Senior Manager of GRC, Information Security
6 months ago
We are hiring a Senior Manager of GRC in our Information Security department
The Role:
A strategic and integral member of the Information Security Team, reporting to the AVP, Information Security, is responsible for ensuring the security, integrity, and availability of First National information assets. The candidate will contribute to the management and continuous improvement of security program(s). The position entails the development, implementation, and compliance of security control programs across the organization.
This role requires the following skills:
Specialized knowledge and experience in information security, security strategies, and security management frameworks. Knowledge and understanding of current security standards and best practices, particularly ISO 27001. Development, maintenance and review of Information Security Policy, Standards, Processes and Procedures Effective and dynamic communicator.Reporting To:
Assistant Vice President, Information Security
Full-Time/Part- Time:
Full-time
Posting Date:
March 6, 2024
Closing Date:
April 6, 2024
Hours of Work:
8:30 – 5:00
Grade:
Office Location:
Downtown Toronto
Great location Steps away from the main public transit station
What we offer:
Highly competitive compensation package which includes, base salary, bonus, benefits, and career advancement opportunities
*Eligibility for benefits is dependent on the terms of employment
What you will do:
Review and improve the Information Security Management Framework. Build strong cross-organizational relationships. Manage the security risk management and compliance strategy, framework, and approach. Advise other teams within First National in the design and implementation of effective security controls. Proactively track and communicate the status of the risk response activities.
Governance
Risk Management
Lead the Information Security Risk Management program, through evaluation of information security risks, accounting for people, processes, data, and all associated security controls. Provide oversight of all relevant information security risks, and support in risk treatment of identified risks. Assist in the third-party risk assessments process to ensure risk identification, transparency and business acceptance and contractual obligations. Ensure that all the program-specific risk assessment results, such as Data Security, IAM security, Physical Security, Security Operations, Application Security, etc. dovetail into the information security risk management program.Compliance Management
Control monitoring and review of internal security risk assessments. Develop, document, and assess measures, metrics, and internal controls related to cyber security assessments and acceptance. Develop, document, and assess measures, metrics, and internal controls related to information security assessments and acceptance. In conjunction with Legal, Privacy and Compliance, identify information management and protection laws and regulations and implement actions to ensure compliance. Ensure that the programs maintain compliance with relevant laws and regulations, as appropriate.Audit Management
Assist in all current and future security related audit and certification processes. Support audit and assessment activities, such as internal and external audit, vendor assessments, benchmarking, etc.The Requirements Needed:
A total of 10 years of experience, with a minimum of 7 years of prior information security management work experience in a medium or large size organization is required in the GRC domain. Bachelor’s degree in computer science or the equivalent work experience is required. Graduate degree preferred. Information security certifications, such as CISSP, CISM, ISO27001 or equivalent preferred. Information systems auditing certification such as CISA, or experience is desirable. Preference will be given to candidates who have experience and/or familiarity with Azure, Defender for Cloud, and Microsoft suite of security products. Management experience in financial services industry is beneficial. Must have experience with information security management frameworks. Experience developing and maintaining information security policies, standards, processes, guidelines, procedures, controls, for financial institutions or processors. Track record of planning and executing complex work efforts. Strong interpersonal communication, analysis, and writing skills. Leadership skills including ability to work effectively with business unit managers, application development and IT operations staff. Able to align management and leadership strategies when working on projects. Ability to work effectively with business unit and IT department managers, including Application Development, Infrastructure, Operations, Network, Technical Support, and others. Superior verbal and written communication skills. Must be a team player. Ability to successfully lead extended teams through new and complex concepts and processes.The team you will join:
Founded in 1988, First National is one of Canada’s largest non-bank lenders. We provide residential mortgages exclusively through our mortgage broker channel and service commercial clients through our national origination team of empowered advisors.
At First National, It’s in our Nature is our rallying cry. It underlies our values, beliefs, and how we show up for each other, our clients, our partners and the community. Our nature defines who we are and guides every decision we make.
First National is proud to be an equal opportunity employer and is committed to diversity and inclusion regardless of race, color, religion, national origin, age, gender identity, physical or mental disability, sexual orientation or any other category protected by law.
