Senior Cybersecurity Risk Manager-Sr Consultant
Telus View all jobs
- Alberta
- Permanent
- Full-time
- Provide expert guidance to team members on cybersecurity risk methodologies, communication strategies, and risk mitigation practices — fostering a culture of continuous improvement.
- Act as a trusted advisor to the CSO's office and business leaders, translating technical risk into business context and helping shape enterprise-level decisions.
- Ensure risk management practices and control measures are aligned with industry frameworks (e.g., NIST, ISO/IEC 27001) and internal governance standards.
- Support and elevate how we work, recommending improvements to our tools, templates, processes, and reporting to drive greater clarity and impact.
- Own and maintain the Cybersecurity Risk Register, providing strategic guidance to the CSO and cross-functional teams in documenting, classifying, and evaluating cybersecurity risks TAC's information systems.
- Conduct comprehensive annual risk assessments and threat risk assessments as needed, and develop clear, concise risk reporting for CSO leadership and executive stakeholders.
- Critically analyze and understand established and newly emerging risks and ensure accuracy and consistency across all assessments.
- Deliver high-quality risk evaluations and propose actionable recommendations.
- Elevate reporting and insights, using dashboards and executive summaries to ensure risk data drives meaningful conversations with senior leadership and clearly conveys our risk posture and priorities.
- Collaborate closely with risk owners and key stakeholders to support the mitigation and remediation of identified risks, following through on open actions with a balance of diligence and diplomacy.
- Partner cross-functionally with Privacy, IT, Compliance, Legal, and Product to embed cybersecurity risk thinking into early-stage design and everyday operations.
- 7+ years of cybersecurity experience, including strong hands-on risk management exposure and deep knowledge in at least two domains (e.g., cloud security, vulnerability management, GRC, product security).
- Proven leadership experience — whether you've led a team or acted as a senior peer and mentor, you know how to guide others and influence outcomes.
- Advanced understanding of risk frameworks and regulatory expectations (e.g., NIST 800 series, ISO/IEC 27001/27036, GDPR, NIS2).
- Strong stakeholder management, interpersonal skills and communicator with the ability to tailor messages to technical teams, executives, and cross-functional partners across a broad range of geographies and sectors.
- An adaptive communication style to reflect a diverse stakeholder audience across a global environment.
- Hands-on experience conducting risk and threat assessments across hybrid environments, especially cloud platforms like AWS, Google and Azure.
- Hands-on experience with GRC platforms such as AuditBoard, HelmGuard, OneTrust.
- Strong organisational skills, with the ability to coordinate and effectively self-manage your own portfolio of work, independently to ensure high quality and timely delivery.
- Pragmatic and balanced outlook relative to risk and impact with the ability to apply sound judgement.
- Strong analytical skills and attention to detail, coupled with capability to identify omissions, gaps and areas of focus.
- Professional certifications like CISSP, CRISC, CISM, or CISA