Senior Consultant, Cyber Risk Management & Transformation

BDO Canada

Ottawa

On-site

CAD 90,000 - 125,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

BDO Canada is seeking a Senior Consultant to join its Cyber Risk Management & Transformation practice in Ottawa. You will lead cybersecurity risk assessments and controls reviews, align with regulatory requirements, and guide clients on governance and risk programs.

You will manage multiple engagements, develop remediation roadmaps, and deliver executive-level insights to boards. This role emphasizes actionable risk management, strong client service, and collaboration across teams.

Qualifications

  • 5–8+ years in cybersecurity, IT risk, privacy, or related consulting.
  • Strong knowledge of industry frameworks and standards (NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FedRAMP, StateRAMP).
  • Experience leading client engagements, risk assessments, controls reviews, and regulatory compliance.
  • Excellent written, verbal, and stakeholder management skills.
  • Professional certifications such as CISSP, CISM, CRISC, or CISA are preferred.

Responsibilities

  • Lead cybersecurity risk assessments, maturity assessments, gap assessments, and control evaluations.
  • Identify, assess, and report on cyber, technology, third‑party, and privacy risks.
  • Develop roadmaps and remediation plans aligned with client objectives and risk tolerance.
  • Evaluate governance structures, risk management processes, and security controls across environments.
  • Conduct third‑party and vendor security assessments and support supply‑chain risk initiatives.
  • Prepare executive-level reports, dashboards, and strategic recommendations for leadership.

Skills

Cyber risk assessments
Stakeholder management
Governance & risk
Project management
Regulatory compliance
Presentation skills

Tools

NIST CSF
ISO 27001
SOC 2
FedRAMP
StateRAMP
CIS Controls

Job description

Putting people first, every day

BDO is a firm built on a foundation of positive relationships with our people and our clients. Each day, our professionals provide exceptional service, helping clients with advice and insight they can trust. In turn, we offer an award‑winning environment that fosters a people‑first culture with a high priority on your personal and professional growth.

Your Opportunity

We are seeking a highly motivated Senior Consultant to join our Cyber Risk Management & Transformation practice. The successful candidate will support organizations in identifying, assessing, and managing cybersecurity, technology, and privacy risks while helping clients strengthen their overall security posture and meet regulatory and compliance requirements.

