Cybersecurity Risk Manager

6 hours ago

Ottawa, Ontario, Canada Kinaxis Inc. Full-time

About Kinaxis

Are you looking to join an innovative, market-leading company where you can truly elevate your career? At Kinaxis we are serious about culture, we are serious about technology, we are serious about customers, and we are serious about not taking ourselves too seriously. If you are looking to be part of an incredible growth story, then we might just be the place for you

In 1984, we started out as a team of three engineers. Today, we have grown to become a global organization with over 2000 employees around the world, 6 global office and a best-in-class HQ in Ottawa, Canada. As winners of several Top Employer awards globally, we are proud to work with our customers and employees towards solving some of the biggest challenges facing supply chains today.

Kinaxis is a global leader in modern supply chain orchestration, powering complex global supply chains, and supporting the people who manage them. Our powerful, AI infused platform provides full transparency and visibility across end-to-end supply chains, enabling our customers to make faster, better decisions. We are trusted by renowned global brands to provide the agility and predictability needed to navigate today’s volatility and disruption. With more than 40,000 users in over 100 countries, we are expanding our team as we continue to innovate and revolutionize how we support our customers.

Location

Ottawa and Toronto, Canada - Hybrid

Other Canadian and USA locations - Remote

About the team

The Cybersecurity Risk Manager is accountable for the execution, quality, and continuous improvement of the enterprise cybersecurity risk management program. This role ensures that cybersecurity risks across cloud, product, third‑party, and AI-enabled capabilities are consistently identified, assessed, governed, and translated into decision‑ready insights and actionable remediation outcomes. This role does not include direct people management responsibilities, but it does require cross-functional influence.

The role also incorporates FedRAMP readiness and emerging AI risk management considerations into the broader cybersecurity risk program, ensuring cloud, product, third-party, and AI-enabled risks are evaluated consistently and translated into actionable remediation, reporting, and governance outcomes.

Vacancy Status

This is an existing job vacancy

What you will do

Cybersecurity Risk Program Execution

  • Lead the end‑to‑end execution of cybersecurity risk identification, assessment, prioritization, and treatment planning across enterprise systems and services
  • Ensure consistent application of risk frameworks and methodologies aligned to enterprise governance and regulatory expectations
  • Oversee control evaluation, residual risk analysis, and risk acceptance recommendations, ensuring clear rationale and alignment to risk appetite

Risk Governance and Reporting

  • Maintain a complete, accurate, and decision‑ready cybersecurity risk register with clear ownership, status, and evidence
  • Deliver management‑ready risk reporting and insights that enable informed decision‑making, prioritization, and escalation
  • Strengthen data quality, metrics, and reporting practices to improve visibility into enterprise risk posture

Regulatory and Compliance Alignment

  • Align cybersecurity risk practices to regulatory and assurance requirements including FedRAMP, SOC, ISO 27001, and related frameworks
  • Translate regulatory expectations into actionable risk management practices, remediation plans, and governance controls
  • Support continuous monitoring and evidence readiness for audit and certification requirements

Emerging Risk Domains

  • Evaluate risks associated with cloud environments, third‑party services, and AI-enabled capabilities
  • Contribute to AI risk governance practices, including assessment criteria, controls, and reporting mechanisms
  • Monitor emerging cybersecurity, AI, and regulatory developments and integrate relevant changes into the risk program

Technical Leadership and Influence

  • Provide technical leadership and quality oversight across risk assessment activities and outputs
  • Influence cross-functional stakeholders (engineering, product, legal, compliance) to ensure risks are understood, owned, and effectively addressed
  • Drive continuous improvement of processes, tooling, and automation to enhance risk program maturity

What we are looking for

Primary Skills and Qualifications

  • University degree or equivalent practical experience in Information Security, Computer Science, or related field
  • 5–7 years