We are seeking a strategic Senior Manager, Cybersecurity & GRC to lead cybersecurity strategy, governance, risk, compliance, and continuous improvement initiatives. This role will partner with executive leadership and oversee key areas including GRC, SOC/MSSP, incident response, cyber resilience, cloud security, third-party risk, and AI security.
Key Responsibilities
- Develop and execute the enterprise cybersecurity strategy and roadmap.
- Lead GRC, risk assessments, policies, controls, compliance, and audit programs.
- Advise CIO, executives, and senior stakeholders on cybersecurity risks and priorities.
- Oversee SOC/MSSP, incident response, vulnerability management, and cyber resilience.
- Establish security governance for AI, GenAI, cloud, and emerging technologies.
- Lead third-party and supply-chain cybersecurity risk management.
- Develop cybersecurity KPIs/KRIs, budgets, business cases, and investment priorities.
- Lead and mentor cybersecurity teams and drive continuous security improvement.
Qualifications
- 12+ years of cybersecurity/information security experience.
- 5+ years in a leadership/management role.
- Strong experience in Cybersecurity Strategy, GRC, Enterprise Risk, and Security Assurance.
- Experience with SOC/MSSP oversight, incident response, cloud security, and compliance.
- Strong knowledge of NIST, ISO 27001, CIS Controls, and SOC 2.
- Experience presenting cybersecurity strategy and risk to executive leadership.
- Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field.
- CISSP, CISM, CRISC, CCSP, or GIAC certification is an asset.
If you're a senior cybersecurity leader with strong GRC and strategic experience, we'd like to hear from you.