Key Responsibilities
  • Lead cybersecurity risk assessments, maturity assessments, gap assessments, and control evaluations using frameworks such as NIST CSF, NIST 800-53, ISO 27001:2022, CIS Controls, SOC 2, FedRAMP, and StateRAMP.
  • Identify, assess, measure, and report on cybersecurity, technology, third‑party, and privacy risks through security reviews, audits, evaluations, and risk assessments.
  • Develop cybersecurity roadmaps, remediation plans, and target‑state operating models aligned with client business objectives and risk tolerance.
  • Assess the effectiveness of cybersecurity programs, governance structures, risk management processes, and technical controls across client environments.
  • Assess and recommend controls related to Identity and Access Management (IAM), Data Protection, Endpoint Security, Security Monitoring, Vulnerability Management, and Zero Trust Architecture.
  • Assist organizations with implementing and monitoring privacy programs to ensure compliance with regulations and standards such as PIPEDA, Quebec Law 25, GDPR, and other applicable privacy requirements.
  • Evaluate security and control requirements for new technologies, cloud implementations, digital transformation initiatives, and emerging technologies, including Artificial Intelligence (AI).
  • Conduct third‑party and vendor security assessments and support supply‑chain risk management initiatives.
  • Assess incident response, business continuity, disaster recovery, and cyber resilience programs, providing recommendations to improve readiness and response capabilities.
  • Facilitate cybersecurity workshops, risk discussions, and stakeholder interviews.
  • Develop executive‑level reports, presentations, dashboards, risk registers, and strategic recommendations for senior leadership and boards.
  • Research, pilot, and implement innovative cybersecurity and privacy solutions tailored to client objectives and business environments.
  • Provide strategic guidance on Governance, Risk, Compliance (GRC), Privacy, and Cybersecurity Program initiatives.
  • Identify opportunities to improve delivery efficiency, methodologies, and client outcomes.
  • Drive the successful completion of cybersecurity engagements while managing project plans, budgets, deliverable schedules, resources, and client expectations.
  • Support proposal development, business development initiatives, thought leadership, and client presentations.
How do we define success for your role?
  • You demonstrate BDO's core values through all aspects of your work: Integrity, Respect and Collaboration.
  • You understand your stakeholder’s industry, challenges, and opportunities; stakeholders describe you as positive, professional, and delivering high‑quality work.
  • You identify, recommend, and are focused on effective service delivery to your stakeholders.
  • You share in an inclusive and engaging work environment that develops, retains & attracts talent.
  • You actively participate in the adoption of digital tools and strategies to drive an innovative workplace.
  • You grow your expertise through learning and professional development.
Your Experience and Education
  • 5‑8+ years of experience in cybersecurity, information security, IT risk management, privacy, governance, or cybersecurity consulting.
  • Strong understanding of industry frameworks and standards including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FedRAMP, and StateRAMP.
  • Experience conducting cybersecurity risk assessments, control reviews, maturity assessments, and compliance assessments.
  • Strong understanding of cybersecurity governance, risk management, and security control frameworks.
  • Experience assessing security controls across cloud, infrastructure, application, and data environments.
  • Excellent written, verbal, presentation, and stakeholder management skills.
  • Experience delivering client‑facing consulting engagements and managing multiple concurrent projects.
  • Strong analytical, problem‑solving, and project management capabilities.
Professional Certifications (One or More Preferred)
  • CISSP
  • CISM
  • CRISC
  • CISA
  • ISO 27001 Lead Implementer/Lead Auditor
  • PMP
Equal Opportunity

We are committed to creating a workplace where employees can participate fully, contribute meaningfully and succeed without barriers. We are dedicated to fostering a workplace defined by respect, fairness, and a true sense of belonging for everyone. We recognize and celebrate the unique experiences, identities, and perspectives that each of us bring, and these experiences strengthen how we work together.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant, Cyber Risk Management & Transformation
Senior Consultant, Cyber Risk Management & Transformation

BDO Canada • Toronto

On-site
CAD 100,000 - 140,000
Consultant/Senior Consultant, Risk Advisory Services
Consultant/Senior Consultant, Risk Advisory Services

BDO Canada • Vancouver

On-site
CAD 68,000 - 104,000
Senior Consultant, Risk Advisory Services
Senior Consultant, Risk Advisory Services

BDO Canada • Ottawa

Hybrid
CAD 68,000 - 104,000
Manager, Privacy Compliance Advisory
Manager, Privacy Compliance Advisory

BDO Canada • Toronto

Hybrid
CAD 88,000 - 134,000
Comprehensive benefits from day one
Professional development opportunities
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Bell • Toronto

Hybrid
CAD 120,000 - 180,000
Competitive salary
Comprehensive benefits package
Medical, dental, vision and mental健康
+2
Senior Consultant, Risk Advisory Services
Senior Consultant, Risk Advisory Services

BDO • Toronto

On-site
CAD 68,000 - 104,000
null
Cyber Compliance Consulting Associate - Summer 2027
Cyber Compliance Consulting Associate - Summer 2027

rsm • Toronto

On-site
CAD 65,000 - 90,000
Cyber Compliance Consulting Associate - Summer 2027
Cyber Compliance Consulting Associate - Summer 2027

RSM US LLP • Toronto

On-site
CAD 62,000 - 74,000
Competitive benefits
Senior Leader, Cyber Risk Management
Senior Leader, Cyber Risk Management

Capco • Toronto

On-site
CAD 120,000 - 160,000
100% company-paid health, life, and disability insurance
Retirement Savings Program (RRSP) with employer matching
Company-paid virtual health care program
+5
Manager, Risk Advisory Services
Manager, Risk Advisory Services

BDO Canada • Montreal (administrative region)

On-site
CAD 90,000 - 130,000