Director, IT Risk, Compliance
2 days ago
The Director, reporting to the VP of Information Security & CISO, will be responsible for designing and overseeing governance frameworks to proactively identify, assess, and manage technology risks. The director will also drive enterprise IT compliance and internal controls programs to safeguard our assets against threats and meet compliance obligations.
This is a high-impact leadership role that collaborates with executives, IT leaders, risk, audit, and compliance partners across the organization to enable a security risk-informed culture.
**The Director, IT Risk, Compliance & Security Assurance will**:
**IT Risk Management & Governance**:
- Lead, develop, and execute the IT risk management and governance frameworks
- Align IT risk governance with Enterprise Risk Management (ERM) programs
- Facilitate IT risk assessments, mitigation planning, and ongoing risk monitoring
- Maintain a centralized IT risk registry with defined ownership and remediation tracking
- Provide risk governance reporting to senior leadership and stakeholders
**IT Compliance & Security Assurance**:
- Oversee IT compliance with regulatory, contractual, and legal requirements
- Lead IT responses to audits, assessments, and reviews by regulators or third parties
- Manage the IT compliance certification program and stakeholder awareness
- Partner with Legal and Compliance teams to align requirements and remediation efforts
**Information Security Assurance**:
- Champion a formal security assurance program that includes control testing, evidence collection, gap analysis, and remediation
- Validate security controls aligned to industry frameworks such as ISO, NIST, and COBIT
- Partner with architecture and infrastructure teams to confirm control effectiveness
- Provide security assurance to third-party risk management and vendor due diligence
**Internal Controls Management**:
- Maintain IT internal controls framework and ensure alignment with policies and standards
- Implement and maintain security policies, standards, and control libraries across IT
- Partner with business and technology to conduct RCSAs and document identified risk
**Reporting & Governance Oversight**:
- Report on IT risk, compliance, and security assurance to executive leadership
- Support governance forums and committees with risk insights and recommendations
- Track and report on key performance indicators (KPIs) and key risk indicators (KRIs)
**Continuous Improvement & Professional Engagement**:
- Monitor emerging security threats and regulatory trends in IT risk and cybersecurity
- Engage with industry networks and professional groups to bring in best practices
- Foster a culture of continuous improvement, transparency, and accountability
**To be successful as a Director, IT Risk, Compliance & Security Assurance with People Corporation, you will need**:
- Leadership & influence: able to lead cross-functional teams and foster collaborations
- Governance & strategy: able to design and implement enterprise governance structures
- Execution & accountability: deliver results under pressure with competing priorities
- Communication: able to communicate effectively in both business and technology context
- Analytical judgment: drive action, assess risk, and guide strategic decisions
- Integrity: demonstrates high ethical standards and professionalism
- Degree or diploma in Information Security, Computer Science, or a related field
- Industry certifications such as: CGEIT, CISA, CISM, CISSP, CRISC
- Proven experience in IT risk, compliance, governance, and security assurance programs
- Strong knowledge of control frameworks (e.g., COBIT, ISO 27001/2, NIST, ITIL)
**What’s in it for you**:
- Learn by working alongside our experts
- Extended health care and dental benefits
- A retirement savings plan with company contributions
- A suite of Health & Wellness offerings
- Mental Health programs and support for you and your family
- Assistance for the completion of industry designations
- Competitive compensation
At People Corporation we are committed to helping businesses succeed. We are a national provider of benefits, retirement, wealth, wellness, and human resource solutions. Our experts and solutions serve over 20,000 clients representing nearly 3 million Canadians. We offer customized solutions designed to fit the unique needs of businesses and their employees, members and stakeholders.
-
Director of Compliance
2 weeks ago
Winnipeg, Canada IntouchCX Full timeAbout IntouchCX IntouchCX is a global leader in customer experience management, digital engagement, and AI and automation solutions. We immerse ourselves in your world with curiosity, creativity, and innovation to deliver exceptional results. For over 20 years, we have scaled with soul to become a disruptive industry leader by building trusted long-term...
-
Director, Audit
4 days ago
Winnipeg, Canada Western Canada Lottery Corp. Full timeWestern Canada Lottery Corporation (WCLC) is seeking a dynamic and experienced Director, Audit & Risk to join our office in Winnipeg, Manitoba. The **Director, Audit & Risk** provides strategic leadership and oversight to Winnipeg-based internal audit and risk function, ensuring the organization's risk management and internal control systems are effective...
-
Cyber Security Risk
2 days ago
Winnipeg, Canada Manitoba Hydro Full time**CYBER SECURITY RISK & COMPLIANCE OFFICER** **WINNIPEG, MB** **_ Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers!_** **_ Great Benefits_** - Competitive salary and benefits package. - Defined-benefit pension plan. - Nine-day work cycle which normally results in every other Monday off, providing for a balanced approach to...
-
Ft Director, Corporate Risk
2 weeks ago
Winnipeg, Canada Manitoba Liquor and Lotteries Full time**_All Manitoba Liquor & Lotteries employees may apply. _**_Manitoba Liquor and Lotteries is committed to Diversity, Equity and Inclusion. We strive to hire a workforce that reflects the community we serve. Employment equity will be considered therefore applicants who identify as women, Indigenous people, members of racialized groups, and persons with a...
-
IT Governance Risk Compliance Officer
4 days ago
Winnipeg, Canada Manitoba Public Insurance Full timeOverview: Reporting to the Manager, Cybersecurity & IT Governance, Risk and Compliance, the IT Governance, Risk & Compliance (GRC) Officer is accountable for the daily oversight and coordination of the IT GRC function. This position ensures the consistent execution of IT risk management, compliance monitoring, and governance practices across the IT...
-
Winnipeg, Canada Manitoba Public Insurance Full timeOverview: As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes. You will work with operational teams to provide risk and compliance management...
-
Governance Risk,
1 week ago
Winnipeg, Canada WCLC Full timeIs the next step in your career, helping define, implement, and mature Cybersecurity Governance, Risk and Compliance Management Services at a data-driven organization? Are you passionate about identifying opportunities to mitigate risk ?Do you get energized guiding others through processes to identify and manage cybersecurity risks? We are looking for...
-
Commercial & Risk Director, Energy & Resources
2 weeks ago
Winnipeg, Canada Stantec Full timeOverview This is a senior leadership role: Commercial & Risk Director, Energy & Resources. The position can be based in any Energy & Resources office location in North America and may require in-office presence and travel across North America. The role partners with operations, pursuit, and project teams to guide business and legal decisions across pursuits,...
-
Commercial & Risk Director, Energy & Resources
2 weeks ago
Winnipeg, Canada Stantec Full timeOverviewThis is a senior leadership role: Commercial & Risk Director, Energy & Resources. The position can be based in any Energy & Resources office location in North America and may require in-office presence and travel across North America. The role partners with operations, pursuit, and project teams to guide business and legal decisions across pursuits,...
-
Customs Compliance Specialist
3 days ago
Winnipeg, Canada Border Brokers Full timeDescription: Border Brokers is hiring a Customs Compliance Specialist in Winnipeg, MB. This planned succession role offers a clear path into the Director of Compliance position as the current leader transitions to retirement. We’re seeking a CCS-designated professional with 6+ years’ customs brokerage experience. Competitive salary, benefits, signing...