Skip to content

Information Security Manager, M&A at WSP, Montreal

wsp jobs logoWSP·Montreal, QCfull time

Posted: July 16, 2026

Apply for this jobExpires: August 15, 2026

Browse more WSP jobs · See other jobs in Montreal

job description

AI Summary

This Information Security Manager, Mergers & Acquisitions role at WSP in Montreal, QC, focuses on driving secure business growth. Key duties involve leading security due diligence, evaluating risk, and managing integration efforts across acquisitions. Top requirements include 4-8 years in information security with M&A experience and strong project management skills.

Driving Secure Business Transformation at WSP

WSP is seeking an ambitious Information Security Manager for Mergers & Acquisitions in Montreal, QC, to play a pivotal role in shaping secure business growth. This position is crucial for ensuring that every transaction, including acquisitions, divestitures, and joint ventures, aligns with WSP’s robust security framework and risk posture. The successful candidate will collaborate extensively with Corporate Development, Legal, IT, and executive stakeholders to assess, advise, and integrate security practices within a dynamic, deal-driven environment. This role directly influences the success and resilience of strategic business initiatives across Canada, making a significant impact on WSP's overall security landscape and operational integrity. The focus is on proactively identifying and mitigating potential security risks associated with new business ventures.

Key Responsibilities and Security Integration

The Information Security Manager will lead information security due diligence activities for all mergers, acquisitions, and divestitures. This includes performing pre-acquisition security risk assessments, evaluating existing policies, controls, technologies, and the overall cyber maturity of target entities. A core aspect of the role involves identifying key security risks, liabilities, and remediation requirements, encompassing regulatory, contractual, and operational risks. The manager will coordinate security penetration testing activities with vendors and manage remediation schedules, alongside coordinating breach assessment activities in line with transaction timelines. Providing clear, actionable risk reports and executive-level summaries is essential for supporting transaction decision-making. Furthermore, this role supports deal teams in defining security-related representations, warranties, and contractual requirements, ensuring robust protection across all business activities.

Working closely with M&A Operations, the manager will develop and maintain security integration playbooks and frameworks that align with WSP standards. This involves defining Day 1 security expectations and subsequent 30/60/90-day security integration plans, covering identity, network, endpoint, data protection, and monitoring controls. Coordinating the execution of these security integration activities across IT, infrastructure, and business teams is paramount to successful transitions. The manager ensures the alignment of acquired entities to WSP’s security policies, standards, and ISO27001-aligned ISMS, tracking and reporting on integration progress, risks, and remediation activities. This ensures M&A activities are consistently aligned with WSP’s Information Security Governance framework and risk management processes, acting as the primary security advisor for all M&A initiatives.

Skills and Expertise for Risk Management

Candidates for this critical security role should possess a Bachelor’s degree in Information Technology, Computer Science, Business, Risk Management, or a related field, or equivalent practical experience. A minimum of 4–8 years in information security, IT risk, or cybersecurity is required, with at least two years specifically supporting M&A security due diligence or integration activities. Proven experience leading security risk assessments, control evaluations, and compliance activities is essential. Strong project management skills are necessary to lead multiple concurrent workstreams independently and effectively. A working knowledge of industry standards such as ISO 27001, NIST CSF, and CIS Controls is expected. Broad expertise across core security domains, including Identity and Access Management (IAM), network and endpoint security, data protection, vulnerability management, and monitoring, will be key to success. Experience in third-party and vendor risk management and security assessment methodologies is also highly valued. The role demands strong communication, stakeholder engagement, and analytical skills, with the ability to operate effectively in fast-paced environments where quick and accurate risk assessments are vital for business continuity.

categories

about wsp

similar jobs