Director, Cybersecurity and IT Risk Management, Regulatory, Compliance, Audit

4 weeks ago


Ottawa, Ontario, Canada Scotiabank Full time
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Title: Director, Cybersecurity and IT Risk Management, Regulatory, Compliance, Audit & Issue Management

Requisition ID: 214337

Leads and oversees the execution of the bank's second line of defense (2LoD) Cybersecurity and IT strategy and roadmap within Operational Risk / Global Risk Management (GRM) globally ensuring business strategies, plans and initiatives are executed/delivered in compliance with governing regulations, internal policies and procedures.

This role leads Cyber & IT Risk transformation activities, manages regulatory change management, and supports audit and regulatory activities. A deep understanding of cybersecurity frameworks, regulatory standards, and best practices is a requirement in the role to ensure the bank's Cybersecurity and IT posture is robust and resilient.

Is this role right for you? In this role, you will:

1. Lead and drive a customer focused culture throughout their team to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
2. Lead the implementation of a comprehensive Second Line of Defense (2LoD) cybersecurity and IT strategy, governance framework and IT maturity roadmap, ensuring alignment with the bank's security posture and resilience and regulatory requirements.
3. Effectively partner with Global Cyber and Technology Risk, Internal Audit and Regulatory Relations teams to ensure that regulatory examination requirements across second lines of defense are met. Collaborate with senior leaders in Global Cybersecurity and Technology to ensure integrated activities across regulatory remediation.
4. Oversee and support internal and external audits, including documentation preparation, auditor coordination, and addressing audit findings.
5. Develop and uphold 2LoD cybersecurity and IT policies, procedures, and standards to ensure compliance and best practices.
6. Ensure that remediation activities are traceable to root causes and regulatory responses in partnership with senior leaders.
7. Review and challenge all regulatory submissions to ensure accuracy, validity, completeness, and alignment with internal Scotiabank policies, standards, and regulatory requirements.
8. Identify areas for improvement through regulatory submission reviews, communicating issues, risks, and control gaps to the broader Second Line of Defense team and subject matter experts for targeted deep dives.
9. Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
10. Create an environment in which their team pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles.
11. Build a high-performance environment and implement a people strategy that attracts, retains, develops, and motivates their team by fostering an inclusive work environment and using a coaching mindset.

Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have experience with:

1. University degree, preferably in Computer Engineering, Computer Science or related field, and a minimum of 10 years' experience in increasingly senior Information Security roles in a complex, global organization.
2. Financial services and, specifically, banking experience is mandatory.
3. Experience in driving cross functional senior executive steering committees with a global presence.
4. Professional Certification is preferred: CISA or equivalent, compliance frameworks (e.g. ISO or NIST)
5. 12+ years of related IT process experience including previous internal audit experience, external audit experience or risk assessment experience.
6. Experience with financial sector regulatory practices and second line of defense effective challenge.
7. Excellent written and verbal communication skills, with the ability to communicate security objectives and concepts to technical and non-technical stakeholders.
8. Ability to lead teams in a highly complex and matrixed organization.
9. Strong leadership and collaboration skills. Excellent oral and written communication, attention to detail and strong planning and management ability.
10. Experience with and knowledge of formal project management methodologies is desired.
11. English fluency required and Spanish preferred.

What's in it for you?

1. We have an inclusive and collaborative work environment that values curiosity & ownership, encourages pragmatic creativity, and celebrates success
2. You'll get to work with and learn from an incredibly friendly and diverse group of accomplished leaders.
3. Access to thousands of online and in-person courses so you can brush up on skills, or learn new ones.
4. Multiple career paths and innumerable progression opportunities.
5. A competitive rewards package that includes a base salary, a performance bonus, company matching programs on pension and profit sharing, paid vacation, personal & sick days, medical, vision and dental benefits that start from day one.

Location(s): Canada : Ontario : Toronto

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation during the recruitment and selection process, please let our Recruitment team know.

Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

#J-18808-Ljbffr

  • Ottawa, Ontario, Canada Scotiabank Full time

    The Cybersecurity and IT Risk Management Director will play a key role in ensuring the bank's Cybersecurity and IT posture is robust and resilient. This individual will lead Cyber & IT Risk transformation activities, manage regulatory change management, and support audit and regulatory activities.This role requires a deep understanding of cybersecurity...


  • Ottawa, Ontario, Canada Scotiabank Full time

    About the JobThis role requires a unique blend of technical and business acumen, as well as excellent leadership and collaboration skills. As Director, Cybersecurity and IT Risk Management, Regulatory, Compliance, Audit & Issue Management, you will lead and oversee the execution of our bank's 2LoD cybersecurity and IT strategy and roadmap, ensuring business...


  • Ottawa, Ontario, Canada Thumbtack Full time

    About the Cybersecurity TeamThe Cybersecurity team at Thumbtack serves as an internal cybersecurity advisory and auditing body, dedicated to preserving the confidentiality, integrity, and accessibility of information systems, identities, and data assets. Our primary objectives include offering proactive security guidance, establishing and upholding a robust...


