Manager, Risk
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
Team Leadership & Oversight
Conduct and coordinate enterprise-wide risk assessments to identify and evaluate current and emerging risks.
Maintain and continuously improve the organization’s risk register, control libraries, and mitigation plans.
Lead root cause analysis and corrective action planning for key risk incidents, control failures, and audit findings.
Third-Party & Cybersecurity Risk
Partner with IT and Procurement to assess and monitor third-party risk, including due diligence, contract risk review, and ongoing oversight.
Support the cybersecurity team in aligning risk management practices with frameworks such as NIST, ISO, and other industry standards.
Compliance & Policy Governance
Ensure adherence to internal policies, regulatory requirements (e.g., SOX, GDPR, HIPAA), and industry standards.
Monitor compliance metrics and escalate issues requiring executive visibility.
Contribute to the development, maintenance, and communication of risk-related policies, procedures, and training programs.
Reporting & Stakeholder Engagement
Prepare risk dashboards, heat maps, and executive summaries for the Director of Risk & Security, senior leadership, and audit committees.
Serve as a primary liaison for external auditors, regulators, and business unit leaders.
Communicate complex risk topics clearly to both technical and non-technical audiences.
Cross-Functional Collaboration
Collaborate with IT, Legal, Product, and other departments to assess operational, cybersecurity, and third-party risks.
Promote a culture of risk awareness, accountability, and continuous improvement across the organization.
QUALIFICATIONS
- Bachelor’s degree in Risk Management, Business, Accounting, Information Security, or related field.
- 5+ years of relevant experience in risk management, internal audit, or compliance.
- 2+ years in a people leadership role.
- Professional certifications such as CRMA, CISM, CISA, CIA, or equivalent preferred.
- Strong knowledge of risk frameworks (e.g., COSO, ISO 31000, NIST).
- Work experience and/or background in technology-based roles or industry
- Excellent communication, analytical, and stakeholder engagement skills.
- Ability to manage multiple priorities in a dynamic, fast-paced environment.
PREFERRED QUALIFICATIONS
- Familiarity with GRC platforms (e.g., Hyperproof, Archer, ServiceNow GRC, MetricStream).
- Experience working in regulated industries (e.g., government, healthcare, financial services).
- Working knowledge of cybersecurity, data privacy, or third-party risk management.
- This position requires proficiency in English to interact, support and/or provide services to non-French speaking customers, employees and/or partners inside and/or outside the province of Quebec.
- We are an equal opportunity employer and encourage applications from candidates of all backgrounds. We do not require “Canadian work experience”; all relevant experience will be considered. This posting is for an existing vacancy.
- Expected Compensation: C$110,000 - C$130,000
- At Fortra, we’re breaking the attack chain. Ready to join us? Visit our website to learn more about why employees choose to work for Fortra. Remember to connect with us on LinkedIn.
- All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, veteran or disability status.
About Fortra
Private cybersecurity company providing offensive and defensive security software and services to organizations worldwide.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Fortra
Channel Program Coordinator
, KSA
Fortra is seeking a Channel Program Coordinator to support Middle East channel programs, partner onboarding, deal registration, CRM administration, reporting, and regional partner engagement. The role requires a business
Sr. Business Analyst
, CAN
Sr. Project Manager
, GBR
Business Development Representative
, GBR
Customer Advocacy Manager
, GBR
Channel Program Coordinator
, KSA
Sr. Windows Kernel Developer
, CAN
Customer Success Manager
, CAN
Analyst Relations Manager
, CAN