Manager of Cyber Risk Advisor (Managed Risk)
Sophos · Ottawa, Canada
About The Role
Join Sophos, a global leader in cybersecurity, as the Manager of Cyber Risk Advisor. In this senior-level role, you will combine your deep technical expertise in exposure management with hands-on people leadership. You will deliver an exceptional managed service experience to a portfolio of customers while mentoring and managing a team of Cyber Risk Advisors. Your responsibilities will include leading complex advisory engagements, interpreting vulnerability and attack surface data, and providing prioritized, context-driven remediation guidance. You will also coach team members, oversee workload distribution, conduct regular 1:1s, contribute to hiring, evaluate performance, and act as an escalation point for both customers and colleagues. Strong communication skills are essential, as you will be presenting to CISOs and diving into raw scan data with IT teams.
- Lead and manage a team of Cyber Risk Advisors, overseeing workload distribution, conducting regular 1:1s, and providing ongoing coaching and feedback.
- Serve as a senior-level, trusted Cyber Risk Advisor for a portfolio of customers, leading high-stakes Cyber Risk Advisory sessions and providing prioritized, context-driven remediation recommendations.
- Track and report on service-level and individual performance KPI metrics, providing clear visibility to the Director of Operations and relevant stakeholders on team output, customer outcomes, and areas for improvement.
- Experience owning or contributing to service delivery processes and operational metrics
- Deep knowledge of vulnerability management, attack surface management (reduction), and common security frameworks (NIST, CIS, ISO, MITRE ATT&CK)
- 5+ years of experience in cybersecurity, with at least 1–2 years in a team lead, senior advisor, or people management role
- Hands-on experience with EASM/IASM tools, vulnerability scanning platforms (e.g., Tenable, Qualys), and remediation workflows
- Proven ability to manage multiple customer relationships simultaneously, balancing strategic advisory with timely escalation of critical risks
- Exceptional communication and advisory skills — fluent in both executive-level narratives and deep-dive technical discussions
- A collaborative leadership style with a proactive, problem-solving mindset and a genuine drive to help both customers and colleagues succeed
- Strong knowledge of enterprise networking concepts (routing, switching, VLANs, firewalls, VPNs, and remote access technologies)
- Demonstrated ability to lead, coach, and develop technical teams in a managed service environment
- Experience presenting to and influencing C-suite and board-level stakeholders
- Industry certifications such as CISSP, CISM, OSCP, CEH, or Security+; networking credentials such as CompTIA Network+ or equivalent
- Prior experience in a managed security service provider (MSSP) or consultancy, including exposure to customer success or account management functions
- Background in Incident Response, Threat Intelligence, or Red/Blue Team operations
- Knowledge of cloud security (AWS, Azure, GCP) and securing hybrid and multi-cloud environments
- Hands-on experience with Tenable Nessus and/or the Tenable One platform
- At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply
This listing was posted by a verified recruiter at Sophos. Report this listing
JobSpring