Senior Manager, Cybersecurity Operations

2 weeks ago


Montréal, Canada CMHC Full time

Job Requisition ID: 10747 Position Status:  Permanent Full Time  Position Type:  Hybrid  Office Location:  Ottawa (preferred), Montreal (QC) and Toronto (ON) will be considered Travel Requirement:  Occasional  Language Designation:  Bilingual  Language Skill Levels (Read/Write/Speak):  CBC  Security Requirement:  Secret  Salary:  Our salaries generally range from $ 126024.66 to $ 157530.82 and are based on qualifications and experience.  About CMHC The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system. At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration , connecting across CMHC and involving the right people to get our work done. We have  flexibility , in how, when, and where we work, within the boundaries of the business needs and the nature of your role. Our leadership style is guided by trust , where our leaders favour an adaptive approach based on the needs of their teams. Join us and be part of a team that's committed to making a real difference and be part of something meaningful. What’s in it for you We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee: Annual paid vacation. Annual individual performance incentive. Defined benefit pension plan. Comprehensive group insurance plan to support your well-being from day one. Support towards your personal and professional growth with training, mentorship and more.  An inclusive workplace culture and environment. About the role The Senior Manager, Cybersecurity Operations is responsible for ensuring the continuous security of IT operations by managing security tools, conducting vulnerability identification, and providing threat intelligence. This role leads a team of cybersecurity professionals to deliver high-quality operations to protect the organization assets and data and collaborates with other departments to integrate risk management practices and ensure a coordinated response to security incidents. Office Location:  Ottawa (preferred), Montreal (QC) and Toronto (ON) will be considered. What you’ll do:  Manage and supervise day-to-day security operations to safeguard the organization’s data and assets and ensure the effective functioning of security tools and platforms to maintain optimal service delivery including threat detection, incident response, vulnerability management, and continuous monitoring of IT infrastructure. Collaborate with key departments (e.g., IT, legal, compliance, and HR) to ensure risk management practices are integrated into all aspects of the business (proactive threat identification, vulnerability management) and lead the development of effective cybersecurity protocols to guide operations and ensure consistency across security activities.  Provide regular reporting to senior leadership to: highlighting trends, areas of concern, recommendations for continuous improvement, status of cybersecurity compliance efforts, risk management initiatives, and the effectiveness of cross-department collaboration in maintaining a secure and compliant security and IT environment. Ensure the proper configuration of security and cybersecurity tools (e.g., SIEM, firewalls, intrusion detection/prevention systems) to align with organizational security policies and best practices, and continuously optimize their performance for maximum effectiveness and relevant to regulatory requirements and that they remain current and capable of defending against the latest threats, vulnerabilities, and compliance requirements.  Oversee relationships with third-party security tool vendors, ensuring contractual obligations are met, and managing product evaluations, renewals, and escalations related to performance issues or tool enhancements. Direct and oversee regular vulnerability assessments across the organization's IT infrastructure, applications, and cloud environments, identifying potential risks and areas of weakness and collaborating with relevant teams to implement corrective actions where feasible. Establish a risk-based prioritization framework for discovered vulnerabilities, ensure continuous monitoring and automated scanning of systems for vulnerabilities in collaborate with IT infrastructure, application development, and network teams for vulnerabilities to be promptly addressed with effective remediation plans and oversee the validation and verification process post-remediation to ensure vulnerabilities are properly mitigated, and the systems have been securely patched and tested for resilience. Lead incident response efforts, ensuring a swift, coordinated, and effective response to security breaches and incidents ie: to investigate, contain, and remediate security incidents, while minimizing business impact and aligns with both operational and compliance requirements. Ensure that all departments understand their roles in responding to security incidents and mitigating any potential business impact. What you should have: Undergraduate degree in Cyber Security, Computer Security, Information Systems Security, Computer Science or in a related field. An equivalent combination of education and/or experience can be considered. A Professional designation, such as Certified Information Security Manager (CISM). 10 years experience in IT Security and/or in information security working with cybersecurity frameworks, privacy regulations, and industry standards, including data protection laws and principles governing confidentiality, integrity, availability, authentication, and non-repudiation and an expertise in incident framework and methodologies (data breaches, denial of service attacks, insider threats, etc.). 5 years of management experience providing leadership and direction to cybersecurity staff. Advanced proficiency in: identifying and assessing a wide range of cyber threats (e.g., malware, ransomware, insider threats) and vulnerabilities (e.g., software flaws, configuration weaknesses, network security gaps). identifying and remediating application vulnerabilities, including secure software development practices, common vulnerabilities (e.g., OWASP Top 10), and tools for vulnerability scanning and penetration testing to enhance application security and mitigate risks. Advance knowledge of: personally Identifiable Information (PII) data security standards and regulations (e.g., GDPR, CCPA, HIPAA), including best practices for securing sensitive data, ensuring compliance, and implementing effective privacy protections to prevent unauthorized access or breaches. current industry methods for evaluating, implementing, and using security tools for assessment, monitoring, detection, and remediation of security threats. Extensive experience in developing, documenting, and refining cybersecurity processes and procedures that align with operational requirements and ensure consistent, repeatable actions in response to security events, incidents, and audits. how traffic flows across IT networks, including knowledge of TCP/IP, the OSI model, and associated network protocols. Proficient in ITIL frameworks for service management, with the ability to design, implement, and optimize network security controls aligned with operational needs. Strong ability to: identify emerging trends in security operations (analysis of incident data, vulnerability reports, and threat intelligence) combined with extensive experience conducting vulnerability assessments, performing regular scans (using industry-leading tools) and identifying critical vulnerabilities in systems, applications, and networks. communicate (written and verbal) both in English and French combined with the ability to negotiate, influence and challenge various audiences. It would be great if you also had: Certified Information Systems Security Professional (CISSP), GIAC Security Leadership (GSLC), GIAC Critical Controls Certification (GCCC) or other relevant IT Security licence, designation, or certificate. Experience and knowledge of security technologies such as identity management, computer forensics, application security and network security technologies. Experience and/or knowledge of recognized standards. E.g. NIST CSF, ISO 27001/27002, ITSG-33, OSFI B13, CIS, etc. Knowledge of Canadian laws and Government of Canada regulatory requirements and standards. E.g. Treasury Board, Office of the Superintendent of Financial Institutes, etc. Posting closing date:  Note, the competition will remain active until filled. Our commitment to diversity, equity, and inclusion  We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada. CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission. What happens after you apply  We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. . If you are selected for an interview or testing, please advise us if you require an accommodation. If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around



