Cybersecurity Risk Manager
RemoteCalifornia, United States or Ottawa, Ontario, Canada
Job Summary
Lead end-to-end execution of cybersecurity risk identification, assessment, prioritization, and treatment planning across enterprise systems and services. Maintain a complete, accurate risk register with clear ownership and deliver management-ready reporting that enables informed decision-making. Ensure consistent application of frameworks such as NIST CSF, ISO 27001, and SOC 2 while aligning practices to regulatory requirements including FedRAMP. Evaluate risks associated with cloud environments, third-party services, and AI-enabled capabilities to strengthen governance and evidence readiness. Influence cross-functional stakeholders to drive continuous improvement of processes and tooling.
Required Qualifications
- University degree or equivalent practical experience in Information Security, Computer Science, or related field
- 5–7 years of progressive experience in cybersecurity risk, IT risk, audit, or compliance
- Strong knowledge of risk and control frameworks (NIST CSF, NIST SP 800 53, ISO 27001, SOC 2)
- Demonstrated ability to operationalize risk frameworks into scalable processes, metrics, and reporting
- Strong analytical and influencing skills, with ability to translate technical risk into business decision insights
- Experience working with GRC platforms, audit evidence, and workflow automation
- A demonstrated commitment to continuous learning, with a strong desire to stay current on rapid advancements in AI, particularly in generative and agentic AI, and their implications for cybersecurity
Desired Qualifications
- Professional certifications such as CRISC, CISSP, CISM, CISA, or equivalent
- Experience with cloud security and regulated SaaS/cloud environments, including FedRAMP readiness
- Familiarity with AI risk management concepts, including governance, privacy, and emerging regulatory expectations (NIST AI, ISO/IEC 42001)
- Practical experience applying AI, automation, analytics, or GRC workflow improvements to strengthen cybersecurity risk analysis, reporting, or evidence management
- Experience with privacy, data protection, or regulatory requirements such as GDPR, CCPA, NIS2, or other applicable security and compliance obligations
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.