First National supports requests for accommodation from applicants with disabilities; please contact Human Resources at .
We would like to thank all applications for their interest, but only candidates selected for an interview will be contacted.
#FNLOON
-
GRC Security Lead
4 weeks ago
Toronto, Ontario, Canada Sprinklr Full timeJob DescriptionJob Title: GRC Security LeadLocation: RemoteJob Type: Full-timeAbout Sprinklr: We're a global leader in cloud-based enterprise software for customer experience and marketing.Job Summary: We're looking for a highly skilled GRC Security Lead to join our team. As a GRC Security Lead, you will be responsible for assisting the GRC team in planning...
-
SAP GRC Lead
1 month ago
Toronto, Canada Experis Full timeSAP GRC Lead Start ASAP Contract Term: 6 months, renewable Work Location: Monday to Friday working from client office in downtown Calgary, AB Our client, a global leading IT consulting firm, is seeking an experienced SAP GRC Lead to join the Risk & Compliance team. As a Compliance Lead, your primary focus will be on SAP GRC and Security Strategy....
-
Grc Security Specialist
6 months ago
Toronto, Canada Cohere Full time**Who are we?** - Cohere is focused on building and deploying large language model (LLM) AI into enterprises in a safe and responsible way that drives human productivity, and creates magical new ways to interact with technology and real business value. We’re a team of highly motivated and experienced engineers, innovators, and disruptors looking to change...
-
Cyber Security Grc Analyst
6 months ago
Toronto, Canada VortalSoft Usa Full timeConduct comprehensive risk assessments to identify potential security threats and vulnerabilities within the organization’s systems and processes. Policy development, compliance management, training, incident management. Pay: $40.00-$45.00 per hour Expected hours: 40 per week **Benefits**: - Dental care - Extended health care - Paid time...
-
Information Security Consultant
1 week ago
Toronto, Canada Insight Global Full timeLocation: Toronto, 1x/week onsiteLength: 6 months + extensions Required Skills & Experience - 4-8 years of experience as a security risk consultant - Experience working a major category 1 bank within North America - Strong experience assessing security risks, specifically for web applications - Experience with full cycle risk assessments - assessing risks,...
-
Analyst Iii, Security Grc
2 weeks ago
Toronto, Canada Moneris Solutions Full time**Your Moneris Career - The Opportunity** At Moneris, we are re-imagining commerce and shaping the future of FinTech. To do that, we empower our teams to redefine what's possible, enable them with the right tools, and support them every step of the way. Our Technology Team's goal is to connect ideas and technology to create solutions that shape the way...
-
Manager- Governance, Risk, and Compliance
6 months ago
Toronto, Canada Manulife Full timeWe are a leading financial services provider committed to making decisions easier and lives better for our customers and colleagues around the world. From our environmental initiatives to our community investments, we lead with values throughout our business. To help us stand out, we help you step up, because when colleagues are healthy, respected and...
-
Information Security Consultant
2 weeks ago
Toronto, Ontario, Ontario, Canada Insight Global Full timeLocation: Toronto, 1x/week onsiteLength: 6 months + extensions Required Skills & Experience - 4-8 years of experience as a security risk consultant - Experience working a major category 1 bank within North America - Strong experience assessing security risks, specifically for web applications - Experience with full cycle risk assessments - assessing risks,...
-
Grc Consultant
6 months ago
Toronto, Canada Atlantis IT group Full time**Job Title: GRC Consultant** **Location: Toronto, ON** **Duration: Long Term Contract** - Lead and oversee GRC initiatives related to SOC 2, PCI, and SOX compliance. - Conduct risk assessments, gap analyses, and control testing to ensure compliance with regulatory requirements. - Develop and implement policies, procedures, and controls to mitigate risks and...
-
Grc Consultant
6 months ago
Toronto, Canada Atlantis IT group Full time**Job Title: GRC Consultant** **Location: Toronto, ON** **Duration: Long Term Contract** - Lead and oversee GRC initiatives related to SOC 2, PCI, and SOX compliance. - Conduct risk assessments, gap analyses, and control testing to ensure compliance with regulatory requirements. - Develop and implement policies, procedures, and controls to mitigate risks and...
