Director, Cyber Security Risk Oversight – Global Risk

Manulife

Not Interested
Bookmark
Report This Job

profile Job Location:

Ontario - Canada

profile Monthly Salary: Not Disclosed
Posted on: 30+ days ago
Vacancies: 1 Vacancy

Job Summary

Manulife is seeking a strategic and experienced Director Cybersecurity Risk Oversight as a Line 2 leadership role responsible for independent oversight challenge and governance of enterprise systems. Reporting to the AVP Information Security this position will participate in the design and execution of a fit-for purpose risk oversight framework to ensure that technology solutions align with enterprise risk appetite regulatory expectations and secure software development best practices. The role will act as a strategic advisor across multiple cyber security risk domains including identity and access management cloud security and data security.

Key Responsibilities:

Independent Oversight:

  • Lead the independent oversight of cybersecurity risks ensuring robust alignment with Manulifes standards and strategic objectives. Provide expert guidance to uphold the integrity of the cybersecurity framework.

  • Collaborate with multidisciplinary teams to gain a comprehensive understanding of Manulifes technology strategy operations and regulatory environment. Proactively identify and assess areas of emerging and heightened risk related to information and cybersecurity.

  • Evolve and enhance Line 2 oversight frameworks to effectively manage and mitigate risks associated with information and cybersecurity ensuring these frameworks remain agile and responsive to new challenges.

  • Oversee Line 1 risk compliance and operational metrics and actively participate in the development and maintenance of Line 2s information and cybersecurity risk measurement programs. Ensure these metrics are comprehensive and support strategic risk management initiatives.

Cyber & Technology Risk Assessment:

  • Conduct comprehensive and in-depth assessments of technology programs particularly those with third-party dependencies to ensure the safeguarding of organizational assets. Utilize advanced risk assessment methodologies to identify vulnerabilities and implement effective mitigation strategies.

  • Execute independent and objective challenges to existing cybersecurity measures across critical risk domains including Identity & Access Management Cloud Security Network Security and Data Security. Ensure these challenges rigorously test the effectiveness and resilience of current risk management practices.

  • Maintain a forward-looking approach by continuously monitoring emerging risks and active threats in the cybersecurity landscape. Integrate these insights into assessments to enhance preparedness and adaptability to new challenges.

  • Provide unbiased and evidence-based oversight to ensure that risk assessments not only meet regulatory requirements but also align with Manulifes strategic objectives and risk appetite fostering continuous improvement in the organizations cybersecurity posture.

Standards and Policy Framework Development:

  • Lead the research development and continuous enhancement of Manulifes internal technology and cyber policies and standards. Ensure these policies are not only aligned with industry best practices but are also responsive to active threats anticipate emerging risks and adapt to evolving regulatory environments.

  • Develop a dynamic and comprehensive policy framework that fosters organizational resilience and promotes a proactive security culture. This framework should empower the organization to preemptively address vulnerabilities and remain agile in the face of new challenges.

  • Collaborate with cross-functional teams to integrate insights from threat intelligence and risk assessments into policy development processes ensuring a holistic approach to risk management that supports strategic business objectives.

  • Champion a culture of security awareness and compliance across the organization by effectively communicating policy changes and their implications thus reinforcing the importance of cybersecurity at every level.

Cyber Risk Reporting & Strategy:

  • Collaborate across first and second lines of defense to develop and report onKey Risk Indicators (KRIs).

  • Support leadership in preparing board-level cybersecurity materials offering actionable insights on cyber and emerging risks data security and operational resilience.

Key Qualifications:

  • 7-10 years in cybersecurity or technology risk management and/or First Line cybersecurity operations
  • Experience with critical security risk domains such as cloud security network security identity and access management and third-party security
  • Commitment to continuous learning of cybersecurity risks threat landscape and best practices with a focus on effective and efficient governance and oversight
  • Experience in developing enterprise policies & standards conducting risk assessments and a strong understanding of common risk frameworks such as NIST Cybersecurity Framework and 800-53 ISO 27001/27002 and PCI DSS 4.0
  • Ability to work cross-functionally aligning risk management with broader business strategies
  • Excellent verbal and written communication skills with a focus on technical writing. Must be able to effectively convey complex risk concepts and insights to senior leadership and business collaborators. Skilled in crafting clear and concise reports presentations and documentation to facilitate informed decision-making
  • Expertise in engaging with diverse collaborators to integrate their feedback into risk management practices
  • Ability to effectively manage crises related to cybersecurity risks demonstrating resilience and adaptability
  • Keen interest in emerging technologies and innovations with the ability to assess potential risks and opportunities

When you join our team:

  • Well empower you to learn and grow the career you want.
  • Well recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team well support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider helping people make their decisions easier and lives better. To learn more about us visit is an Equal Opportunity Employer

At Manulife/John Hancock we embrace our diversity. We strive to attract develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment retention advancement and compensation and we administer all of our practices and programs without discrimination on the basis of race ancestry place of origin colour ethnic origin citizenship religion or religious beliefs creed sex (including pregnancy and pregnancy-related conditions) sexual orientation genetic characteristics veteran status gender identity gender expression age marital status family status disability or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process contact .

Referenced Salary Location

Waterloo Ontario

Working Arrangement

Hybrid

Salary range is expected to be between

$110530.00 CAD - $205270.00 CAD

If you are applying for this role outside of the primary location please contact for the salary range for your location. The actual salary will vary depending on local market conditions geography and relevant job-related factors such as knowledge skills qualifications experience and education/training. Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance.

Manulife offers eligible employees a wide array of customizable benefits including health dental mental health vision short- and long-term disability life and AD&D insurance coverage adoption/surrogacy and wellness benefits and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays vacation personal and sick days and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S. please contact for more information about U.S.-specific paid time off provisions.


Required Experience:

Director

Manulife is seeking a strategic and experienced Director Cybersecurity Risk Oversight as a Line 2 leadership role responsible for independent oversight challenge and governance of enterprise systems. Reporting to the AVP Information Security this position will participate in the design and execution...
View more view more

Key Skills

  • Category Management
  • Athletics
  • Customer
  • ABAP
  • Hydraulics
  • ITI

About Company

Company Logo

Manulife is a leading financial services group. We provide financial advice, insurance, as well as wealth and asset management solutions for individuals, groups and institutions.

View Profile View Profile