Archived listing. The details below describe a past opening.
Position Overview
Location: Greater Toronto Area (GTA), Ontario
Employment Type: Full-Time
Work Model: Hybrid – 2 to 3 days per week onsite in the GTA
Experience: 10+ years in Cybersecurity
We are seeking an experienced Senior Manager – Continuous Threat Exposure Management (CTEM) to lead enterprise cybersecurity initiatives focused on vulnerability management, exposure management, and proactive cyber risk reduction.
The ideal candidate will have 10+ years of cybersecurity experience, with a strong foundation in enterprise Vulnerability Management (VM) and demonstrated experience transitioning into Exposure Management and/or Continuous Threat Exposure Management (CTEM).
This is a senior, client-facing role requiring a combination of cybersecurity expertise, program leadership, stakeholder management, and strong communication skills. The successful candidate will work closely with client cybersecurity leadership, technical teams, business stakeholders, and technology partners to design and operationalize CTEM programs.
Key Responsibilities
- Lead the planning, design, implementation, and operationalization of enterprise CTEM programs.
- Assess existing vulnerability management programs and help organizations evolve toward a risk-based exposure management model.
- Lead continuous exposure discovery, assessment, prioritization, validation, remediation, and reporting initiatives.
- Establish processes for prioritizing vulnerabilities and exposures based on exploitability, asset criticality, business impact, threat intelligence, reachability, and compensating controls.
- Work with security and infrastructure teams to improve remediation processes and accelerate vulnerability reduction.
- Integrate CTEM processes with existing cybersecurity technologies and programs, including vulnerability management, EDR/XDR, SIEM, IAM, cloud security, application security, CMDB, threat intelligence, and ITSM.
- Facilitate workshops and working sessions with client cybersecurity, infrastructure, cloud, application, network, and risk teams.
- Define CTEM operating models, workflows, governance, KPIs, KRIs, dashboards, and reporting.
- Track exposure and remediation trends and communicate risk reduction and program effectiveness to leadership.
- Lead client presentations, executive discussions, technical workshops, and project status meetings.
- Manage stakeholder expectations, project risks, dependencies, deliverables, and timelines.
- Provide guidance and mentorship to cybersecurity analysts, consultants, and technical team members.
- Support the development of CTEM methodologies, best practices, and reusable delivery frameworks.
Required Qualifications
- 10+ years of professional cybersecurity experience.
- Strong hands-on and program-level experience in Vulnerability Management.
- Demonstrated experience with Exposure Management, CTEM, Risk-Based Vulnerability Management (RBVM), or Attack Surface Management.
- Experience leading enterprise cybersecurity projects or transformation initiatives.
- Strong understanding of the CTEM lifecycle, including:
- Scoping and asset discovery
- Exposure identification
- Risk-based prioritization
- Attack-path and exploitability analysis
- Exposure validation
- Remediation management
- Continuous reassessment and reporting
- Understanding of CVE, CVSS, EPSS, CISA KEV, threat intelligence, exploitability, asset criticality, and risk-based prioritization.
- Familiarity with cloud, endpoint, identity, network, application, and infrastructure security.
- Experience integrating cybersecurity processes with ITSM platforms such as ServiceNow or similar technologies.
- Strong project and program management capabilities.
- Excellent written and verbal communication skills.
- Strong presentation, facilitation, and stakeholder-management skills.
- Demonstrated ability to communicate technical cybersecurity risks and recommendations to both technical teams and senior executives.
- Ability to manage multiple stakeholders and work effectively in complex enterprise environments.
- Must be able to work onsite in the Greater Toronto Area 2–3 days per week.
Preferred Qualifications
- Experience implementing or operating a formal CTEM program within a large enterprise or public-sector organization.
- Experience with attack-path analysis, Breach and Attack Simulation (BAS), penetration testing, or exposure validation.
- Knowledge of cybersecurity frameworks such as NIST CSF, CIS Controls, ISO 27001, and related security standards.
- Experience working in regulated industries, financial services, government, utilities, healthcare, or critical infrastructure.
- Relevant certifications such as CISSP, CISM, CRISC, CCSP, GIAC, or equivalent are considered an asset.
Ideal Candidate
The ideal candidate is not simply a traditional vulnerability management professional. We are looking for someone who understands how the industry is evolving from identifying and patching vulnerabilities toward continuous, business-risk-driven exposure management.
You should be comfortable leading conversations with CISOs and cybersecurity leaders while also being able to work directly with vulnerability management, SOC, infrastructure, cloud, application, and remediation teams.