Find your next opportunity
Cargojet
YYZ - Senior Manager, Cybersecurity & GRC - FT (4929)
Mississauga, ON · On-site
Posted Aug 27, 2026
Why it matched your search
- Skill: Supply Chain
Job summary
The Senior Manager will lead the organization's cybersecurity strategy, governance, risk management, and compliance programs while overseeing security operations and incident response. They will also serve as a strategic advisor to executive leadership regarding cybersecurity risks, emerging technologies, and the secure adoption of AI.
Job details
Accelerate your career with the most awarded Air Cargo Airline in Canada! Cargojet is Canada's leading provider of time-sensitive overnight air cargo services and carries over 1,300,000 pounds of cargo each business night. Cargojet operates its network across North America each business night, utilizing a fleet of all-cargo aircraft Cargojet has been awarded one of Canada’s 50 Best Managed Companies as well as being awarded the Shipper’s Choice Award for the best Air Cargo Carrier in Canada for the past number of years. Being part of Cargojet will allow you to become a part of a diverse and vibrant family at the leading edge of the air cargo industry both domestically and internationally. Cargojet team members are dedicated, hardworking, and have a strong sense of leadership and commitment. Primary Objective of the Position The primary objective of this role is to provide strategic leadership for the organization's cybersecurity program by proactively monitoring emerging cybersecurity trends, technologies, and evolving threat landscapes. The role is responsible for establishing and advancing cybersecurity governance, risk management, compliance, and security initiatives to protect organizational assets, ensure regulatory compliance, and drive continuous improvement of the overall security posture. This role serves as a trusted cybersecurity advisor to IT leadership and Executive Management, translating complex cybersecurity and technology risks into clear business priorities, strategic recommendations, and actionable plans. The position is responsible for leading the organization's cybersecurity strategy, governance, risk management, and compliance (GRC) program while providing oversight of security operations, incident response, cyber resilience, cloud security, third-party risk management, and the secure adoption of artificial intelligence (AI) and other emerging technologies. Through proactive risk management and strategic leadership, the role ensures the organization's cybersecurity posture remains resilient, compliant, and aligned with business objectives. Job Duties: * Develop and execute a multi-year cybersecurity strategy, roadmap, and operating model aligned with business objectives and enterprise risk. * Lead the Cybersecurity Governance, Risk & Compliance (GRC) program, including risk assessments, risk registers, policies, controls, remediation, and executive reporting. * Lead cybersecurity strategy for the secure adoption of Artificial Intelligence (AI), Generative AI, machine learning, and other emerging technologies. * Assess and manage cybersecurity, privacy, data, and third-party risks associated with AI-enabled technologies and emerging technology platforms. * Establish security and governance requirements for the responsible use of AI and Generative AI, including data protection, access controls, model security, monitoring, and risk management. * Identify opportunities to leverage AI and automation to enhance threat detection, security monitoring, incident response, vulnerability management, and security operations. * Monitor emerging cyber threats and attack techniques involving AI and develop appropriate controls, detection capabilities, and response strategies. * Partner with technology, data, privacy, legal, and business teams to establish secure-by-design principles for AI and emerging technologies. * Advise CIO, IT leadership, executive management, and other senior stakeholders on cybersecurity and technology risk. * Support Executive and Board-level reporting on cybersecurity posture, risk, compliance, and strategic initiatives. * Lead cybersecurity compliance, audit, customer security assessments, and regulatory reviews. * Establish cybersecurity KPIs/KRIs and metrics to measure risk, control effectiveness, maturity, and program performance. * Develop cybersecurity priorities, budgets, business cases, and investment plans. * Provide executive oversight of cyber incident response, cyber resilience, tabletop exercises, and major incident reviews. * Oversee the performance of the outsourced Security Operations Center (SOC), including monitoring, detection, incident response, vulnerability management, and threat intelligence. * Lead third-party and supply-chain cybersecurity risk management, including vendor assessments and security requirements. * Provide cybersecurity governance