Senior Manager, Information Security Governance and Risk Management

9 hours ago


Montreal, Quebec, Canada Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) Full time

Job Requisition ID:
11673

Position Status:
Permanent Full Time

Position Type:
Hybrid

Office Location:
Travel Requirement:
Limited

Language Designation:
Bilingual

Language Skill Levels (Read/Write/Speak):
CBC

Security Requirement:
Secret

Salary:
Our salaries generally range from $ to $ and are based on qualifications and experience.

About CMHC
The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our
results
and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by
trust
, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What's in it for you

Benefits
We've got the purpose, the people and the perks you need for a fulfilling career. Here's the comprehensive and generous benefits you get when you're a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Defined benefit pension plan.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.

About The Role
Join the security team, in the Senior Manager Information Security Governance and Risk Management position, where your expertise in governance and cyber risk management will make a difference. Here, you build, influence, and protect. Your ideas matter: your experience directly contributes to safeguarding the organization's digital future.

What You'll Do

  • Lead a team of risk specialists, tackle real challenges, and propose solutions aligned with business priorities.
  • Inform and advise leadership: risk analyses, recommendations, solution management, and action plans for remediation.
  • Alternate between mitigation strategies, regulatory alignment (OSFI B-13, NIST, ITSG-33), and team coaching.
  • Participate in audits, drive adoption of best practices, and stay ahead of evolving threats.
  • Be the trusted advisor who turns complexity into actionable plans for the CISO.
  • Support and assist the CISO in resolving and monitoring compliance issues.
  • Be responsible for growing the security team.
  • Represent the Information Security Office and influence the entire organization.

What You Should Have

  • 3+ years of direct experience in cybersecurity management.
  • 5 to 10 years working within IT operations, security, or risk teams.
  • Experience in a regulated sector (financial, government, etc.): an asset.
  • Mastery of security frameworks (NIST, OSFI B-13, CIS, etc.).
  • Recognized leadership, clear communication, ability to simplify complex topics.
  • Preferred certifications: CISSP, CCSP, GIAC, or equivalent.

Posting closing date:
Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We're committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

About
Learn more about our commitment to diversity and inclusion
What happens after you apply

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort.
Learn more about our hiring process
. If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful don't worry – we're always posting new positions, so don't hesitate to give it another shot. We're excited to see what you bring to the table this time around



  • Montreal, Quebec, Canada Air Liquide Full time

    How will you CONTRIBUTE and GROW?The Security Analysts supports the Information Security Officer to uphold Governance, Risk Management, and Compliance standards across Digital & IT environments. Security analysts are essential in maintaining the cybersecurity integrity of Air Liquide's IT and OT systems, as well as its sensitive data by ensuring adherence of...

  • Data Security Manager

    9 hours ago


    Montreal, Quebec, Canada WSP in Canada Full time

    Job DescriptionThe Opportunity:We are seeking an experienced professional to lead and manage the overall data security management practice at WSP. This is a pivotal role where you will own the overall data loss prevention practice and at the forefront of protecting our critical data from internal and external threats, with a core focus on Data Loss...


  • Montreal, Quebec, Canada McKesson Full time $108,100 - $180,100

    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.What you do at McKesson matters. We foster a...


  • Montreal, Quebec, Canada TalentBurst, an Inc 5000 company Full time

    Risk Governance SpecialistLocation: Montreal HybridDuration:5 month(s) plus extensionsDescription/Comment: The Model Risk Governance Specialist is part of the RISK Independent Review & Control team (RISK IRC) and is the central point for ensuring that the bank's models meet all regulatory and internal model‐risk requirements, particularly those outlined in...


  • Montreal, Quebec, Canada PSP Investments Full time

    ABOUT USWe're one of Canada's largest pension investors, with CAD$299.7 billion of net assets as of March 31, 2025.We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Reserve Force. Headquartered in Ottawa, PSP Investments has its principal business office in...


  • Montreal, Quebec, Canada eTeam Full time

    **Job Title: Model Risk Governance SpecialistLocation: Montreal, QC (Hybrid)Duration: 05 MonthPay rate: $70/hr - $75/hrThe position at a glance**RISK Independent Review & Control (RISK IRC) is a special unit within the RISK organization and reports directly to the Group Chief Risk Officer. The independent review arm of the department provides second line of...


  • Montreal, Quebec, Canada National Bank of Canada Full time

    Attendance: Hybrid Employment Category: Senior Professional Type of Contract: Permanent Benefits for vendors:A career as a Senior Technology risk Advisor in the Technology, Cyber and Data risk Management team at National Bank means acting as a second-line expert to support oversight, consistency of practises and integrated governance of technology and...


  • Montreal, Quebec, Canada iA Financial Group Full time

    Job DescriptionJob TitleSenior Risk Management AdvisorBuild the future with usAre you driven by strategy and innovation in risk management and eager to contribute to an organization whose purpose is to ensure clients feel confident and secure about their future? As a Senior Risk Management Advisor, you will play a key role in implementing innovative...


  • Montreal, Quebec, Canada Desjardins Full time

    As a risk management analyst, you contribute to analysis, guidance and prevention with regard to risk-related operations and activities such as crisis management and security, as well as compliance and internal control. You are responsible for monitoring internal controls and operational risks. You act as a risk management resource person and serve as a risk...


  • Montreal, Quebec, Canada Alteo Full time

    Alteo is looking for an Information Systems Compliance and Governance Manager for a permanent position based in Montreal.You will be responsible for developing, implementing, and optimizing policies and procedures related to information controls and compliance, ensuring compliance with applicable security standards and regulations. You will work closely with...