Manager, Cybersecurity Governance
The Manager, Cybersecurity Governance leads the design and maturity of the cybersecurity GRC program across IT and OT/ICS environments. They are responsible for driving enterprise risk assessments, managing audit obligations, and providing clear, business-focused reporting to senior leadership.
- Hybrid
- Concord, ON
- Posted Aug 20, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Toromont is looking for a Manager, Cybersecurity Governance to join our team in Concord. The Manager, Cybersecurity Governance leads the design, implementation, and ongoing maturity of Toromont’s cybersecurity governance, risk, and compliance program across IT and OT/ICS environments. The role provides cyber risk and regulatory expertise, ensuring frameworks, controls, and audit obligations are met while translating technical risk into clear, business focused reporting for senior leadership. The Manager oversees a team of Governance Analysts and partners closely with JSOC, IAM, Legal, Privacy, Compliance, and Internal Audit across Toromont’s national operations to strengthen enterprise cyber governance and risk management. Compensation $103,625 - $129,533 The listed base salary is just one component of our total rewards package, and performance-based or discretionary bonuses may be available. As a Manager, Cybersecurity Governance, YOU will experience: * Working within one of the safest organizations in the industry where your safety and well-being are our most important priority * Working for the best in class equipment dealer and with the premium Caterpillar brand * Opportunities to continuously Learn, Grow and Develop with our Toromont team through our internal Training teams that are geared for your success * Competitive total rewards including: wages, benefits, and premiums (as eligible) * An opportunity for flexible work schedules and opportunities across multiple locations across Eastern Canada In a typical day, YOU will: * Lead and mature Toromont’s Cybersecurity GRC framework across IT and OT/ICS, aligned to NIST, ISO 27001, COBIT, and emerging AI/agentic‑risk governance. * Drive enterprise cyber risk identification, assessment, prioritization, and tracking; deliver AI‑enabled dashboards and control‑monitoring metrics. * Own cybersecurity policy development and maintenance; serve as primary contact for internal/external/regulatory audits, including ICFR cyber controls. * Lead security awareness training, phishing simulations, and facilitate cyber tabletop and simulation exercises across IT and OT/ICS. * Produce executive‑level dashboards and presentations on cyber risk posture, control maturity, and audit status; support leadership communications and planning. * Manage cybersecurity governance initiatives and projects from planning through execution, ensuring effective collaboration across JSOC, IAM, Technology, and business unit teams. * Lead and mentor Cybersecurity Governance Analysts; partner with JSOC, IAM, Legal, Privacy, Compliance, and Internal Audit; monitor evolving regulatory requirements. Must-haves for this role: * 12+ years of progressive cybersecurity, risk, or governance experience, 6+ years of team leadership * A bachelor’s degree in Business Administration, Information Technology, Computer Science, or Engineering (or equivalent experience) * Preferred certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor/Implementer. About Toromont Cat With over 4,000 employees and 56 locations from Manitoba to Newfoundland, Toromont Cat has a proven track record, industry knowledge, dealership infrastructure, and service mindset to ensure our Construction, Mining, and Power Generation customers succeed. At Toromont Cat, work is built around people's strengths, our products, technology and an outstanding customer experience and through our strong partnership with Caterpillar ™, Toromont Cat takes care of our employees who take care of our customers! When you join our team, you become a member of the Toromont family. Your success is our success! Artificial Intelligence (AI) Please note that our hiring processes involve the use of artificial intelligence (AI) tools to assist with screening, assessing, or selecting candidates; all final decisions are reviewed by our Talent Acquisition team to ensure fairness and compliance with applicable laws
What you’ll do
The Manager, Cybersecurity Governance leads the design and maturity of the cybersecurity GRC program across IT and OT/ICS environments. They are responsible for driving enterprise risk assessments, managing audit obligations, and providing clear, business-focused reporting to senior leadership.
Requirements
Candidates must have 12+ years of progressive experience in cybersecurity, risk, or governance, including 6+ years of team leadership. A bachelor's degree in a relevant field such as Business, IT, or Engineering is required.
Benefits
• Competitive total rewards • Flexible work schedules • Training and development opportunities • Performance-based or discretionary bonuses
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Governance
- Risk Management
- Compliance
- IT/OT Security
- NIST
- ISO 27001
- COBIT
- Team Leadership
- Policy Development
- Audit Management
- Cyber Risk Assessment
- Security Awareness Training
- Executive Reporting
- Stakeholder Management
- Mentoring
- Certified Information System Auditor (CISA)
- Cyber Security Management
- Cyber Governance
- Cyber Security Policy Development
- Cyber Risk
- Planning
- Artificial Intelligence
- Auditing
- Business Administration
- Dashboard
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Customer Service
- Control Objectives For Information And Related Technology (COBIT)
- Communication
- Computer Science
- Information Technology
- Certified In Risk And Information Systems Control
- Cyber Security
- Governance
- Governance Risk Management And Compliance
- Leadership
- Internal Auditing
- ISO/IEC 27001
- Operations
- Presentations
- Regulatory Requirements
- Phishing
- Security Awareness
- Simulations
- Prioritization
Job areas
- Security & Safety
- Management & Leadership
- Technology
- Consulting
- Security Governance Manager
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
Additional details
- Minimum education
- Bachelor’s degree
- Minimum experience
- 10+ years
- Posting language
- English
- Working hours
- 40 hours per week