Senior Manager Governance, Risk

3 weeks ago


Toronto ON MC, Toronto, Canada Canadian National Railway Full time
At CN, we work together to move our company-and North America-forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and safely and our employees can focus on value-added tasks. You will be able to develop your skills and career in our close-knit, safety-focused culture working together as ONE TEAM. The careers we offer are meaningful because the work we do matters. Join us

Job Summary

The purpose of this role is to establish and maintain an industry leading Governance, Risk & Compliance (GRC) practice, develop & mentor a team, and develop policies, standards, risk registries and metrics to comply with business and regulatory requirements and build resilience in people, systems and data to enable CN to reach strategic goals and objectives in the face of evolving cyber threats.

Main Responsibilities
Leading Others

Partner with HR to maintain and bring new talent to the organization by determining which skills and roles will be required in the future, supporting, and demonstrating diversity and inclusion, and by making thoughtful hiring decisions

Provide a positive and welcoming onboarding experience to all new employees by ensuring they have access to the tools and resources needed to fulfill the requirements of their job

Recognize employee milestones (service awards, retirements, etc.) as well as significant contributions and enhanced responsibilities

Focus on communications and foster collaboration by regularly providing updates to teams about ongoing initiatives and encouraging teams to work together to accomplish common goals and learning

Manage employee performance to enable potential and ensure employees not meeting expectations are identified and supported through the performance improvement process

Create and enable a positive and engaging work environment by ensuring individual strengths are uncovered and leveraged through frequent and focused conversations - collaborate, coach, and build connections with employees

Participate in succession planning by contributing to the yearly talent review cycle and identifying employees with the potential to move up the management and expertise paths

Support employee development by having regular career conversations with all employees (documented and tracked) and supporting them in reaching their career goals

Ensure knowledge is preserved through cross-training for key skill sets in the team (knowledge transfer)

Governance, Risk & Compliance (GRC) Practice Development

Direct and put in place the proper GRC organizational structure and practices to track and manage information and cyber risk for both IT and OT (Operational Technologies) environments and ensure compliance while enabling the business for digital transformation. Incorporating behavioral change as a key risk management strategy with security awareness training and testing.

Ensure the GRC processes are sustainable and properly documented

Maintain and build relevant, current, valid and reliable team knowledge related to governance, risk and compliance programs and practices.

Advance team accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members

Ensure the full documentation and timely updates of policies, standards, guidelines, risks, exceptions, management action plans, and GRC processes through clear diagrams and well-written documents

GRC Continuous Improvement

Collaborate with the CISO, cybersecurity team, portfolio managers, architects, business and I&T leadership to understand the business direction and consequent impact on the security posture and risk appetite

Monitor threat intelligence sources, Security Operations Center (SOC) reports, vulnerability management reports, internal audit reports, regulatory changes, industry reporting and business impact analysis to accurately identify and articulate the risk priorities and implement appropriate controls to maintain an appropriate security posture

Engage the cybersecurity vendor ecosystem to understand capabilities and limitations to drive improvements in the security posture of current products, and assist in the selection of the right partners

Continuously monitor and evaluate the environment, including third party risk and subsidiaries, through self-assessments and independent security reviews as well as metrics against the framework. Identify deficiencies and inefficiencies and initiate improvement actions though engaging leadership and architecture.

Working Conditions

Occasional business travel (Canada and US) in accordance with CN policy

Requirements
Experience

Minimum 15 years overall work experience in audit, IT sales, or IT delivery

Minimum 10 years experience in IT audit or IT governance, risk and compliance

Minimum 5 years experience in managing IT governance, risk and compliance

Railroad, transportation, or Global industrial experience is a significant plus (asset)

Education/Certification/Designation

Bachelor's degree in Computer Science, Business Administration, System Analysis or other relevant field (or) an additional 5 years of relevant experience.

At least one recognized cybersecurity certification appropriate for GRC: e.g. Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Privacy Professional (CIPP), Certified in Risk and Information Systems Control (CRISC), etc.