  • Ottawa, Ontario, Canada CMHC Full time

    The Manager, Cybersecurity Risk Assessment, is responsible for supporting the development and implementation of cybersecurity risk mitigation strategies and monitoring cybersecurity risk levels within the organization. This role assists in identifying and assessing potential threats, ensures alignment with organizational objectives, and collaborates with...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    About the RoleBarracuda Networks is seeking a highly experienced Compliance Risk Manager to join our Security team. As a key member of the team, you will be responsible for leading compliance-focused programs and ensuring adherence to regulatory requirements.ResponsibilitiesCollaborate with cross-functional teams to integrate compliance requirementsDevelop...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    About Our TeamBarracuda Networks is committed to a candidate selection process and work environment that is inclusive and barrier-free. We are seeking a highly experienced Regulatory Compliance Expert to join our Security team.ResponsibilitiesCollaborate with cross-functional teams to integrate compliance requirementsDevelop and implement compliance-related...


  • Ottawa, Ontario, Canada Scotiabank Full time

    The Cybersecurity and IT Risk Management Director at Scotiabank will be responsible for leading the execution of the bank's second line of defense (2LoD) Cybersecurity and IT strategy and roadmap within Operational Risk / Global Risk Management (GRM) globally. This role is responsible for ensuring business strategies, plans, and initiatives are...


  • Ottawa, Ontario, Canada CMHC Full time

    Job Requisition ID: 10748Position Status: Permanent Full TimePosition Type: HybridOffice Location: Ottawa (ON) preferred, Montreal (QC) and Toronto will be consideredTravel Requirement: OccasionalLanguage Designation: BilingualLanguage Skill Levels (Read/Write/Speak): CBCSecurity Requirement: SecretSalary: Our salaries generally range from $99646.37 to...


  • Ottawa, Ontario, Canada Scotiabank Full time

    Requisition ID: 218289Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.PurposeAs the 3rd Line of Defence, Internal Audit provides enterprise-wide, independent, and objective assurance over the design and operations of the Bank's internal controls, risk management and governance processes. We are...


  • Ottawa, Ontario, Canada TD Bank Full time

    Audit Manager II, QAIP Global Compliance and RiskLocation: Toronto, Ontario, CanadaHours: 37.5Business Sector: AuditJob Description: As an Audit Manager II, you'll provide oversight to complex audits and ensure completion for multiple business groups. You will be managing associated working relationships with business lines as per regulatory requirements....


  • Ottawa, Ontario, Canada Canaccede Financial Group Full time

    Company InformationCanaccede Financial Group Ltd. and its subsidiaries are Canadian industry leaders in specialized investment and financial services products. Through our acquisition entities and our managing and servicing entity, Canaccede International Management Ltd., we have been working with large lenders and financial institutions in the acquisition...


  • Ottawa, Ontario, Canada Thumbtack Full time

    About the Cybersecurity TeamThe Thumbtack cybersecurity team plays a vital role in safeguarding our information systems, identities, and data assets. Our primary objectives include offering proactive security guidance, establishing a robust and secure infrastructure, and promoting a culture of security consciousness and adherence across the organization.We...


  • Ottawa, Ontario, Canada Interac Corp. Full time

    About the RoleThis position will play a key role in maintaining and enhancing audit, regulatory, and contractual compliance activities within the organization. The successful candidate will be responsible for collaborating with internal and external stakeholders to maintain the company's ISO 27001 Certification.Key ResponsibilitiesDevelop and maintain a risk...


  • Ottawa, Ontario, Canada Employment and Social Development Canada Full time

    Join our dynamic team as a Cybersecurity Risk Management Leader and take on the challenge of protecting our organization's digital assets. With your expertise in threat detection and mitigation, you will play a critical role in ensuring the security and integrity of our systems.About the Role:In this exciting position, you will be responsible for leading our...


  • Ottawa, Ontario, Canada Fidelity Canada Full time

    About This OpportunityWe are seeking a highly skilled Risk Management and Compliance Officer to join our compliance team. The successful candidate will be responsible for analyzing and mitigating risks, developing risk management plans, and conducting regular audits and reviews.Your primary focus will be on ensuring that our operations and systems are...


  • Ottawa, Ontario, Canada Scotiabank Full time

    About ScotiabankWe are a purpose-driven winning team committed to results, working in an inclusive and high-performing culture. Our team is responsible for leading the execution of our second line of defense (2LoD) cybersecurity and IT strategy and roadmap within Operational Risk / Global Risk Management (GRM) globally.As Director, Cybersecurity and IT Risk...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    Job OverviewBarracuda Networks seeks a seasoned Cybersecurity Governance Specialist to support the development of global compliance initiatives. The ideal candidate will lead compliance-focused programs, collaborate with cross-functional teams, and define strategies to ensure adherence to regulatory requirements.Key ResponsibilitiesConduct detailed risk...


  • Ottawa, Ontario, Canada Trade Ready Full time

    Compliance Officer Role:We are looking for a skilled Compliance Risk Manager to join our global trade compliance team in Ottawa, ON. The successful candidate will work closely with GTC colleagues to ensure consistent, accurate communication and implementation of trade compliance goals and objectives.Key Responsibilities:Collaborate with GTC management and...


  • Ottawa, Ontario, Canada Scotiabank Full time

    About this OpportunityWe are seeking a highly skilled and experienced professional to join our team as Director, Cybersecurity and IT Risk Management, Regulatory, Compliance, Audit & Issue Management. This role requires a unique blend of technical and business acumen, as well as excellent leadership and collaboration skills.You will be responsible for...


  • Ottawa, Ontario, Canada CMHC Full time

    About the Position">The Manager of Cybersecurity and Risk is responsible for developing and implementing cybersecurity risk mitigation strategies within CMHC. This position involves collaborating with various departments to integrate risk management practices into business operations.">Develop and implement cybersecurity risk mitigation strategies to reduce...