Manager, Cybersecurity

Posted:
1/16/2026, 3:54:17 AM

Location(s):
Oakville, Ontario, Canada ⋅ Ontario, Canada

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security

Workplace Type:
Hybrid

Union Tank Car Company & Procor

As a part of the global industrial organization Marmon Holdings—which is backed by Berkshire Hathaway—you’ll be doing things that matter, leading at every level, and winning a better way. We’re committed to making a positive impact on the world, providing you with diverse learning and working opportunities, and fostering a culture where everyone’s empowered to be their best.

MUST BE ELIGIBLE TO WORK IN OAKVILLE, ONTARIO WITHOUT VISA SPONSORSHIP.

MUST LIVE IN PROXIMITY TO THE OAKVILLE, ONTARIO HQ OFFICE FOR A HYBRID WORK SCHEDULE OF AT LEAST 2 DAYS PER WEEK IN OFFICE .

COMPENSATION RANGE LISTED IS IN CANADIAN DOLLARS - CAD

POSITION SUMMARY

We are seeking a hands-on technical leader to manage and grow our cybersecurity team. This role focuses on building and maintaining a robust hybrid security posture across on-premises infrastructure and Microsoft Azure cloud environments. The ideal candidate will combine deep technical expertise with proven leadership experience, driving initiatives that enhance security, compliance, and resilience across the enterprise.

PRIMARY RESPONSIBILITIES

  • Leadership & Strategy
    • Lead and mentor a team of cybersecurity professionals, fostering a culture of collaboration and continuous improvement.
    • Define and execute the cybersecurity roadmap aligned with organizational goals and regulatory requirements.
    • Act as a trusted advisor to senior leadership on security risks, trends, and mitigation strategies.
  • Hybrid Security Posture
    • Design, implement, and maintain security controls for on-premises systems and Azure cloud environments.
    • Oversee identity and access management, network security, and data protection across hybrid infrastructure.
    • Ensure compliance with industry standards (e.g., ISO 27001, NIST, CIS benchmarks).
  • DevSecOps Enablement
    • Integrate security practices into CI/CD pipelines, enabling secure software delivery.
    • Implement container security for Kubernetes and Docker environments.
    • Collaborate with development and operations teams to embed security in application lifecycle.
  • Incident Response & Risk Management
    • Lead incident response efforts, including detection, containment, and remediation.
    • Conduct regular risk assessments and vulnerability management activities.
    • Develop and maintain disaster recovery and business continuity plans.

REQUIRED SKILLS & SPECIFICATIONS

  • Technical Skills:
    • Proficiency in Azure Security Center, Defender for Cloud, and related tools.
    • Hands on experience with Cloud Security Posture Management.
    • Experience with Kubernetes, Docker, and container orchestration security.
    • Familiarity with SIEM, EDR, and vulnerability management platforms.

EDUCATION/EXPERIENCE/QUALIFICATIONS

  • Education: Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred).
  • Experience:
    • Minimum 5 years of management experience leading cybersecurity teams.
    • Cloud Security Posture Management (CSPM) tooling such as Tenable One or WIZ.
    • Proven hands-on technical expertise in hybrid environments (on-prem + Azure).
    • Background in DevSecOps, container security, and cloud-native security tools.
  • Certifications: CISSP, CISM, or Azure Security certifications preferred.

COMP RANGE FOR CANADIAN DOLLARS $129,000 - 158,000 CAD

DISCLAIMER

Please note the duties listed are not set forth for purposes of limiting the assignment of work. They are not to be construed as a complete list of the many duties normally to be performed under a job title or those to be performed temporarily outside an employee's normal line of work. Duties, and activities may change at any time with or without notice.

Following receipt of a conditional offer of employment, candidates will be required to complete additional job-related screening processes as permitted or required by applicable law.