Competencies

Demonstrated capability to understand the security implications of complex business operations and how they are linked to technological or process solutions that provide practical risk mitigation and business enablement

Significant experience in applying a structured approach to problem resolution in large, geographically dispersed organizations with 24/7 operations

Proven collaborative leadership and teamwork aligning to strategic business objectives

Excellent written and verbal English communication skills with French highly desirable, able to interact with a broad cross-section of personnel to explain risks and enforce security measures

Detail-oriented self-starter with a high level of commitment and personal motivation

Knack for prioritizing tasks and working in a fast-paced, Agile environment

Technical Skills/Knowledge

Knowledge and practical experience applying standards, frameworks, regulations, and legislation governing information security and privacy, e.g. NIST, ISO 27001, COBIT, SOX, PIPEDA

Knowledge and general understanding of IT and OT security controls and control models.

Knowledge of data classification, security policies and standards, strategic threat intelligence, threat modeling, vulnerability management, risk assessments, third party risk programs, risk management techniques, risk registries, regulatory compliance, security awareness training and testing, security metrics, security enforcement, and other relevant GRC areas of practice.

This position is posted as a grade LEVEL 5. For internal candidates, note that the grade level of the position may adjust based on the employee's experience.

About CN

CN is a world-class transportation leader and trade-enabler. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. As the only railroad connecting Canada's Eastern and Western coasts with the Southern tip of the U.S. through a 19,500 mile rail network, CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN is committed to programs supporting social responsibility and environmental stewardship. At CN, we work as ONE TEAM, focused on safety, sustainability and our customers, providing operational and supply chain excellence to deliver results.

For internal candidates, note that the grade level of the position will depend on the employee's experience.

CN is an employment equity employer and we encourage all qualified candidates to apply. We thank all applicants for their interest, however, only candidates under consideration will be contacted. Please monitor your email on a regular basis, as communication is primarily made through email.

  • Toronto, Ontario, M3C, Toronto, Canada TD Bank Full time

    Work Location:Toronto, Ontario, CanadaHours:37.5Line of Business:AuditPay Details:We're committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions, including pay details for this role.Job Description:Department...

  • Orthodontist

    3 weeks ago


    Toronto, ON, M3C, Toronto, Canada Arthur Marshall Inc Full time

    Would you like to work two days a week in an orthodontic practice in Toronto? Established group that operates 13 clinics in and around Toronto Generous daily rate with quarterly bonuses Mentoring available for younger providers Fully-staffed clinics with top-of-the-line equipmentIf you are open to a new orthodontic opportunity in their clinic in the...

  • Project Manager

    4 weeks ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Matchtech North America Full time

    Project ManagerLocation: Toronto, Canada (other locations within Canada will be considered) - hybrid remote workingPermanent PositionThe RoleWe have an exciting opportunity for a Project Manager to join our North America team.The role is to work with our engineering and assurance teams to manage a wide range of projects, including budget management,...

  • Project Manager

    4 weeks ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Hays Full time

    As a High-Rise Project Manager, you’ll play a pivotal role in overseeing the successful execution of high-rise construction projects for our well known residential developer out of Toronto, Ontario. Your expertise will shape iconic skylines and contribute to the realization of architectural marvels. If you thrive in a dynamic environment and have a passion...


  • Toronto, ON, M5P 2N7, City of Toronto, Canada Kumaran Systems Full time

    As a Delivery Consultant with Payments Background, you will play a pivotal role in ensuring the successful implementation and delivery of our payment solutions to clients. You will be responsible for overseeing the end-to-end project management process, ensuring that projects are delivered on time, within scope, and with the highest quality. In addition to...


  • Toronto, ON, M5P 2N7, City of Toronto, Canada Martyn Bassett Associates Full time

    About the Client:Our client is a Toronto based startup helping homeowners connect with trusted professionals and better manage all of their household needs through one easy-to-use platform. Our client has ambitious goals and the funding to support their next level of growth.The Opportunity:We are looking for a Senior Product Designer who is interested in...

