Senior Manager, Cyber Security and IT Risk Management

Not Interested
Bookmark
Report This Job

profile Job Location:

Toronto - Canada

profile Monthly Salary: Not Disclosed
Posted on: 30+ days ago
Vacancies: 1 Vacancy

Job Summary

Requisition ID: 230577

Join a purpose driven winning team committed to results in an inclusive and high-performing culture.

Contributes to the overall success of Cyber & IT Risk Management Global Risk Management (GRM) globally ensuring specific individual goals plans initiatives are executed/delivered in support of the teams business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations internal policies and procedures.

Leads expert technical risk assurance and control oversight to ensure the bank achieves its objectives while effectively managing risk. Collaborate with cross-functional teams across the first line of defense to identify assess and mitigate emerging risks and vulnerabilities. This role is crucial in fostering a robust risk culture and driving continuous improvement contributing to the development and implementation of comprehensive risk management policies standards and controls.

As part of the second line of defense the Cybersecurity and IT Risk team provides independent oversight and challenge and assists in developing methodologies policies processes and tools to support the Cyber and IT Risk Management Framework.

Is this role right for you In this role you will:

Including but not exclusively:

  • Lead 2nd Line Challenge:Conduct comprehensive challenge to identify potential threats and vulnerabilities in the Banks processes systems and operations. Partner with 1st line of defense to develop risk mitigation strategies across key cyber and IT domains. Challenge IT and cybersecurity risks within scenario analysis and thematic reviews. Conduct cyber risk assessments metrics and controls within globally complex dispersed and diverse organizations.
  • RCSA Program Management. Define the annual plan in collaboration with GOR the business and IT Risk. Assign resources as needed on selected RCSAs. Review and challenge the scope for IT participants and IT Profile for RCSAs.
  • Risk Assessment and Identification. Objectively review & challenge the inherent risk control effectiveness and residual risk assessments & rationales as well as related issues/APs for technology specific risk/controls. Provide feedback and follow up on the technology specific risk/control responses.
  • Issue Management. Ensure all IT risks/controls have been properly documented and reflected in deliverables and applicable tracking systems including suitable action plans.
  • Reporting and Monitoring. Prepare reports on IT components of RCSAs including findings track IT risk trends and monitor the effectiveness of controls.
  • Training and Communication. Develop and deliver training programs to educate and support peers and stakeholders on IT processes of the RCSAs and best practices.
  • Stakeholder Management. Act as a liaison between business units control owners IT Risk and other stakeholders.
  • Champions a customer focused culture to deepen client relationships and leverage broader Bank relationships systems and knowledge.
  • Understand how the Banks risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabanks Values its Code of Conduct and the Global Sales Principles while ensuring the adequacy adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational compliance AML/ATF/sanctions and conduct risk.
  • Champions a high performance environment and contributes to an inclusive work environment.

Do you have the skills that will enable you to succeed in this role Wed love to work with you if you have:

  • Strong expertise in IT Risk Management (e.g. Logical Access Data Leakage Disaster Recovery)
  • Masters degree or higher in science technology engineering business administration is an asset.
  • 5 years of experience in Technology or Operational Risk Management IT Audit IT Compliance regulatory-supervision consulting or advisory roles.
  • 1 years of experience in RCSAs as part of the 1LoD or 2LoD.
  • Industry certifications desirable (e.g. CISSP CRISC CISM)
  • Advanced knowledge of relevant regulatory rules (OSFI FFIEC NYDFS 500) and frameworks (NIST COBIT) is preferred
  • Experience using of GRC risk management tools.
  • Demonstrated expertise in regulatory compliance risk management frameworks and industry best practices (e.g. NIST ISO FFIEC GDPR)
  • Proficiency in data security risk management & controls security governance and analytical thinking with a track record of implementing effective risk mitigation strategies
  • Advanced knowledge of data analytics and data literacy
  • Strong understanding of IT risk management frameworks in a global banking environment.
  • Strong understanding of risk and controls assessments and self-assessments.
  • Able to convey complex concepts and ideas on issues requiring interpretation and opinion.
  • Maintain in-depth knowledge of cyber and IT risks and controls across various information system architecture and engineering domains such as data protection application security identity and access management vulnerability management change management network security endpoint security logging and monitoring and incident management. Stay actively engaged in the industry on the latest in cyber risk and emerging operational risks.
  • Demonstrate a sense of urgency in implementing programs and evaluating priorities; be decisive action-oriented and practical.
  • Analyze and think through highly complex issues then appropriately execute and implement against a well-thought-through framework in a seamless manner. Be a global citizen comfortable in all geographies regions and cultures.
  • Demonstrate strong leadership communication and presentation skills including the ability to adapt style to suit the different needs of any audience
  • Independent in judgment and with a high standard of conduct and ethics. Able to challenge and be challenged while maintaining the highest levels of professionalism.
  • Good negotiation skills and ability to resolve conflict between teams or individuals so that functional / organizational objectives are achieved.
  • Excellent analytical skills; critical thinking and problem solving skills.
  • Good interpersonal skills
  • Spanish proficiency is required.

Whats in it for you

  • We have an inclusive and collaborative work environment that values curiosity & ownership encourages pragmatic creativity (i.e. true innovation) and celebrates success!
  • An inclusive working environment that encourages creativity curiosity and celebrates success!
  • A rewarding career path with diverse opportunities for professional development
  • Internal training to support your growth and enhance your skills
  • A competitive rewards package that includes a base salary a performance bonus company matching programs on pension and profit sharing paid vacation personal & sick days medical vision and dental benefits that start from day one and much more!

Location(s): Canada : Ontario : Toronto

Scotiabank is a leading bank in the Americas. Guided by our purpose: for every future we help our customers their families and their communities achieve success through a broad range of advice products and services including personal and commercial banking wealth management and private banking corporate and investment banking and capital markets.

At Scotiabank we value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including but not limited to an accessible interview site alternate format documents ASL Interpreter or Assistive Technology) during the recruitment and selection process please let our Recruitment team know. If you require technical assistance please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however only those candidates who are selected for an interview will be contacted.


Required Experience:

Senior Manager

Requisition ID: 230577Join a purpose driven winning team committed to results in an inclusive and high-performing culture.Contributes to the overall success of Cyber & IT Risk Management Global Risk Management (GRM) globally ensuring specific individual goals plans initiatives are executed/delivered...
View more view more

Key Skills

  • Children Activity
  • Graphic Designing
  • Information Technology
  • FX
  • Airlines
  • Asic

About Company

Company Logo

Scotiabank is one of the leading foreign banks serving large national and multinational corporations in the U.S. through its Global Banking and Markets, Global Transaction Banking and Wealth Management business lines.

View Profile View Profile