1

Cyber Risk Manager Jobs in Ontario (NOW HIRING)

Our constantly evolving offerings lead the market in cyber, equipment breakdown, renewable energy, technology services, engineering-based risk management and inspection services. We bring technical ...

... Party Risk Management (TPRM). The successful candidate will be responsible for being a key ... Contribute to cross-service opportunities within multiple areas of the firm including Cyber ...

Work across key security domains including IAM, Zero Trust, cloud security, data protection, application security, vulnerability management, security operations, third-party cyber risk, and cyber ...

Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Governance, Methodology, and PMO * Establish Agile SDLC, program governance, RAID, and executive ...

The Manager for Cyber Resilience is responsible for collecting, analyzing, assessing and applying ... Familiar with industry standard risk management frameworks including NIST 800-53, NIST 800-160 ...

Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Advisory, Enablement, and Change Management * Advise on regulations and frameworks; create ...

next page

Showing results 1-20

Cyber Risk Manager information

How does a Cyber Risk Manager typically collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

What are the key skills and qualifications needed to thrive as a Cyber Risk Manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What does a Cyber Risk Manager do?

A Cyber Risk Manager is responsible for identifying, assessing, and mitigating risks related to information technology and cybersecurity within an organization. They develop and implement strategies to protect sensitive data and systems from cyber threats, ensure compliance with regulations, and work closely with other departments to minimize vulnerabilities. Their role often includes conducting risk assessments, managing incident response plans, and advising leadership on cybersecurity best practices.
What job categories do people searching Cyber Risk Manager jobs in Ontario look for? The top searched job categories for Cyber Risk Manager jobs in Ontario are:
What cities in Ontario are hiring for Cyber Risk Manager jobs? Cities in Ontario with the most Cyber Risk Manager job openings:
Global Head, Technology Risk Officer

Global Head, Technology Risk Officer

Scotiabank

Toronto, ON • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Posted 28 days ago


Job description

Requisition ID: 259458 
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

The role:


The Global Head, Technology Risk Officer (TRO) leads the First Line of Defense (1B) Technology Risk and Internal Control function, accountable for the design, implementation, operation, and continuous improvement of technology and cybersecurity risk management practices across the enterprise. The role ensures technology and cybersecurity risks are identified, assessed, mitigated, monitored, and reported in alignment with the firm's risk appetite, regulatory expectations, and business strategy.

This role requires a visionary leader with a deep understanding of cybersecurity principles, risk management, and compliance frameworks. The ideal candidate will possess strong communication and leadership skills, the ability to navigate complex regulatory landscapes, and a commitment to continuous improvement in the face of a rapidly evolving cybersecurity environment.

 

What will you do?

