×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Specialist - Cyber Risk & Compliance

Job in Toronto, Ontario, C6A, Canada
Listing for: Caatpension
Full Time position
Listed on 2026-01-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below
Senior Security Specialist - Cyber Risk & Compliance page is loaded## Senior Security Specialist - Cyber Risk & Compliance remote type:
Hybrid locations:
Toronto, ONtime type:
Full time posted on:
Posted 3 Days Agojob requisition :
JR100095

At CAAT, we’re passionate about what we do. And it shows!

Here, you’ll find a cultural spark in everything we do – from the way we partner with members and employers, to the way we work, collaborate, and grow. It doesn’t just feel different  
* is* different. We’re one of the fastest-growing pensions in the country for a reason. We challenge the status quo, making a real impact on the hundreds of employers we serve – from education institutions to major corporations and household brands. And we’re just getting started. Driven by core values and a shared purpose, we’re fierce champions for better retirement security, known for our can-do culture where everyone plays a role in bringing our vision to life.

If this sounds like a fit, we’d love you to be a part of it.

*
* About the Role:

** We are seeking a
** Senior Security Specialist, Cyber Risk and Compliance,
** for our Technology & IT Services Management team. Reporting to the  Senior Manager GRC, you will be responsible for executing and advancing CAAT’s cybersecurity and technology risk programs.

The successful incumbent possesses technical depth with execution focused on managing cybersecurity risks to ensure CAAT remains secure, compliant, and resilient amid rapidly evolving threats, risks while ensuring compliance with regulatory obligations and alignment with CAAT’s Enterprise Risk Management (ERM) and Cybersecurity framework.
** As the Newest Member of our Team, You’ll:
*** Perform technical Threat risk assessments (TRA) and conduct threat modeling assessments across key applications, infrastructure, and AI/ML systems.
* Maintain and update the cyber risk register, ensuring accurate documentation and tracking of risks and remediation activities.
* Assess risks associated with AI/ML integrations, GenAI platforms, emerging technologies, quantum readiness, and synthetic data use.
* Prepare dashboards, KPIs, KRIs, and security performance scorecards for governance reporting.
* Collaborate with Dev Sec Ops , Engineering, Architecture, Legal, and Compliance teams to provide second-line oversight and challenge.
* Produce detailed technical findings and recommendations for stakeholders, including auditors and governance committees.
* Operationalize AI-driven (GenAI, Agentic AI, etc) platforms controls for compliance with ISO 27001, PCI-DSS, NIST 800-53, ISO/IEC 42001, NIST AI Risk Management Framework & other regulations.
* Perform vendor risk reviews for vendors, including emerging tech partnerships, including LLM plugin providers, API suppliers, and federated data platforms.
* Support the Senior Manager in reporting on the performance of the Information Security Management System (ISMS) to the Information Security Advisory Board (ISAB)
* Support the Senior Manager in creating executive or board level presentations to provide a view on the Cyber and Technology risk profile.
** To Succeed, You Bring:
*** At least 10+ years of experience in cybersecurity risk management, compliance, and governance, with strong hands-on audit execution and control implementation.
* At least 8+ years of experience managing audit readiness (ISO 27001, SOC 2, PCI-DSS, and NIST etc) and cyber risk in regulated industries (pension, financial services, insurance etc.)
* CISSP or CISM, CISA, ISO 27001 Lead Implementer/Auditor certification required.
* Strong knowledge of frameworks such as ISO 27001/27005, NIST CSF, NIST 800-53, NIST AI RMF, COBIT, COSO, CSA CCM, MITRE ATT&CK, MITRE ATLAS, and FAIR.
* Effective communication skills, with the ability to influence across levels and teams within the organization
* Knowledge of the Pension Administration and/or Financial Services industry would be an asset

At CAAT, we believe innovation, passion, and purpose are ingredients for a great work environment. We’re incredibly proud of our people and the remarkable impact they have as catalysts for change. We’re committed to attracting and keeping great talent, which means…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary