Senior Manager, Cyber and IT Risk
7 days ago
Requisition ID: 213064
Join a purpose-driven winning team, committed to results, in an inclusive and high-performing culture.
Contributes to the overall success of Cyber & IT Risk Management, Global Risk Management (GRM) globally ensuring specific individual goals, plans, initiatives are executed/delivered in support of the team's business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations, internal policies, and procedures.
Leads expert technical risk assurance and control oversight to ensure the bank achieves its objectives while effectively managing risk. Collaborate with cross-functional teams across the first line of defense to identify, assess, and mitigate emerging risks and vulnerabilities. This role is crucial in fostering a robust risk culture and driving continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.
As part of the second line of defense, the Cybersecurity and IT Risk team provides independent oversight and challenge, and assists in developing methodologies, policies, processes, and tools to support the Cyber and IT Risk Management Framework.
Is this role right for you? In this role, you will:
1. Champion a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems, and knowledge.
2. Lead 2nd Line Challenge: Conduct comprehensive challenge to identify potential threats and vulnerabilities in the Bank's processes, systems, and operations. Partner with the 1st line of defense to develop risk mitigation strategies across key cyber and IT domains. Challenge IT and cybersecurity risks within scenario analysis and thematic reviews. Conduct cyber risk assessments, metrics, and controls within globally complex, dispersed, and diverse organizations.
3. Control Evaluation: Evaluate the design of controls and communicate the impact of control weaknesses to first line teams and control implementers.
4. Alignment Evaluation: Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
5. Framework Expertise: Be a subject matter expert in one or more industry-standard risk management frameworks (including ISO27001, COBIT, NIST) and have an in-depth understanding of cyber risk mitigation strategies.
6. Stakeholder Advisory: Advise stakeholders on risk management, controls development, and adherence to mitigate risks.
7. Risk Monitoring: Proactively monitor key risk indicators, analyze control metrics, and provide insights on risk management effectiveness to senior management, driving continuous improvement initiatives.
8. Reporting: Support monthly and quarterly IT and Cyber Risk report development for various risk committees and senior management.
9. Security Operations: Manage, assess, or audit security operations processes and technologies, including SOC, SIEM, Fusion Center, and Incident Response.
10. Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
11. Actively pursue effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to, and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions, and conduct risk.
12. Champion a high-performance environment and contribute to an inclusive work environment.
Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have experience with:
1. Strong expertise in IT Risk Management (e.g., Logical Access, Data Leakage, Disaster Recovery)
2. Experience with Cybersecurity Risk Management is preferred
3. A minimum of 7 years of experience in technology departments and/or risk management, preferably in a financial institution
4. Advanced knowledge of relevant regulatory rules (OSFI, FFIEC, NYDFS 500) and frameworks (NIST, COBIT) is preferred
5. 5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation
6. Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
7. Proficiency in data security, risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
8. Advanced knowledge of data analytics and data literacy
9. Strong understanding of IT risk management frameworks in a global banking environment.
10. Able to convey complex concepts and ideas on issues requiring interpretation and opinion.
11. Maintain in-depth knowledge of cyber and IT risks and controls across various information system architecture and engineering domains, such as data protection, application security, identity and access management, vulnerability management, change management, network security, endpoint security, logging and monitoring, and incident management. Stay actively engaged in the industry on the latest in cyber risk and emerging operational risks.
12. Demonstrate a sense of urgency in implementing programs and evaluating priorities; be decisive, action-oriented, and practical.
13. Analyze and think through highly complex issues, then appropriately execute and implement against a well-thought-through framework in a seamless manner. Be a global citizen comfortable in all geographies, regions, and cultures.
14. Demonstrate strong leadership, communication, and presentation skills, including the ability to adapt style to suit the different needs of any audience.
15. Independent in judgment and with a high standard of conduct and ethics. Able to challenge and be challenged while maintaining the highest levels of professionalism.
16. Good negotiation skills and ability to resolve conflict between teams or individuals so that functional/organizational objectives are achieved.
17. Excellent analytical skills; critical thinking and problem-solving skills.
18. Good interpersonal skills.
What's in it for you?