  • Own execution and accountability for Technology Risk Management and Internal Controls within the First Line of Defense (1B). 
  • Provide direction and oversight to Technology 1A risk owners to strengthen their capability to identify, assess, mitigate, and monitor technology and cyber risks. 
  • Serve as a trusted 1B Technology Risk partner to Technology, Product, and Business teams. 
  • Lead the identification, escalation, monitoring, and measurement of technology and operational risks in alignment with firm-wide risk management programs. 
  • Serve as a deep subject matter expert and trusted Technology 1B partner on cybersecurity, resiliency and physical security principles, practices and technologies across key domains, including, Threat and Vulnerability Management, Data Protection, Identity and Access Management, Cyber Incident Response, Cyber Threat Intelligence, Technology Resilience, Third Party Cyber Risk, Physical Security and Application Security.
  • Monitor technology risk KRIs and KPIs, supports review and challenge of remediation and get-to-green plans, and tracks delivery of sustainable risk reduction. 
  • Ensures technology risk outcomes remain aligned to the firm's risk appetite and governance expectations. 
  • Prepare and presents technology risk insights, trends, and recommendations to senior management and governance forums. 
  • Provide 1B risk and control advisory support, including targeted risk reviews, root cause analysis, and development of sustainable mitigation strategies. 
  • Implements the firm's technology risk management strategy, ensuring alignment with regulatory and industry standards. 
  • Drives a proactive risk and control culture focused on prevention, transparency, and continuous improvement. 
  • Partner with Second Line of Defense to support effective review, challenge, and enterprise consistency. 
  • Collaborate with Technology leadership, Product Owners, Business Control Managers, and key stakeholders to maintain a comprehensive enterprise technology risk view. 
  • Engage with regulators and internal governance bodies, as required. 
  • Leads and scales a large, global Technology Risk and Internal Control organization, providing clear direction, priorities, and accountability across multiple teams and geographies
  • Establish a strong operating model, including defined roles, decision rights, escalation paths, and performance expectations. 
  • Build a strong leadership bench through coaching, succession planning, and capability development. 
  • Drive workforce planning, capacity management, and resource allocation aligned to strategic priorities and regulatory commitments. 
  • Foster an inclusive, high-performance culture emphasizing ownership, execution discipline, and continuous improvement. 
  • Lead through change, effectively managing organizational complexity while maintaining focus on risk outcomes and control effectiveness. 
  • Create an environment in which the team pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to, and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions, and conduct risk.
  • Lead and drives a customer focused culture throughout their team to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  • Build a high-performance environment and implement a people strategy that attracts, retains, develops, and motivates the team by fostering an inclusive work environment and using a coaching mindset and behaviors; communicating vision/values/business strategy; and managing succession and development planning for the team.


What do you need to succeed?

  • University degree in Computer Engineering, Computer Science, Technology, or a related field, with 10+ years of experience in progressively senior security roles within a complex, global organization.
  • Professional certifications in cybersecurity, technology, or risk management (e.g., CISSP, CCSP, CEH, CISM).
  • Strong understanding of regulatory and industry cybersecurity frameworks, including NIST, ISO 27001, FFIEC, OSFI, DORA, PCI DSS, and MITRE ATT&CK.
  • Proficiency in risk management tools and data analytics.
  • Mandatory experience in financial services, with a strong preference for banking.
  • Proven experience leading audit, regulatory, and Second Line of Defense findings, including ownership of remediation planning, execution tracking, and sustainable closure.
  • 10+ years of IT process and control experience, including internal audit, external audit, risk assessment, or issue management functions.
  • Demonstrated experience driving crossfunctional, senior executive forums and remediation governance in a global environment.
  • Strong adaptive leadership skills, with the ability to lead effectively through change and ambiguity.
  • Excellent written and verbal communication skills, with the ability to articulate complex security and control concepts to technical and nontechnical stakeholders, including senior executives.
  • Strong leadership and collaboration skills, including the ability to influence across all levels of management and manage large, complex initiatives.
  • Fluency in English required; Spanish preferred.
  • Deep practical knowledge of cybersecurity disciplines, including Cloud Security, AI/ML, Network Security, Threat Modeling, Vulnerability Management, and Technology Resilience.
  • Strong analytical and criticalthinking skills to assess business, technical, and operational risks.
  • Proven ability to operate in highpressure, timesensitive environments, managing dependencies and competing priorities.
  • Experience with cybersecurity diligence practices, including vulnerability assessments and penetration testing.
  • Experience leveraging AI/ML capabilities to manage risks associated with emerging technologies.

What's in it for you?

  • We have an inclusive and collaborative working environment that encourages creativity and curiosity and celebrates success
  • We provide you with the tools and technology needed to create meaningful customer experiences
  • You'll get to work with and learn from diverse industry leaders, who have hailed from top technology companies around the world
  • We hire you for your talent - not just a job - so you can grow with us. We'll equip you for success not only in your role, but also in your career as a whole
  • Dress codes don't apply here: being comfortable does
  • Access to thousands of online and in-person courses so you can hone your current skills, or learn new ones
  • A competitive rewards package that includes a base salary, a performance bonus, company matching programs on pension and profit sharing, paid vacation, personal & sick days, medical, vision, and dental and much more

Location(s):  Canada : Ontario : Toronto 
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.  
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our  Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.