Montreal’s CISOs to Watch: Securing Quebec’s Critical Systems

Related

Share

Montreal’s security leadership protects an unusual concentration of things that cannot fail. The provincial electricity utility, the municipal government, the health and social services network for the eastern half of the island, a major university, and a commuter rail project under construction all appear in the careers below, alongside supply chain software, vertical software, and IT consulting. Several of these CISOs built their expertise inside one institution over a decade or more, which is a different pattern from cities where security chiefs move every three years.

Alexandra St-Hilaire – CISO, Hydro-Québec

Alexandra St-Hilaire leads cybersecurity for Hydro-Québec, the provincial electricity utility, covering governance, operations, and technology product management. She took the director role in September 2024, capping sixteen years inside the organisation and an unusually complete path to it. She began as an investigator on electricity theft cases with peace officer status, then advised on industrial security in the nuclear domain and in technology, then spent three years as a physical security specialist for transmission installations working to NERC CIP standards. She moved into cyber as head of security consulting expertise, coordinated emergency measures, then led the security operations centre for two and a half years, ran cybersecurity operations, and served as assistant director for cybersecurity products. She has also sat on the board of CyberEco, the Quebec non-profit working on cybersecurity talent and resilience, since October 2024.

Martin-Guy Richard – CISO, Ville de Montréal

Martin-Guy Richard has been CISO of Ville de Montréal since June 2020, running the security programme for a municipal government where reliability and public trust matter as much as the technology. He has rebuilt and scaled the cybersecurity organisation, set security architecture across cloud and on-premises environments, and is driving a shift toward agile product management and DevSecOps. His route to the seat is distinctive: he joined the city in 2016 as senior manager of AI and analytics, building that practice from the ground up and taking machine learning systems into production, and he now chairs the city’s AI governance committee and created its organisation-wide AI strategy. His twenty-seven years include enterprise and security architecture roles at CGI and Accenture, where he delivered programmes for finance, government, and defence clients.

Richard Veilleux – CISO, CIUSSS de l’Est-de-l’Île-de-Montréal

Richard Veilleux has been chief information security officer and executive manager for cybersecurity and telecommunications at the CIUSSS de l’Est-de-l’Île-de-Montréal since April 2023, leading technology risk management for the integrated health and social services network serving eastern Montreal Island. His remit covers risk methodology, regulatory compliance, and executive reporting to senior management, the board, and regulators. He came from Alstom, where he managed cybersecurity for the Réseau express métropolitain, the light rail network under construction in Montreal, overseeing every cybersecurity deliverable on the project and acting as the interface between client, certifier, operator, and maintainer. His twenty-five years include senior information security roles at Desjardins, cybersecurity direction for Randstad’s fraud division, and IT security and compliance work at Saputo, where he handled IT and OT convergence and industrial control system segregation.

Mike Popoff – CISO, Concordia University

Mike Popoff has spent more than twenty-two years at Concordia University, arriving as a systems analyst in 2004 and becoming CISO in February 2022. His remit is broader than the title suggests: alongside information security, incident response, cyber training, and risk assessment, he oversees both the Director of Client Experience and the Director of Infrastructure and Operations, making him responsible for the university’s IT infrastructure and service delivery as well as its defence. He previously spent nearly seven years as Director of IT Solutions and Experience and four as manager of information systems and technology. Before Concordia he worked as a systems analyst for the Government of British Columbia and in network support at BC Hydro.

Sev Kelian – CISO and VP of Security, Tecsys

Sev Kelian has been CISO and VP of Security at Tecsys, the Montreal supply chain software company, since January 2022. He arrived from National Bank of Canada, where he was executive director for cloud platform security, cloud adoption, and engineering. The foundation was sixteen years at Paysafe Group, where he rose from senior network and security administrator through architecture and team leadership to Director of Cloud Platform and Security Services, giving him deep grounding in payments security. Earlier he worked as a network and security consultant and sales engineer at Metafore and ESI Technologies, where he developed the first French-language Cisco firewall and routing training materials for the firm’s clients. His expertise spans AWS, GCP, and Azure alongside SOC 2, PCI DSS, FedRAMP, and ISO 27001.

Christophe Melki – CISO, Valsoft Corporation

Christophe Melki became CISO of Valsoft Corporation in May 2025, securing a group that acquires and grows vertical software businesses serving essential industries. He arrived from Lightspeed, where he spent more than seven years building the security practice from scratch, rising from senior manager of cybersecurity to Director of Information Security and growing teams across cloud security, application security, security operations, and GRC. Before moving in-house he was a senior cyber security advisor at Ivanhoé Cambridge, a security analyst at Vidéotron, and spent four years at Deloitte across Canada and France on identity and access management, penetration testing, and ISO 27001 audits. He began as a research engineer at Thales Communications working on routing protocols for public safety mesh networks, with a patent registered in his name.

Benoit Renaud – CISO, Alithya

Benoit Renaud has been CISO of Alithya, the IT and strategy consulting firm, since October 2018, bringing more than twenty-five years across national defence, federal, provincial, and municipal government, financial services, transport, and manufacturing. The decade before was spent at CGI as a security practice leader and director of consulting services, where he built and grew the cybersecurity practice while advising clients on governance, architecture, risk management, and PCI compliance. Woven through that period was a run of client-side programme work that reads as a tour of Quebec’s institutions: a security programme manager posting at Hydro-Québec, project management at Ville de Montréal, identity and access management at National Bank of Canada and Manulife, and a security programme setup at VIA Rail that delivered PCI compliance and an ISO 27001 framework. He has held the PMP since 1993.

What This Group Says About Montreal

Montreal’s security bench is built on tenure. St-Hilaire spent sixteen years inside Hydro-Québec before taking its top security job, Popoff more than twenty-two at Concordia, Kelian sixteen at Paysafe. That depth produces a particular kind of leader, one who understands the organization’s operational reality from the inside before being asked to defend it, and it suits a city whose critical systems are old, physical, and interconnected. The consultancy alumni here, most of them from CGI, supply the counterweight: pattern recognition across sectors that a single-employer career cannot provide.

Montreal is one stop in an ongoing series profiling the security leaders shaping their cities, provinces, and sectors; explore more features from across Canada below.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.