1. The opportunity to join a forward-thinking and collaborative team, surrounded by innovative thinkers
2. A rewarding career path with diverse opportunities for professional development
3. Internal training to support your growth and enhance your skills
4. An inclusive working environment that encourages creativity, curiosity, and celebrates success
5. Work in an Ecosystem; a bright, modern space where you'll have access to group seating, offices, collaboration spaces, a cafeteria with different options daily, a bistro, and more
Location(s): Canada : Ontario : Toronto
Scotiabank is a leading bank in the Americas. Guided by our purpose: 'for every future', we help our customers, their families, and their communities achieve success through a broad range of advice, products, and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
#J-18808-Ljbffr
-
Manager, Cyber Security
4 weeks ago
Ottawa, Ontario, Canada Employment and Social Development Canada Full timeReference number: SIF24J-085897-000113Selection process number: 24-25-SIF-EA-10969Office of the Superintendent of Financial Institutions Canada - Cyber SecurityVancouver (British Columbia), Ottawa (Ontario), Toronto (Ontario), Montréal Island (Québec)IT-04, IT-05, RE-06 - NOTE: This position is classified at the RE-06 group and level which is roughly...
-
Global Cyber Risk Leader
1 day ago
Ottawa, Ontario, Canada Scotiabank Full timeAbout the OpportunityThe Global Cyber Risk Leader will play a key role in identifying, assessing, and mitigating emerging risks and vulnerabilities in the Bank's processes, systems, and operations. Key responsibilities include:Collaborating with cross-functional teams across the first line of defense to identify and assess emerging risks and...
-
Senior Cyber Security Specialist
1 day ago
Ottawa, Ontario, Canada Diverse Lynx Full timeDiverse Lynx LLC is seeking an experienced Senior Cyber Security Specialist to join our team. As a key member of our organization, you will be responsible for analyzing and mitigating cyber security threats.Job DescriptionIn this role, you will work on various projects, including Vulnerability Management/Security, Application Security Projects, and Identity...
-
Cyber Security Manager
5 days ago
Ottawa, Ontario, Canada ipss inc. Full timeJob Title: Cyber Security ManagerDivision: Office of the Chief Information Security OfficerReports To: Director Cyber AdvisorySalary Range: $140,350.00 to $182,614.00Work Location: Toronto, OntarioJob Type: Permanent Full TimeShift Information: Monday to Friday, 35 hours work weekJOB SUMMARY:The City of Toronto is seeking a highly skilled and experienced...
-
Global Cyber Risk Auditor
2 days ago
Ottawa, Ontario, Canada Cognizant Full timeJob DescriptionAs a Senior IT Auditor at Cognizant, you will play a critical role in planning, executing, and reporting on IT and Cybersecurity audit engagements. Your responsibilities will include:Understanding engagement objectives and assisting the engagement manager in preparing the plan and testing procedures to meet the review objectives.Gaining a...
-
Senior Cyber Security Consultant
7 days ago
Ottawa, Ontario, Canada MDOS Consulting Full timeJob DescriptionWe are seeking a highly experienced IT Security Solutions Specialist to join our team at MDOS Consulting. As a key member of our team, you will be responsible for providing expert advice on information technology security matters and developing strategic plans to mitigate risks.RequirementsMinimum 5 years of experience in providing cyber...
-
Specialist Risk Management
2 weeks ago
Ottawa, Ontario, Canada ipss inc. Full timeDivision: Office of the Chief Information Security OfficerSalary Range: $122,305 to $163,639Work Location: 55 John Street, TorontoJob Type: Permanent Full TimeShift Information: Monday to Friday, 35 hours work weekJOB SUMMARY:To provide expert guidance, advice, and operational support for the City's cyber risk management program, ensuring robust protection...
-
Senior IT Risk Management Consultant
2 days ago
Ottawa, Ontario, Canada Cognizant Full timeJob ResponsibilitiesThe Senior IT Auditor supports the Engagement Manager in the planning, execution, and reporting of IT and Cybersecurity audit engagements. The responsibilities include:Understanding engagement objectives and assisting the engagement manager in preparing the plan and testing procedures to meet the review objectives.Gaining a detailed...
-
Cybersecurity Risk Management Lead
2 days ago
Ottawa, Ontario, Canada Scotiabank Full timeJob Overview:As a Cybersecurity Risk Management Lead at Scotiabank, you will play a crucial role in ensuring the bank's IT systems and infrastructure are secure and compliant with regulatory requirements. You will be responsible for identifying, assessing, and mitigating cybersecurity risks across the organization.About Us:Scotiabank is a leading bank in the...