  • General Counsel

    4 weeks ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada IKO North America Full time

    IKO Industries Ltd. is a market leader in the manufacturing of roofing and building materials. IKO is a Canadian owned and operated business with production facilities worldwide and has many years of unparalleled success in the roofing materials industry. Quality, integrity, and trustworthiness are the values that underlie this success, and we have built...


  • Toronto, ON, M5P 2N7, City of Toronto, Canada fusionSpan Full time

    fusionSpanis a fast-growing multinational information technology services company based in the USA. fusionSpan has won numbers our awards including Best Places to Work, Inc 5000 fastest growing company in America. As a company we focus on working on interesting technologies and helping our clients provide the best experience for their members.This position...

  • Project Coordinator

    5 days ago


    Toronto, Ontario, M2N2M3, Toronto, Canada Dexion North America Full time

    We are leader in the North American material handling marketplace. We are a provider of industrial storage, building, and warehouse solutions, expertly designed and engineered to enable businesses to increase capacity, productivity, and efficiency. Our services include consultancy, planning, installation, and ongoing service and support from complete...


  • Toronto, ON, M5P 2N7, City of Toronto, Canada Aecon Group Inc. Full time

    What is the Opportunity?Faster.Smarter.Safer. This is how Aecon Utilities is committed to delivering projects. Aecon Utilities is ready to become Canada’s #1 utility construction provider and we’re looking for a Superintendent to help us get there!Reporting to the Operations Manager, the Superintendent is responsible to ensure that projects are completed...


  • Woodstock, ON, M4S, City of Toronto, Canada Soprema inc. Full time

    The Human Resources Business Partner is the main point of contact for managers and employees in his sector for all matters related to human resources management. He ensures the interface between his clientele and the various specialists (centers of expertise), by providing a value-added contribution and by promoting optimal human resources management for the...

  • Wealth Associate

    1 week ago


    Waterloo, ON, M2L, City of Toronto, Canada National Bank Full time

    A career as a Wealth Associate at National Bank is a job where you can showcase your ability to work in synergy with clients and colleagues. In this role, you will help investment advisors to stand out by offering exceptional customer service that will have a positive, long-term impact on our clients. Your job: Support investment advisors in providing...


  • Toronto, Canada BFL Canada Full time

    We offer more than a job, we offer a career! We support our employees to shape their career by encouraging continuing education and investing in training and development. We put our employees at the center of what we do to allow them to grow personally and professionally, with projects and challenges that are motivating and rewarding. We inspire people...


  • Toronto, Canada BFL Canada Full time

    We offer more than a job, we offer a career! We support our employees to shape their career by encouraging continuing education and investing in training and development. We put our employees at the center of what we do to allow them to grow personally and professionally, with projects and challenges that are motivating and rewarding. We inspire people...


  • Toronto, Ontario, Canada CN Rail Full time

    At CN, we work together to move our company-and North America-forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and safely...

  • Manager, IT Risk

    1 month ago


    Mississauga, ON, Canada Community Trust Company Full time

    Questrade Financial Group (QFG) of Companies is committed to helping our customers become much more financially successful and secure. We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about...


  • Old Toronto, Canada HomEquity Bank Full time

    Friday, May 3, 2024 WHO WE ARE HomeEquity Bank is a Schedule 1 Canadian chartered bank and the leading national provider of reverse mortgages, with a growing portfolio. As the only bank solely dedicated to serving homeowners 55 and up, we’re passionate about helping Canadian homeowners live retirement on their terms. We live that commitment every day,...


  • Old Toronto, Canada HomEquity Bank Full time

    Friday, May 3, 2024 WHO WE ARE HomeEquity Bank is a Schedule 1 Canadian chartered bank and the leading national provider of reverse mortgages, with a growing portfolio. As the only bank solely dedicated to serving homeowners 55 and up, we’re passionate about helping Canadian homeowners live retirement on their terms. We live that commitment every day,...


  • Old Toronto, Canada HomEquity Bank Full time

    Friday, May 3, 2024 WHO WE ARE HomeEquity Bank is a Schedule 1 Canadian chartered bank and the leading national provider of reverse mortgages, with a growing portfolio. As the only bank solely dedicated to serving homeowners 55 and up, we’re passionate about helping Canadian homeowners live retirement on their terms. We live that commitment every day,...


