YYZ - Senior Manager, Cybersecurity & GRC - FT (4929)
Cargojet
Job at a glance
Accelerate your career with the most awarded Air Cargo Airline in Canada! Cargojet is Canada's leading provider of time-sensitive overnight air cargo services and carries over 1,300,000 pounds of cargo each business night. Cargojet operates its network across North America each business night, utilizing a fleet of all-cargo aircraft Cargojet has been awarded one of Canada’s 50 Best Managed Companies as well as being awarded the Shipper’s Choice Award for the best Air Cargo Carrier in Canada for the past number of years.
Being part of Cargojet will allow you to become a part of a diverse and vibrant family at the leading edge of the air cargo industry both domestically and internationally. Cargojet team members are dedicated, hardworking, and have a strong sense of leadership and commitment. Primary Objective Of The Position The primary objective of this role is to provide strategic leadership for the organization's cybersecurity program by proactively monitoring emerging cybersecurity trends, technologies, and evolving threat landscapes.
The role is responsible for establishing and advancing cybersecurity governance, risk management, compliance, and security initiatives to protect organizational assets, ensure regulatory compliance, and drive continuous improvement of the overall security posture. This role serves as a trusted cybersecurity advisor to IT leadership and Executive Management, translating complex cybersecurity and technology risks into clear business priorities, strategic recommendations, and actionable plans.
The position is responsible for leading the organization's cybersecurity strategy, governance, risk management, and compliance (GRC) program while providing oversight of security operations, incident response, cyber resilience, cloud security, third-party risk management, and the secure adoption of artificial intelligence (AI) and other emerging technologies. Through proactive risk management and strategic leadership, the role ensures the organization's cybersecurity posture remains resilient, compliant, and aligned with business objectives.
Job Duties Develop and execute a multi-year cybersecurity strategy, roadmap, and operating model aligned with business objectives and enterprise risk. Lead the Cybersecurity Governance, Risk & Compliance (GRC) program, including risk assessments, risk registers, policies, controls, remediation, and executive reporting. Lead cybersecurity strategy for the secure adoption of Artificial Intelligence (AI), Generative AI, machine learning, and other emerging technologies.
Assess and manage cybersecurity, privacy, data, and third-party risks associated with AI-enabled technologies and emerging technology platforms. Establish security and governance requirements for the responsible use of AI and Generative AI, including data protection, access controls, model security, monitoring, and risk management. Identify opportunities to leverage AI and automation to enhance threat detection, security monitoring, incident response, vulnerability management, and security operations.
Monitor emerging cyber threats and attack techniques involving AI and develop appropriate controls, detection capabilities, and response strategies. Partner with technology, data, privacy, legal, and business teams to establish secure-by-design principles for AI and emerging technologies. Advise CIO, IT leadership, executive management, and other senior stakeholders on cybersecurity and technology risk.
Support Executive and Board-level reporting on cybersecurity posture, risk, compliance, and strategic initiatives. Lead cybersecurity compliance, audit, customer security assessments, and regulatory reviews. Establish cybersecurity KPIs/KRIs and metrics to measure risk, control effectiveness, maturity, and program performance. Develop cybersecurity priorities, budgets, business cases, and investment plans.
Provide executive oversight of cyber incident response, cyber resilience, tabletop exercises, and major i