-
Ottawa, Ontario, Canada S I Systems Full timeSr. Threat Modeling Analyst to lead the identification of Cyber security risks and ensure sufficient controls are in place to mitigate these risks for our banking clientPosition: Sr. Threat Modeling Analyst to lead the identification of Cyber security risks and ensure sufficient controls are in place to mitigate these risks for our banking clientDuration: 6...
-
Cyber PMO Lead
3 days ago
Ottawa, Ontario, Canada ipss inc. Full timeOverview of the Role:The Senior Specialist Cyber PMO will be responsible for overseeing the execution of cyber security projects, managing key deliverables such as gate processes, status reports, and risk management frameworks.This individual will establish and refine project methodologies, standards, and guidelines, continuously evaluating projects to...
-
Senior Cyber Security Strategist
3 days ago
Ottawa, Ontario, Canada ipss inc. Full timeAbout the RoleWe are seeking a highly skilled Senior Cyber Security Strategist to join our team at ipss inc. As a key member of our organization, you will play a critical role in developing and implementing effective cyber security strategies to protect our assets.Key ResponsibilitiesLead the development of comprehensive cyber security strategies to mitigate...
-
Risk Management Professional
7 days ago
Ottawa, Ontario, Canada Malleum Full timeWe are a leading provider of cybersecurity services, dedicated to helping our clients navigate the complex landscape of cybersecurity threats. Our team of experts has extensive experience in designing and implementing effective cybersecurity controls, and we're looking for a skilled Senior GRC Consultant to join our team.Key ResponsibilitiesThe successful...
-
Senior Specialist Cyber Services
3 days ago
Ottawa, Ontario, Canada ipss inc. Full timeJob SummaryThe Senior Specialist Cyber Services will provide strategic and operational guidance to the Manager Cyber Service Delivery as well as the Chief Information Security Office (CISO).This role involves defining, developing and supporting cyber programs and initiatives, engaging with teams across the organization to build alignment on key projects and...
-
Senior Specialist Cyber Finance Management
4 weeks ago
Ottawa, Ontario, Canada ipss inc. Full timeJob Title: Senior Specialist Cyber Finance ManagementDivision: Office of the Chief Information Security OfficerReports To: Manager Strategic TransformationSalary Range: $122,305 to $163,639Work Location: 55 John Street, TorontoJob Type: Permanent Full TimeShift Information: Monday to Friday, 35 hours work weekJOB SUMMARY:To provide strategic and operational...
-
Cyber Finance Management Lead
5 days ago
Ottawa, Ontario, Canada ipss inc. Full timeCyber Finance Management Role OverviewThe Office of the Chief Information Security Officer is seeking a highly skilled individual to fill the position of Cyber Finance Management Lead. This role will be responsible for providing strategic and operational guidance to senior management in establishing and maintaining a robust cyber program that ensures...
-
Ottawa, Ontario, Canada ipss inc. Full timeDivision: Office of the Chief Information Security OfficerReports To: Manager Cyber ComplianceSalary Range: $122,305 to $163,639Work Location: 55 John Street, TorontoJob Type: Permanent Full TimeShift Information: Monday to Friday, 35 hours work weekJOB SUMMARY:To support the Manager of Cyber Compliance and the Chief Information Security Officer (CISO) in...
-
Cyber Security Program Manager
3 days ago
Ottawa, Ontario, Canada ipss inc. Full timeJob OverviewThe Cyber Security Program Manager will provide strategic and operational guidance to the Manager Cyber Service Delivery as well as the Chief Information Security Office (CISO) in the execution of its mandate to establish and maintain a City-wide cyber program.This role will define, develop and support cyber programs and initiatives, engaging...
-
Manager, Cybersecurity Risk Assessment
4 weeks ago
Ottawa, Ontario, Canada CMHC Full timeThe Manager, Cybersecurity Risk Assessment, is responsible for supporting the development and implementation of cybersecurity risk mitigation strategies and monitoring cybersecurity risk levels within the organization. This role assists in identifying and assessing potential threats, ensures alignment with organizational objectives, and collaborates with...
-
Communications Manager
3 days ago
Ottawa, Ontario, Canada ipss inc. Full timeWe are seeking a skilled communications manager to join our team at ipss inc. As a key member of our cyber security team, you will play a critical role in developing and executing communications strategies to build brand awareness and boost cyber security knowledge. Your expertise will be essential in providing business advice, support, and services to all...