... Management, Cyber Incident Response, Cyber Threat Intelligence, Technology Resilience, Third Party Cyber Risk, Physical Security and Application Security. * Monitor technology risk KRIs and KPIs ...
... Management, Cyber Incident Response, Cyber Threat Intelligence, Technology Resilience, Third Party Cyber Risk, Physical Security and Application Security. * Monitor technology risk KRIs and KPIs ...
Lead Cyber Treaty Underwriter
Toronto, ON · Hybrid
CA$140K/yr
Our constantly evolving offerings lead the market in cyber, equipment breakdown, renewable energy, technology services, engineering-based risk management and inspection services. We bring technical ...
Lead Cyber Treaty Underwriter
Toronto, ON · Hybrid
CA$140K/yr
Our constantly evolving offerings lead the market in cyber, equipment breakdown, renewable energy, technology services, engineering-based risk management and inspection services. We bring technical ...
... Party Risk Management (TPRM). The successful candidate will be responsible for being a key ... Contribute to cross-service opportunities within multiple areas of the firm including Cyber ...
... Party Risk Management (TPRM). The successful candidate will be responsible for being a key ... Contribute to cross-service opportunities within multiple areas of the firm including Cyber ...
Keep abreast of external cyber security trends, technologies and cyber risk management approaches, control hygiene of the environment, and often collaborate with other teams on IT risk-related ...
Keep abreast of external cyber security trends, technologies and cyber risk management approaches, control hygiene of the environment, and often collaborate with other teams on IT risk-related ...
The Senior Manager of Technology Risk & Control Assessments will play a critical role in the hands ... and cyber risk exposure. * Partner closely with First Line Technology teams to gather risk and ...
The Senior Manager of Technology Risk & Control Assessments will play a critical role in the hands ... and cyber risk exposure. * Partner closely with First Line Technology teams to gather risk and ...
Senior Manager, KDN Presales Solution Architect - Cyber (24 Month Secondment/Fixed Term Contract)
Toronto, ON · Hybrid
Apply expertise in enterprise cyber functions such as information security, cyber risk, compliance ... Extensive experience designing cyber managed services including MDR, penetration testing ...
Senior Manager, KDN Presales Solution Architect - Cyber (24 Month Secondment/Fixed Term Contract)
Toronto, ON · Hybrid
Apply expertise in enterprise cyber functions such as information security, cyber risk, compliance ... Extensive experience designing cyber managed services including MDR, penetration testing ...
Strong knowledge of Cyber Risk Management and Cyber/IT regulations for Financial Institutions * Strategic skills to develop long-term visions and the ability to translate them into actionable ...
Strong knowledge of Cyber Risk Management and Cyber/IT regulations for Financial Institutions * Strategic skills to develop long-term visions and the ability to translate them into actionable ...
... cyber risk, and ongoing monitoring. Success in this role requires strong stakeholder and conflict management skills to balance business objectives, client expectations, and regulatory obligations, as ...
... cyber risk, and ongoing monitoring. Success in this role requires strong stakeholder and conflict management skills to balance business objectives, client expectations, and regulatory obligations, as ...
Operational or cyber risk management practices; * Client asset protection or fund safeguarding; * Trust, safeguarding, or custodial account oversight; * Audit, assurance, or controls review
Operational or cyber risk management practices; * Client asset protection or fund safeguarding; * Trust, safeguarding, or custodial account oversight; * Audit, assurance, or controls review
RQ00650 - Sr. Security Specialist
Toronto, ON · On-site
Key program areas include Cloud Security, Vulnerability Management, Cyber Risk Management, Security Operations, Incident Response, Threat Intelligence, Security Architecture, Policy Development ...
Quick apply
RQ00650 - Sr. Security Specialist
Toronto, ON · On-site
Key program areas include Cloud Security, Vulnerability Management, Cyber Risk Management, Security Operations, Incident Response, Threat Intelligence, Security Architecture, Policy Development ...
Employing exceptional time management and organization skills to ensure client satisfaction and ... Work closely with our Cyber colleagues and understand leading perspectives in emerging cyber risk ...
Employing exceptional time management and organization skills to ensure client satisfaction and ... Work closely with our Cyber colleagues and understand leading perspectives in emerging cyber risk ...
Ensure alignment with enterprise Cyber risk management and governance requirements. * Drive consistency governance routines, adherence to risk and control framework requirements, and issue management ...
Ensure alignment with enterprise Cyber risk management and governance requirements. * Drive consistency governance routines, adherence to risk and control framework requirements, and issue management ...
AVP, Cyber and Data Risk
Markham, ON · Hybrid
In this role, you'll shape how we manage data risk, strengthen controls, and respond to an evolving ... Deep understanding of cyber, data, and IT infrastructure domains. What you'll get: * Compelling ...
