Back to job search
C
CAEVerified Job Source

Cybersecurity Governance, Risk and Compliance Specialist – Risk Management-EN

Lead and mature the cybersecurity risk management program by identifying, assessing, and monitoring risks to CAE's operations and technologies. Maintain the enterprise risk register and partner with stakeholders to define treatment plans and provide executive risk reporting.

  • On-site
  • Montréal, QC
  • Posted Aug 26, 2026
  • Apply by Sep 25, 2026
  • 1 position

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Job summary

Here are few reasons why folks love working at CAE! Meaningful work that drives professional development Ability to enter and grow within the technology industry Work in a collaborative environment Be part of a high-performance team What We Have To Offer Benefits: Fully flexible for you to choose what is important Retirement: Defined Benefits Retirement Plan & Group Registered Retirement Savings Plan (RRSP) Financial Perks: Employee Stock Purchase Plan & numerous corporate discounts Personal and Family Programs: Physical Wellness Plan & Supplementary Maternity Plan Work-Life Balance: Flextime & California Fridays all year Fun at work: social and community events all-year round! Your Mission As a Cybersecurity Risk Manager, your mission is to lead and mature the cybersecurity risk management program by identifying, assessing, treating, monitoring and communicating cybersecurity risks that may impact CAE’s operations, technologies and business objectives. Your Role & Main Responsibilities Lead and mature the cybersecurity risk management program, including risk identification, assessment, treatment, monitoring and reporting. Maintain the enterprise cybersecurity risk register and ensure risks, issues, exceptions and mitigation plans are documented, tracked and regularly reviewed. Conduct cybersecurity risk assessments for projects, technologies, third parties and business initiatives, and provide practical risk-based recommendations. Partner with business and technology stakeholders to define risk treatment plans, clarify ownership, track remediation progress and support risk acceptance decisions. Prepare clear risk reporting, dashboards and executive summaries to support informed decision-making by cybersecurity leadership and governance committees. Support the development and continuous improvement of risk methodologies, scoring models, control expectations and governance processes aligned with industry frameworks. Monitor key risk indicators, emerging threats and control gaps, and translate them into actionable insights for stakeholders. Advise project teams on cybersecurity risk requirements and ensure risks are identified early, assessed consistently and managed throughout the project lifecycle. Contribute to risk awareness, governance routines and performance indicators that strengthen the Governance, Risk and Compliance function. Your Qualifications Soft skills Want to be in a performing team Show Initiative & leadership Be customer orientated Display a sense of collaboration (teamwork) & interpersonal skills Ability to influence Technical skills Bilingualism (French and English) is required A minimum of seven (7) years experience in IT Security or Cybersecurity In-depth knowledge and experience in IT Security and Telecommunications In-depth knowledge risk analysis methodologies and security standards (e.g. ISO, NIST) Industry-recognized certification (CISSP, CISA, CIRISC, CISM) would be considered an asset Knowledge about threat modeling methodology Aerospace industry knowledge would be considered an asset At CAE, connecting with people is very important. If you have any questions on this career opportunity, please do not hesitate to contact Didier Avignon, Talent Acquisition Specialist and ([email protected]) or Rémi Beauregard, Head of Cybersecurity Governance, Risk and Compliance ([email protected]). About CAE At CAE, our mission is clear: to help make the world a safer place. For nearly 80 years, we’ve driven innovation in simulation, training, and mission readiness to support critical operations worldwide. By leveraging advanced technologies, we empower our customers to operate smarter, faster, and more sustainably. Join a purpose-driven organization where bold ideas are encouraged, collaboration drives progress, and your growth fuels our shared success. Position Type Regular Equal Opportunity & Accommodations CAE is committed to providing equal opportunities to all applicants, regardless of race, nationality, color, religion, sex, gender identity or expression, sexual orientation, disability, neurodiversity, veteran status, age, or other characteristics protected by law. We encourage applicants who may not meet every qualification to apply. Reasonable accommodations are available—contact your recruiter or email [email protected] if needed. Data Privacy Privacy Statement | CAE As part of our process, we may use AI‑supported tools to help review applications, with human decision‑making at every step. CAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.

What you’ll do

Lead and mature the cybersecurity risk management program by identifying, assessing, and monitoring risks to CAE's operations and technologies. Maintain the enterprise risk register and partner with stakeholders to define treatment plans and provide executive risk reporting.

Requirements

Requires a minimum of seven years of experience in IT security or cybersecurity with in-depth knowledge of risk analysis methodologies and security standards like ISO and NIST. Bilingualism in French and English is required, and industry certifications such as CISSP, CISA, CRISC, or CISM are considered assets.

Benefits

• Defined Benefits Retirement Plan • Group Registered Retirement Savings Plan (RRSP) • Employee Stock Purchase Plan • Corporate Discounts • Physical Wellness Plan • Supplementary Maternity Plan • Flextime • California Fridays

Listed skills

  • LeadershipPreferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cybersecurity Risk Management
  • Risk Assessment
  • Risk Identification
  • Risk Treatment
  • Risk Reporting
  • ISO Standards
  • NIST Framework
  • Threat Modeling
  • IT Security
  • Telecommunications
  • Governance Risk and Compliance
  • Stakeholder Management
  • Bilingualism (French and English)
  • Leadership
  • Collaboration
  • Influence

Job areas

  • Security & Safety
  • Technology
  • Engineering
  • Management & Leadership
  • Manufacturing

Additional details

Minimum education
Professional degree
Minimum experience
5+ years
Apply by
Sep 25, 2026
Posting language
English
Working hours
40 hours per week
Seniority
Mid-Senior level