-
Security Analyst
5 days ago
Toronto, Canada Xello Full time**Xello is looking for a Security Analyst**: ***Who are you?**: You are a dedicated security professional who thrives in environments where Governance, Risk, and Compliance (GRC) intersect with hands-on security operations. You excel at developing and implementing robust policies and procedures aligned with industry standards such as SOC2, ISO27001, and...
-
Information Security Intern
6 months ago
Toronto, Canada Thales Full timeLocation: Toronto, Canada Thales people architect solutions that support 85 million mainline and suburban passenger journeys, worldwide, every day. Our Rail Signalling and Communication systems are used on metro lines across major cities, and 72,000 kms of route, 52,000 trains per day in 16 countries are controlled by our Traffic Management Systems....
-
Information Security Intern
3 months ago
Toronto, Canada Thales Full timeAbout Us A career at Hitachi Rail will help create a legacy. With operations in every corner of the world, our work goes to the cutting-edge of digital transformation and technology. From the multi-cultural strength of our global organisation to the sustainable and innovative ways we work to bring people together, there’s something for everyone to get...
-
Senior Consultant, GRC Reporting
6 months ago
Toronto, Canada CIBC Full timeNous bâtissons une banque axée sur les relations pour un monde moderne. Nous recrutons des professionnels talentueux et passionnés qui ont à cœur de faire ce qu’il faut pour nos clients. À la Banque CIBC, nous misons sur vos forces et vos ambitions pour vous donner le pouvoir d’agir. Les membres de notre équipe disposent de ce dont ils ont...
-
Specialist, IT Security
6 months ago
Toronto, Canada Coca-Cola Canada Bottling Limited Full timeFacility Location - Toronto Employee Type - Regular Employee FT Salaried **About This Opportunity**: **Responsibilities**: - Help design, build, and manage the organization's GRC program to ensure compliance with regulatory requirements. - Assist in overseeing the Governance, Risk, and Compliance (GRC) program, including updating the GRC tool as necessary...
-
Senior Manager, IT Issues Management
4 days ago
Toronto, Ontario, Canada Royal Bank of Canada Full timeRole SummaryThis is a highly demanding and rewarding role that requires an experienced leader to manage IT risk issues for the Royal Bank of Canada. The ideal candidate will have a strong background in cyber security management, process management, and executive reporting.About the RoleThe Senior Manager, IT Issues Management will be responsible for leading...
-
Analyst III, Security GRC
2 weeks ago
Toronto, Canada Equest Full timeYour Moneris Career - The OpportunityAt Moneris, we are re-imagining commerce and shaping the future of FinTech. To do that, we empower our teams to redefine what's possible, enable them with the right tools, and support them every step of the way.Our Technology Team's goal is to connect ideas and technology to create solutions that shape the way people pay....
-
Senior GRC Platform Administrator
7 days ago
Toronto, Ontario, Canada Tata Consultancy Services Full timeAbout TCS: A Global Leader in Technology DeploymentTata Consultancy Services (TCS) is a global technology firm that operates on a massive scale, with a diverse talent base of over 600,000 associates from 153 nationalities across 55 countries. We have been recognized as a Global Top Employer by the Top Employers Institute - one of only eight companies...
-
Information Security Management System, Specialist
3 months ago
Toronto, Canada Canada Life Assurance Company Full timeInformation Security Management System, Specialist (ISO 27001) **Description: - Permanent Full Time- The ISMS Specialist works with IT and business partners to help them understand and manage information security risks and comply with the organizational information security policies. The role also supports the delivery of analysis-based Technology Risk...
-
Toronto, Ontario, Canada First National Full timeCompany Overview:Founded in 1988, First National is a leading non-bank lender in Canada.About the Job:We are seeking a Chief Security Strategist to join our Information Security team. As a key member of our leadership team, you will play a critical role in ensuring the security, integrity, and availability of our information assets.Job Description:The ideal...