BDO CANADA Logo

BDO CANADA

Senior Manager, Information Security

Posted 5 Days Ago
Be an Early Applicant
In-Office
2 Locations
Senior level
In-Office
2 Locations
Senior level
Leads cybersecurity governance, risk management, and compliance programs. Responsibilities include managing GRC teams, assessing IT and vendor risks, coordinating audits, developing security policies, implementing governance frameworks, overseeing GRC platform automation, delivering security awareness training, and advising executives on risk and compliance strategy. Requires extensive IT security or risk management experience, team leadership, and familiarity with security technologies and compliance frameworks.
The summary above was generated by AI

Putting people first, every day
 

BDO is a firm built on a foundation of positive relationships with our people and our clients. Each day, our professionals provide exceptional service, helping clients with advice and insight they can trust. In turn, we offer an award-winning environment that fosters a people-first culture with a high priority on your personal and professional growth.

Your Opportunity

The Senior Manager, Information Security leads the organization’s cybersecurity governance, risk management, and compliance programs, ensuring security policies, regulatory requirements, and industry best practices are effectively implemented.

The Senior Manager, Information Security is responsible for developing, managing, and executing IT security governance, risk, and compliance strategy.  This includes overseeing risk assessments, audits, vendor security evaluations, policy enforcement, and leading a team of security analysts or specialists

This role is cross-functional, collaborating with IT, Risk, Legal, Compliance, and business teams to maintain compliance with frameworks like ISO 27001, NIST, SOC 2, and applicable privacy regulations such as GDPR and HIPAA

This role is ideal for a seasoned cybersecurity professional with deep GRC experience, capable of driving cybersecurity programs that ensure operational resilience, regulatory compliance, and enterprise risk mitigation while leading and mentoring a high-performing team.


Key Responsibilities

  • Leadership & Team Management: Build, mentor, and manage a high-performing GRC team, tracking objectives and key results (OKRs) and fostering a culture of continuous development.
  • Risk Management: Identify, assess, and monitor IT-related risks, evaluate risk exceptions, and oversee tactical and strategic resolution plans.
  • Compliance & Auditing: Plan and coordinate internal audits, third-party audits, and regulatory assessments; ensure corrective actions are implemented effectively.
  • Policy Development: Develop, update, and enforce IT security policies, standards, procedures, and guidelines aligned with changing regulations and business requirements.
  • Vendor and Third-Party Risk: Conduct security assessments of vendors, partners, and cloud providers to ensure regulatory and contractual compliance.
  • Governance & Frameworks Implementation: Oversee GRC platform deployment and configuration to automate control monitoring, reporting, and continuous improvement.
  • Awareness & Training: Implement cybersecurity awareness programs and deliver end-user or management training on security and compliance expectations.
  • Strategic Advisory: Serve as a trusted advisor for IT risk and compliance strategy, engaging with executive leadership and stakeholders to ensure alignment with enterprise goals.

Required Qualifications

  • Education: Bachelor’s degree in Information Technology, Cybersecurity, Information Security, Computer Science, or a related field.
  • Experience: 10+ years in IT security or risk management with 2+ years leading teams managing regulatory or compliance programs. Experience in technology risk consulting, IT audits, and multi-country compliance programs is highly valued.
  • Certifications: CISSP, CISM, CRISC, CISA, or CGEIT preferred.
  • Technical Skills: Proficiency in GRC tools, familiarity with identity/access management (LDAP/AD, SAML, OIDC), cloud security, and integration with SIEM, vulnerability management, and ITSM platforms
  • Soft Skills: Strong leadership, communication, stakeholder engagement, problem-solving, and decision-making abilities. Ability to translate complex compliance requirements into actionable strategies.

The expected range of compensation for this role is $132,000 to $182,000 annually.

Why BDO?
Our people-first approach to talent has earned us a spot among Canada’s Top 100 Employers for 2026. This recognition is a milestone we’re thrilled to add to our collection of awards for both experienced and student talent experiences. 


At BDO, our people experience is guided by three core pillars—Do work with genuine care, Do what matters with purpose, and Do what’s next - shaping how we support our people, serve our clients, and grow together.