AVP, Cyber and Data Risk
Markham, ON · Hybrid
In this role, you'll shape how we manage data risk, strengthen controls, and respond to an evolving ... Deep understanding of cyber, data, and IT infrastructure domains. What you'll get: * Compelling ...
Senior Security Specialist
Toronto, ON · On-site
Work across key security domains including IAM, Zero Trust, cloud security, data protection, application security, vulnerability management, security operations, third-party cyber risk, and cyber ...
Senior Security Specialist
Toronto, ON · On-site
Work across key security domains including IAM, Zero Trust, cloud security, data protection, application security, vulnerability management, security operations, third-party cyber risk, and cyber ...
Our Cyber Risk and Data Protection team serves the cybersecurity and data protection related needs ... Manage and expand key client accounts and relationships to drive the transformation of clients ...
Our Cyber Risk and Data Protection team serves the cybersecurity and data protection related needs ... Manage and expand key client accounts and relationships to drive the transformation of clients ...
Manager, GRC
Toronto, ON · On-site
Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Governance, Methodology, and PMO * Establish Agile SDLC, program governance, RAID, and executive ...
Manager, GRC
Toronto, ON · On-site
Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Governance, Methodology, and PMO * Establish Agile SDLC, program governance, RAID, and executive ...
Lead the enterprise function that centralizes, modernizes, and operationalizes technology & cyber risk insights-delivering accurate, timely KRIs and decision support for the Board, Senior Management ...
Lead the enterprise function that centralizes, modernizes, and operationalizes technology & cyber risk insights-delivering accurate, timely KRIs and decision support for the Board, Senior Management ...
Manager, Cyber Resilience
Toronto, ON · On-site
The Manager for Cyber Resilience is responsible for collecting, analyzing, assessing and applying ... Familiar with industry standard risk management frameworks including NIST 800-53, NIST 800-160 ...
Manager, Cyber Resilience
Toronto, ON · On-site
The Manager for Cyber Resilience is responsible for collecting, analyzing, assessing and applying ... Familiar with industry standard risk management frameworks including NIST 800-53, NIST 800-160 ...
... Cyber Risk, IT Risk, and Third-Party Risk. * Ensures material risks are clearly identified ... Manages, monitors, and tests risks and risk controls within the parameters of the risk control ...
... Cyber Risk, IT Risk, and Third-Party Risk. * Ensures material risks are clearly identified ... Manages, monitors, and tests risks and risk controls within the parameters of the risk control ...
Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Advisory, Enablement, and Change Management * Advise on regulations and frameworks; create ...
Enterprise/Operational Risk, Resilience, Regulatory Compliance, Policy, IT/Cyber Risk ... Advisory, Enablement, and Change Management * Advise on regulations and frameworks; create ...
Cyber Risk Manager information
How does a Cyber Risk Manager typically collaborate with other departments to strengthen an organization's cybersecurity posture?
What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?
| Aspect | Cyber Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability testing |
| Employer & Industry Usage | Financial, healthcare, large enterprises | IT departments, security firms, corporate environments |
The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.
What are the key skills and qualifications needed to thrive as a Cyber Risk Manager, and why are they important?
What does a Cyber Risk Manager do?
Other
Medical, Dental, Vision, Retirement, PTO
Posted 28 days ago
Job description
Requisition ID: 259458Â
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
The role:
The Global Head, Technology Risk Officer (TRO) leads the First Line of Defense (1B) Technology Risk and Internal Control function, accountable for the design, implementation, operation, and continuous improvement of technology and cybersecurity risk management practices across the enterprise. The role ensures technology and cybersecurity risks are identified, assessed, mitigated, monitored, and reported in alignment with the firm's risk appetite, regulatory expectations, and business strategy.
This role requires a visionary leader with a deep understanding of cybersecurity principles, risk management, and compliance frameworks. The ideal candidate will possess strong communication and leadership skills, the ability to navigate complex regulatory landscapes, and a commitment to continuous improvement in the face of a rapidly evolving cybersecurity environment.
Â
What will you do?
- Own execution and accountability for Technology Risk Management and Internal Controls within the First Line of Defense (1B).Â
- Provide direction and oversight to Technology 1A risk owners to strengthen their capability to identify, assess, mitigate, and monitor technology and cyber risks.Â
- Serve as a trusted 1B Technology Risk partner to Technology, Product, and Business teams.Â
- Lead the identification, escalation, monitoring, and measurement of technology and operational risks in alignment with firm-wide risk management programs.Â
- Serve as a deep subject matter expert and trusted Technology 1B partner on cybersecurity, resiliency and physical security principles, practices and technologies across key domains, including, Threat and Vulnerability Management, Data Protection, Identity and Access Management, Cyber Incident Response, Cyber Threat Intelligence, Technology Resilience, Third Party Cyber Risk, Physical Security and Application Security.
