Cybersecurity Governance, Risk and Compliance Specialist – Risk Management
The Cybersecurity Risk Manager will lead and mature the cybersecurity risk management program by identifying, assessing, and monitoring risks across operations and technologies. They will also partner with stakeholders to define risk treatment plans and provide clear reporting to leadership and governance committees.
- On-site
- Montréal, QC
- Posted Aug 26, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Here are few reasons why folks love working at CAE! Meaningful work that drives professional development Ability to enter and grow within the technology industry Work in a collaborative environment Be part of a high-performance team What we have to offer Benefits: Fully flexible for you to choose what is important Retirement: Defined Benefits Retirement Plan & Group Registered Retirement Savings Plan (RRSP) Financial Perks: Employee Stock Purchase Plan & numerous corporate discounts Personal and Family Programs: Physical Wellness Plan & Supplementary Maternity Plan Work-Life Balance: Flextime & California Fridays all year Fun at work: social and community events all-year round! Your Mission As a Cybersecurity Risk Manager, your mission is to lead and mature the cybersecurity risk management program by identifying, assessing, treating, monitoring and communicating cybersecurity risks that may impact CAE’s operations, technologies and business objectives. Your Role & Main Responsibilities Lead and mature the cybersecurity risk management program, including risk identification, assessment, treatment, monitoring and reporting. Maintain the enterprise cybersecurity risk register and ensure risks, issues, exceptions and mitigation plans are documented, tracked and regularly reviewed. Conduct cybersecurity risk assessments for projects, technologies, third parties and business initiatives, and provide practical risk-based recommendations. Partner with business and technology stakeholders to define risk treatment plans, clarify ownership, track remediation progress and support risk acceptance decisions. Prepare clear risk reporting, dashboards and executive summaries to support informed decision-making by cybersecurity leadership and governance committees. Support the development and continuous improvement of risk methodologies, scoring models, control expectations and governance processes aligned with industry frameworks. Monitor key risk indicators, emerging threats and control gaps, and translate them into actionable insights for stakeholders. Advise project teams on cybersecurity risk requirements and ensure risks are identified early, assessed consistently and managed throughout the project lifecycle. Contribute to risk awareness, governance routines and performance indicators that strengthen the Governance, Risk and Compliance function. Your Qualifications Soft skills Want to be in a performing team Show Initiative & leadership Be customer orientated Display a sense of collaboration (teamwork) & interpersonal skills Ability to influence Technical skills Bilingualism (French and English) is required A minimum of seven (7) years experience in IT Security or Cybersecurity In-depth knowledge and experience in IT Security and Telecommunications In-depth knowledge risk analysis methodologies and security standards (e.g. ISO, NIST) Industry-recognized certification (CISSP, CISA, CIRISC, CISM) would be considered an asset Knowledge about threat modeling methodology Aerospace industry knowledge would be considered an asset At CAE, connecting with people is very important. If you have any questions on this career opportunity, please do not hesitate to contact Didier Avignon, Talent Acquisition Specialist and ([email protected]) or Rémi Beauregard, Head of Cybersecurity Governance, Risk and Compliance ([email protected]). About CAE At CAE, our mission is clear: to help make the world a safer place. For nearly 80 years, we’ve driven innovation in simulation, training, and mission readiness to support critical operations worldwide. By leveraging advanced technologies, we empower our customers to operate smarter, faster, and more sustainably. Join a purpose-driven organization where bold ideas are encouraged, collaboration drives progress, and your growth fuels our shared success. Position Type Regular Equal Opportunity & Accommodations CAE is committed to providing equal opportunities to all applicants, regardless of race, nationality, color, religion, sex, gender identity or expression, sexual orientation, disability, neurodiversity, veteran status, age, or other characteristics protected by law. We encourage applicants who may not meet every qualification to apply. Reasonable accommodations are available—contact your recruiter or email [email protected] if needed. Data Privacy Privacy Statement | CAE As part of our process, we may use AI‑supported tools to help review applications, with human decision‑making at every step. CAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.
What you’ll do
The Cybersecurity Risk Manager will lead and mature the cybersecurity risk management program by identifying, assessing, and monitoring risks across operations and technologies. They will also partner with stakeholders to define risk treatment plans and provide clear reporting to leadership and governance committees.
Requirements
Candidates must have at least seven years of experience in IT security or cybersecurity and possess in-depth knowledge of risk analysis methodologies and security standards. Proficiency in both French and English is required, and industry-recognized certifications such as CISSP, CISA, or CISM are considered an asset.
Benefits
• Retirement plan • Group registered retirement savings plan • Employee stock purchase plan • Physical wellness plan • Supplementary maternity plan • Flextime • Corporate discounts
Listed skills
- LeadershipPreferred
- Project managementPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity risk management
- Risk assessment
- Governance
- Compliance
- Threat modeling
- ISO standards
- NIST standards
- IT security
- Telecommunications
- Risk reporting
- Leadership
- Stakeholder management
- Project management
- Bilingualism
- Analytical skills
- Certified Information System Auditor (CISA)
- Influencing Skills
- Cyber Governance
- Risk Awareness
- IT Security
- Business Objectives
- Cyber Security Assessment
- Cybersecurity Risk Management
- Data Privacy
- Bilingual (French/English)
- Treatment Planning
- Cyber Risk
- Dashboard
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Decision Making
- Communication
- Continuous Improvement Process
- Cyber Security
- Preparing Executive Summaries
- Innovation
- Interpersonal Communications
- Key Risk Indicator
- Risk Management
- Operations
- Proactivity
- Systems Development Life Cycle
- Risk Analysis
- Threat Modeling
- Mitigation
- Aerospace Industry
- Teamwork
Job areas
- Security & Safety
- Technology
- Management & Leadership
- Consulting
- Compliance Risk Manager
- Risk Manager
- Management and Organization Analysts
- Financial Risk Specialists
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 5+ years
- Posting language
- English
- Working hours
- 40 hours per week