Our firm is committed to providing an environment where you can be successful in the following ways:


  • We enable you to engage with how we change and evolve, being a key contributor to the success and growth of BDO in Canada.
  • We help you become a better professional within our services, industries, and markets with extensive opportunities for learning and development.
  • We support your achievement of personal goals outside of the office and making an impact on your community.
  • We foster a collaborative, inclusive environment where your ideas are valued, and you can do your best work with genuine care and purpose
  • We encourage innovation and forward thinking, empowering you to embrace what’s next and help shape the future of our firm

Giving back adds up: Where company meets community. BDO is actively involved in our communities by supporting local charity initiatives. We support staff with local and national events where you will be given the opportunity to contribute to your community.


Total rewards that matter: We pay for performance with competitive total cash compensation that recognizes and rewards your contribution. We provide comprehensive benefits from day one, and a flexible personal time off policy.  We’re committed to supporting your overall wellbeing and provide reimbursement for wellness initiatives that fit your lifestyle.

Everyone counts: 
We are committed to creating a workplace where employees can participate fully, contribute meaningfully and succeed without barriers. We are dedicated to fostering a workplace defined by respect, fairness, and a true sense of belonging for everyone.  We recognize and celebrate the unique experiences, identities, and perspectives that each of us bring – and that these experiences strengthen how we work together.  Our commitment extends to ensuring that our application process is both inclusive and accessible.  If you require accommodation to complete the application process, please contact us.


Flexibility:
All BDO personnel are expected to spend some of their time working in the office, at the client site, and virtually unless accommodations or alternative work arrangements are in place.


Our model is a blended approach designed to support the flexible needs of our people, the firm and our clients. It’s about creating work experiences that meet everyone’s needs and providing flexibility to adjust when, where and how we work to meet the expectations of our role.

 

Code of Conduct: Our Code of Conduct sets clear standards for how we conduct business. It reflects our shared values and commitments and includes guiding principles to help us make ethical decisions and maintain trust with each other, our clients, and the public.


BDO may use artificial intelligence enabled tools to support certain aspects of the recruitment process. While these tools assist our teams, our use of AI does not replace human decision making, and all employment-related outcomes are made by BDO personnel.


More information on BDO Canada’s Privacy Policy can be found here:

Privacy Policy | BDO Canada

Ready to make your mark at BDO? Click “Apply now” to send your up-to-date resume to one of our Talent Acquisition Specialists.

To explore other opportunities at BDO, check out our careers page.

#LI-SA1

Similar Jobs

3 Days Ago
In-Office
Toronto, ON, CAN
Senior level
Senior level
Financial Services
Provides second-line oversight and credible challenge for cybersecurity and technology risks. Assesses risk profiles, governance frameworks, controls, incidents, remediation, emerging threats, and regulatory expectations. Advises senior leaders and governance bodies, leads independent assessments and thematic reviews, supports audits and regulatory examinations, and translates complex technical issues into actionable recommendations and executive reporting. Builds cross-functional relationships while maintaining independence and promotes data-informed cybersecurity risk management practices.
Top Skills: Cloud PlatformsCloud SecurityCybersecurityEnterprise ArchitectureFfiecIdentity And Access ManagementInformation SecurityIsoNistSecurity ArchitectureSecurity OperationsSoftware DevelopmentVulnerability Management
One Month Ago
In-Office
Toronto, ON, CAN
Senior level
Senior level
Fintech • Insurance • Financial Services
Lead and operate the CSIRT function to coordinate enterprise cyber incident response, technical investigations, forensics, containment, recovery, and post-incident improvements. Partner with detection, threat intel, platform, legal, privacy, and business stakeholders to convert incidents into detections, playbooks, and automation. Establish CSIRT metrics, governance, and capability roadmap while coaching and developing a high-performing incident response team.
Top Skills: Case ManagementCloud SecurityDigital ForensicsEdrEndpointIdentityMalware AnalysisNetwork TelemetrySaaSSIEMSoarThreat HuntingThreat IntelligenceXdr
47 Minutes Ago
Hybrid
Toronto, ON, CAN
Senior level
Senior level
Financial Services
The job description is pending and provides no specific responsibilities or qualifications for the Private Equity Fund Administration Senior Associate role.

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account