Senior Manager, Technology Risk
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
We’re a vibrant, exciting credit union that lives its "profits with a purpose" philosophy in every financial transaction, product, interest rate, and community initiative
we offer
. Founded in 1954, DUCA has grown from a single branch credit union in Toronto to 19 branches across Southern Ontario with over 85,000 Members we are proud to serve.
We exist to help People, Businesses and Communities Do More, Be More, and Achieve More.
DUCA is looking for a Senior Manager, Technology Risk to join our growing team
Job Purpose & Summary
As an integral part of DUCA’s Risk Management team, the Senior Manager, Technology Risk is responsible for supporting the effective management and independent risk oversight of Information Technology (IT), Information Security, Cybersecurity, Operational Resilience, and Emerging Technology risks across the organization. The role provides second line of defense to technology risk management practices, ensuring technology risks are identified, assessed, monitored, mitigated, and reported in accordance with DUCA’s risk appetite, internal policies, and regulatory expectations.
The Senior Manager, Technology Risk partners closely with Technology, Information Security, business stakeholders, Internal Audit, and regulators to support the management of risks related to cybersecurity, cloud services, operational resilience, AI and emerging technologies, IT operations, third-party technology providers, system availability, change management, technology currency, and data protection.
This position supports the ongoing enhancement of DUCA’s Technology Risk Management Framework and contributes to compliance with applicable FSRA guidance, cybersecurity expectations, operational resilience requirements, and industry best practices.
Key Accountabilities & Duties
Technology Risk Governance & Oversight
- Support the development, implementation, maintenance, and continuous enhancement of DUCA’s Technology Risk Management Framework, policies, standards, procedures, methodologies, and reporting processes. Provide independent risk oversight and effective challenge of first-line technology and cybersecurity risk management activities to ensure technology risks are identified, assessed, managed, monitored, and reported within approved risk appetite and regulatory expectations.
- Partner with Technology, Information Security, Internal Audit, Compliance, and business stakeholders to strengthen governance processes, promote sound risk management practices, and support a strong risk culture across the organization.
Technology Risk Assessment & Monitoring
- Provide risk oversight, guidance, and effective challenge of technology and information security risk assessments conducted by Technology, Information Security, and business stakeholders across IT infrastructure, applications, cloud and SaaS environments, cybersecurity controls, AI and emerging technologies, third-party technology providers, operational resilience activities, disaster recovery capabilities, and technology change initiatives to ensure risks are appropriately identified, assessed, and managed.
- Evaluate risks related to system availability, operational stability, technology currency and end-of-life platforms, cybersecurity threats, data protection, access management, privacy, operational disruptions, and technology transformation initiatives. Assess the design and operating effectiveness of controls, challenge risk mitigation strategies and risk acceptance decisions, and maintain technology risk registers, issues, and remediation plans to support ongoing risk management and reporting.
Cybersecurity & Operational Resilience Risk Oversight
- Provide risk oversight and effective challenge of key technology and cybersecurity risk management processes, including IT incident management, cybersecurity incident response, vulnerability management, privileged access management, patch management, IT change management, technology currency management, technical debt management, and risks associated with end-of-support and end-of-life technologies.
- Assist in the oversight of operational resilience, business continuity, and disaster recovery programs by reviewing resilience assessments, recovery capabilities, technology dependencies, scenario testing results, and remediation activities designed to strengthen the organization’s ability to withstand and recover from disruptive events.
Third-Party Technology & Cloud Risk Management
- Review and challenge technology vendor, cloud service provider, and outsourced technology risk assessments, including security reviews, SOC reports, operational resilience capabilities, disaster recovery arrangements, data protection controls, and contractual risk provisions to ensure risks are appropriately identified, assessed, and managed throughout the vendor lifecycl