and risk oversight for cloud, infrastructure, applications, data, identity, AI, and emerging technologies. * Partner with technology, business, Legal, Privacy, Risk, Internal Audit, Procurement, and external providers to embed security into business and technology decisions. * Lead, mentor, and develop cybersecurity team members and build a high-performing security organization. Qualifications: * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline. * 12+ years of progressive cybersecurity/information security experience, including 5+ years in a leadership or management role. * Strong experience in cybersecurity strategy, GRC, enterprise risk management, and security assurance. * Experience overseeing SOC/MSSP relationships and cybersecurity operations. * Understanding of emerging cybersecurity risks associated with AI, cloud, automation, and evolving technology platforms. * Ability to balance innovation with security, privacy, regulatory, and enterprise risk requirements * Demonstrated experience with incident response, cyber resilience, and security program management. * Experience presenting cybersecurity risks and strategy to senior executives. * Experience supporting audits, regulatory reviews, customer security assessments, and compliance programs. * Experience with cloud security and cybersecurity architecture. * Experience developing cybersecurity budgets, business cases, metrics, and investment priorities. * Strong understanding of frameworks such as NIST, ISO 27001, CIS Controls, and SOC 2. Preferred Certifications: * CISSP, CISM, CRISC, CCSP, GIAC, or other recognized cybersecurity, risk, audit, or information security certifications are considered an asset. What Success Looks Like * Improved cybersecurity maturity and enterprise risk posture * Strong cybersecurity governance and executive visibility * Effective management and reduction of material cyber risks * Strong audit, compliance, and regulatory outcomes * Effective third-party cybersecurity risk management * Improved cyber incident preparedness and resilience * Successful execution of the cybersecurity strategy and roadmap * A strong, capable, and sustainable cybersecurity team Important to Know: * Cargojet is an equal opportunity employer. We thank you for your interest. Only those candidates selected for an interview will be contacted. * We are committed to providing accommodations for persons with disabilities. If you require accommodation, we will work with you to meet your needs. * At Cargojet, we make safety the highest priority. Because of this priority and as we operate in a safety-sensitive environment, we require all employees to abstain from consuming Cannabis, in and outside of the workplace. This is a critical element of our drug and alcohol policy that all employees must comply with at all times.
What you’ll do
The Senior Manager will lead the organization's cybersecurity strategy, governance, risk management, and compliance programs while overseeing security operations and incident response. They will also serve as a strategic advisor to executive leadership regarding cybersecurity risks, emerging technologies, and the secure adoption of AI.
Requirements
Candidates must possess a bachelor's degree in a relevant field and at least 12 years of progressive cybersecurity experience, including 5 years in a leadership role. Strong expertise in GRC frameworks, cloud security, and executive-level communication is required.
Listed skills
- Regulatory Compliance · Preferred
- Leadership · Preferred
- Executive Reporting · Preferred
- Risk Management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Strategy
- Governance Risk and Compliance
- Risk Management
- Security Operations
- Incident Response
- Cloud Security
- Third-party Risk Management
- Artificial Intelligence Security
- Cyber Resilience
- Vulnerability Management
- Security Architecture
- Regulatory Compliance
- Executive Reporting
- Leadership
- Strategic Planning
- Audit Management
- Compliance Auditing
- Cyber Security Management
- Cyber Governance
- Cyber Incident Response
- Cyber Operations
- Cyber Security Strategy
- Generative Artificial Intelligence
- Certified Cloud Security Professional (CCSP)
- Cyber Threat Intelligence
- Cloud Automation
- Supply Chain
- Third Party Risk Management
- Business Objectives
- Threat Detection
- Cybersecurity Risk Management
- Data Privacy
- Emerging Technologies
- Resilience
- Enterprise Risk Management (ERM)
- Cybersecurity Compliance
- Cyber Risk
- IT Security Architecture
- Cannabis
- Access Controls
- Artificial Intelligence
- Budgeting
- Auditing
- Automation
- Management
- Investments
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Cloud Infrastructure
- Procurement
Job areas
- Technology
- Management & Leadership
- Security & Safety
- Logistics
- Transportation
- Cybersecurity Manager
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other