Base Career helps you apply smarter for this job.
Key skills for this role
CSA Group has an immediate opportunity for a Manager, IT Governance, Risk & Compliance to lead the development, delivery, and continuous improvement of CSA Group's technology governance, risk and compliance framework, and the assurance and resilience activities that evidence its effectiveness. This role owns the technology policy, standard, procedure, and control framework; leads technology and cybersecurity risk assessment, treatment, and reporting; oversees compliance with internal policies, contractual obligations, customer requirements, and applicable regulatory and privacy requirements; and coordinates internal and external audits through to remediation of findings. The role also leads security assurance and third-party risk activities, governs the enterprise disaster recovery and technology resilience program, and ensures cybersecurity incident response plans and escalation paths are documented, tested, and understood. While technology delivery teams design, build, and operate security controls day-to-day, this role defines the control requirements those teams must meet, independently validates that controls are implemented and operating effectively, tracks remediation to closure, and reports residual risk to the IT Leadership Team and executive leadership.
At the heart of CSA Group is a vision: making the world a better, safer, more sustainable place. It's been part of our mission for nearly one hundred years: from the first engineering standard for railway bridges developed in 1919, to more than 3,500 standards, codes & related products today.
Headquartered in Canada, with a global footprint of more than 30 labs and offices across Europe, Asia and North America, CSA Group tests, inspects and certifies a wide range of products - from every day househould items to leading edge technology-to meet exacting requirements for safety, performance and environmental impact.
Our employees take pride in making a difference in people's lives through the work that we do. We're looking for people like you to help make it happen.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Calgary, CAN
Toronto, CAN
Toronto, CAN
, IND
CSA Group is seeking a Technician Intern to assist with laboratory testing assignments. The role requires a final-year engineering student or a completed electronics or electrical engineering qualification and involves o
Cleveland, USA
Montréal, CAN
Calgary, CAN
Toronto, CAN
Calgary, CAN
Toronto, CAN
Toronto, CAN
, IND
Cleveland, USA
Montréal, CAN
Calgary, CAN
Toronto, CAN
CSA Group has an immediate opportunity for a Manager, IT Governance, Risk & Compliance to lead the development, delivery, and continuous improvement of CSA Group's technology governance, risk and compliance framework, and the assurance and resilience activities that evidence its effectiveness. This role owns the technology policy, standard, procedure, and control framework; leads technology and cybersecurity risk assessment, treatment, and reporting; oversees compliance with internal policies, contractual obligations, customer requirements, and applicable regulatory and privacy requirements; and coordinates internal and external audits through to remediation of findings. The role also leads security assurance and third-party risk activities, governs the enterprise disaster recovery and technology resilience program, and ensures cybersecurity incident response plans and escalation paths are documented, tested, and understood. While technology delivery teams design, build, and operate security controls day-to-day, this role defines the control requirements those teams must meet, independently validates that controls are implemented and operating effectively, tracks remediation to closure, and reports residual risk to the IT Leadership Team and executive leadership.
University degree in Computer Science, Information Technology, Cybersecurity, Engineering, or Business. Master's degree considered an asset.
Ten-plus (10+) years of progressive experience in cybersecurity, information security, technology risk, governance, compliance, or technology operations, including three to five (3-5) years leading a governance, risk, compliance, or security assurance program.
Experience leading enterprise security governance and risk programs within complex, multi-national, and regulated environments.
Experience managing audits, risk programs, security assessments, and technology governance initiatives, including planning, execution, reporting, and remediation.
Experience coordinating the response to cybersecurity incidents, including stakeholder reporting, notification assessment, and tracking of corrective actions to closure.
Experience governing disaster recovery and business continuity programs, including test planning, validation, and corrective action tracking.
Experience with vendor due diligence, contract security and privacy schedules, and customer security due diligence and questionnaire response.
Standards developer and provider of testing, inspection, and certification services for manufacturers and the public.
Visit company websiteJobs and hiring trendsCAD 116230-152555 yearly / year
Full-time
Manager
Hybrid
Apply faster on company sites with our extension.