality tiering, ongoing monitoring, and secure offboarding. Manages customer security questionnaires, due diligence requests, and customer-led audits, and reviews customer and vendor contracts for alignment with IT policies and the governance framework. Governs the enterprise disaster recovery and technology resilience program, ensures plans and RTO/RPO objectives are established and validated through testing, and reports on status and gaps to ITLT and executive leadership. Ensures cybersecurity incident response plans, playbooks, and escalation paths are documented, exercised, and understood, and coordinates governance, reporting, and post-incident corrective action for significant incidents. Governs the reporting and remediation performance of vulnerability management, security monitoring, and threat management activities performed by delivery teams. Builds organizational cybersecurity awareness and owns the security awareness and training program, including phishing simulation and role-based training. Establishes priorities, delivery plans, and performance expectations for the governance, risk, compliance, and assurance program, and directs assigned resources and