- Monitor technology risk KRIs and KPIs, supports review and challenge of remediation and get-to-green plans, and tracks delivery of sustainable risk reduction.Â
- Ensures technology risk outcomes remain aligned to the firm's risk appetite and governance expectations.Â
- Prepare and presents technology risk insights, trends, and recommendations to senior management and governance forums.Â
- Provide 1B risk and control advisory support, including targeted risk reviews, root cause analysis, and development of sustainable mitigation strategies.Â
- Implements the firm's technology risk management strategy, ensuring alignment with regulatory and industry standards.Â
- Drives a proactive risk and control culture focused on prevention, transparency, and continuous improvement.Â
- Partner with Second Line of Defense to support effective review, challenge, and enterprise consistency.Â
- Collaborate with Technology leadership, Product Owners, Business Control Managers, and key stakeholders to maintain a comprehensive enterprise technology risk view.Â
- Engage with regulators and internal governance bodies, as required.Â
- Leads and scales a large, global Technology Risk and Internal Control organization, providing clear direction, priorities, and accountability across multiple teams and geographies
- Establish a strong operating model, including defined roles, decision rights, escalation paths, and performance expectations.Â
- Build a strong leadership bench through coaching, succession planning, and capability development.Â
- Drive workforce planning, capacity management, and resource allocation aligned to strategic priorities and regulatory commitments.Â
- Foster an inclusive, high-performance culture emphasizing ownership, execution discipline, and continuous improvement.Â
- Lead through change, effectively managing organizational complexity while maintaining focus on risk outcomes and control effectiveness.Â
- Create an environment in which the team pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to, and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions, and conduct risk.
- Lead and drives a customer focused culture throughout their team to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
- Build a high-performance environment and implement a people strategy that attracts, retains, develops, and motivates the team by fostering an inclusive work environment and using a coaching mindset and behaviors; communicating vision/values/business strategy; and managing succession and development planning for the team.
What do you need to succeed?
- University degree in Computer Engineering, Computer Science, Technology, or a related field, with 10+ years of experience in progressively senior security roles within a complex, global organization.
- Professional certifications in cybersecurity, technology, or risk management (e.g., CISSP, CCSP, CEH, CISM).
- Strong understanding of regulatory and industry cybersecurity frameworks, including NIST, ISO 27001, FFIEC, OSFI, DORA, PCI DSS, and MITRE ATT&CK.
- Proficiency in risk management tools and data analytics.
- Mandatory experience in financial services, with a strong preference for banking.
- Proven experience leading audit, regulatory, and Second Line of Defense findings, including ownership of remediation planning, execution tracking, and sustainable closure.
- 10+ years of IT process and control experience, including internal audit, external audit, risk assessment, or issue management functions.
- Demonstrated experience driving crossfunctional, senior executive forums and remediation governance in a global environment.
- Strong adaptive leadership skills, with the ability to lead effectively through change and ambiguity.
- Excellent written and verbal communication skills, with the ability to articulate complex security and control concepts to technical and nontechnical stakeholders, including senior executives.
- Strong leadership and collaboration skills, including the ability to influence across all levels of management and manage large, complex initiatives.
- Fluency in English required; Spanish preferred.
- Deep practical knowledge of cybersecurity disciplines, including Cloud Security, AI/ML, Network Security, Threat Modeling, Vulnerability Management, and Technology Resilience.
- Strong analytical and criticalthinking skills to assess business, technical, and operational risks.
- Proven ability to operate in highpressure, timesensitive environments, managing dependencies and competing priorities.
- Experience with cybersecurity diligence practices, including vulnerability assessments and penetration testing.
- Experience leveraging AI/ML capabilities to manage risks associated with emerging technologies.
What's in it for you?
- We have an inclusive and collaborative working environment that encourages creativity and curiosity and celebrates success
- We provide you with the tools and technology needed to create meaningful customer experiences
- You'll get to work with and learn from diverse industry leaders, who have hailed from top technology companies around the world
- We hire you for your talent - not just a job - so you can grow with us. We'll equip you for success not only in your role, but also in your career as a whole
- Dress codes don't apply here: being comfortable does
- Access to thousands of online and in-person courses so you can hone your current skills, or learn new ones
- A competitive rewards package that includes a base salary, a performance bonus, company matching programs on pension and profit sharing, paid vacation, personal & sick days, medical, vision, and dental and much more
Location(s): Â Canada : Ontario : TorontoÂ
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets. Â
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
About Scotiabank
Sourced by ZipRecruiter
Industry
Banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
New York, NY, US