  • Montréal, Canada Chartered Professional Accountants of Canada Full time

    **About Chartered Professional Accountants of Canada** Chartered Professional Accountants of Canada (CPA Canada) works collaboratively with the provincial, territorial and Bermudian CPA bodies, as it represents the Canadian accounting profession, both nationally and internationally. This collaboration allows the Canadian profession to champion best...


  • Montréal, QC HP C, Canada MSP Corp. Full time $120,000 - $180,000 per year

    Advance Your Career in IT. We are hiring on behalf of our client: Manager, IT Operations and CybersecurityLocation: Montreal downtownSchedule: Monday to FridaySalary: Competitive salary with bonusRole Type: Full-timeWork Mode: HybridAt MSP Corp, we don't just build our own teams—we also help our clients build theirs. As a national leader in managed IT...


  • Montréal, QC, Canada American Iron and Metal Full time

    **Company Description** American Iron & Metal (AIM) is a family-owned company and recognized global leader in the metal recycling industry with more than 125 sites and 4000 employees worldwide. We have continued to prosper for the last eight decades thanks to the dedication of our employees and the ongoing trust and support of our customers. Become part of...

  • Cybersecurity Expert

    2 weeks ago


    Montréal, Canada CS GROUP Full time

    Company Description CS Group Canada, a subsidiary of CS Group, is a leader in the development and certification of safety-critical systems in the aerospace, electric and autonomous driving industries. Joining CS Group Canada is a unique opportunity to work on complex high-tech systems for the most prestigious system manufacturers in North America, and our...


  • Montréal, Canada Cogeco Communications Inc. Full time

    Our culture lifts you up—there is no ego in the way. Our common purpose? We all want to win for our customers. We aim to always be evolving, dynamic, and ambitious. We believe in the power of genuine connections. Each employee is a part of what makes us unique on the market: agile and dedicated. Time Type: Regular Job Description: SUMMARY OF JOB...


  • Montréal, Canada EDC Full time

    **Posting Date**: Jun 23, 2025, 3:21:25 PM **Primary Location**: Quebec-Montreal **Job Type**: Permanent **Schedule**: Full-time Are you ready to advance your career while impacting change in emerging markets? We are looking for a **Cybersecurity Specialist**! Welcome to **FinDev Canada**, Canada’s development financial institution! We are looking...


  • Montréal, QC HB C, Canada VIA Rail Full time $60,000 - $100,000 per year

    Reference Number : 1090Status : Permanent - Full-timeAnnual Salary / Hourly Rate : Number of positions to be filled : 1Application Deadline : 12/10/2025Hybrid Position: Starting in January 4 days at the officeDid you know that VIA Rail is carrying out ambitious projects to modernize its services and infrastructure? From our new ultramodern train fleet to...


  • Montréal, Canada KPMG Canada Full time

    OverviewWithin our Incident Response team (DFIR), the advisor contributes to the proactive aspect of cybersecurity intervention services. They play a key role in organizational preparedness and resilience against cyber incidents, notably through the execution of incident simulations (tabletop exercises, technical simulations) and Readiness Assessments...


  • Montréal, Quebec, HA, Canada Richter Full time $60,000 - $120,000 per year

    Richter Montreal OfficeThe Role: Cybersecurity Analyst – Risk, Performance and TechnologyRichter is seeking a Cybersecurity Analyst to strengthen its dedicated cybersecurity team.We are looking to welcome someone organized, proactive, motivated, and results-oriented.As a Cybersecurity Analyst within the Risk, Performance and Technology team, you will...


  • Montréal, Canada Eviden Full time

    **Job Applicant Privacy Notice**: **Cybersecurity Sales Representative**: - Publication Date: Mar 28, 2025 - Ref. No: 528435 - Location: Montreal, CA Remote Home, US **CyberSecurity** **Specialized Sales Representative (528435)** **Must haves for Cybersecurity Services Sales role**: - Cyber Services Sales history of selling into large Enterprises -at...