  • Toronto, ON, Canada Canadian National Railway Full time

    At CN, we work together to move our company—and North America—forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and...


  • Toronto, ON, Canada Canadian National Railway Full time

    At CN, we work together to move our company—and North America—forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and...


  • Toronto, ON, Canada Fengate Asset Management Full time

    IT Governance, Risk, and Compliance Manager This role will have an exciting opportunity to be responsible for the implementation and on-going management of an ISO 27001 program and additional IT policies and procedures. The IT Governance, Risk, and Compliance (GRC) Manager will be responsible for assessing, documenting, and strengthening the...


  • Toronto, ON, Canada Collabera Full time

    Title: Senior Manager, Enterprise Applications & GovernanceLocation: Toronto, ON. Hybrid - 1 day in office 4 days remoteFull-Time Direct HireAs the Senior Manager of Enterprise Applications & Governance at our client, your primary mission is to enhance the lives of employees, especially those living in remote mining camps, by providing robust and reliable IT...


  • Toronto, ON, Canada Collabera Full time

    Title: Senior Manager, Enterprise Applications & GovernanceLocation: Toronto, ON. Hybrid - 1 day in office 4 days remoteFull-Time Direct HireAs the Senior Manager of Enterprise Applications & Governance at our client, your primary mission is to enhance the lives of employees, especially those living in remote mining camps, by providing robust and reliable IT...


  • Toronto, ON, Canada Collabera Full time

    Title: Senior Manager, Enterprise Applications & Governance Location: Toronto, ON. Hybrid - 1 day in office 4 days remote Full-Time Direct Hire As the Senior Manager of Enterprise Applications & Governance at our client, your primary mission is to enhance the lives of employees, especially those living in remote mining camps, by providing robust and...


  • Toronto, ON, Canada EightSix Network Inc Full time

    The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households. AIR MILES collectors earn Reward Miles at more than 300 leading Canadian, global and online brands and at thousands of retail and service locations across the country. AIR...


  • Toronto, ON, Canada TD Bank Full time

    Senior Manager, Audit Governance & Control page is loaded Senior Manager, Audit Governance & Control Postuler remote type Hybride locations Toronto, Ontario time type Temps plein posted on Publié hier job requisition id R_1342429 Lieu de travail: Audit Détails de la rémunération : En votre qualité de candidat ou de candidate, nous vous...

  • Senior Audit

    7 days ago


    Toronto, ON, Canada Robertson & Company Ltd. Full time

    Our Client: Our client is a leading residential mortgage insurer renowned for offering mortgage default insurance to Canadian residential mortgage lenders. As the Manager of Enterprise Risk Management (ERM), you will play a pivotal role in developing and implementing elements to support the ERM program within our client’s organization. Reporting to the...


  • Toronto, Canada TD Bank Full time

    **TD Description** Stay current and competitive. Carve out a career for yourself. Grow with us. **Department Overview** The independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of operational risk across the enterprise. The ORM...


  • Toronto, ON, Canada Global Risk Institute Full time

    The Company The Global Risk Institute (GRI) is a premier organization that defines thought leadership in risk management for the financial industry. GRI brings together leaders from the financial services industry, academia, and government to draw actionable insights on risks globally. The organization was founded in 2010 as a result of efforts by the...

  • Senior Audit

    1 month ago


    Toronto, ON, Canada Lannick Full time

    Our client is a leader in the property services sector. They are looking for a Senior Analyst, Compliance & Risk Management who will be responsible for providing compliance and advisory services to the business in both, Canada and the USA. Reporting to the Manager C&RM, based in Canada, the Senior Analyst will fulfill their duties by collaborating with...


  • Toronto, ON, Canada TRS Staffing Solutions Full time

    TRS Staffing Solutions has exciting opportunities for a Risk Manager to work with the leading construction company in Canada. Our client is based in Toronto, ON, building some of the most impactful rail & transit projects across Canada. This is a perfect opportunity for senior level project controls professionals to work on major projects and grow within a...