1

Operations Risk Specialist Jobs in Toronto, ON (NOW HIRING)

As an Agent Configuration Specialist, you will configure and deliver AI agents and agent-enabled ... risk and the need for human review and operational guardrails. * Experience testing configured ...

Previous experience as a Fraud Analyst, Risk Analyst, Operations Specialist, Data Scientist, or Product Manager. Bachelor's degree in Engineering, Computer Science, Statistics, Finance, or a related ...

... operational efficiency, risk reduction, and business outcomes Partner with the Contract Management team and cross-functional stakeholders to transition post-award administration effectively, maintain ...

Showing results 21-40

Operations Risk Specialist information

What does an operations risk specialist do?

An Operations Risk Specialist is responsible for identifying, assessing, and mitigating risks within an organization's operational processes. They analyze workflows, review compliance with regulations, and develop strategies to minimize losses due to errors, fraud, or system failures. Their work often involves monitoring risk controls, preparing reports for management, and ensuring the company adheres to industry standards and best practices. By proactively managing operational risks, they help protect the organization's assets and reputation.

What are the key skills and qualifications needed to thrive as an operations risk specialist?

To thrive as an Operations Risk Specialist, you need strong analytical skills, risk management expertise, and a relevant degree in finance, business, or a related field. Familiarity with risk assessment software, regulatory compliance systems, and certifications such as FRM (Financial Risk Manager) or ORM (Operational Risk Management) are often required. Attention to detail, effective communication, and problem-solving abilities are vital soft skills for success in this role. These skills enable professionals to identify, assess, and mitigate operational risks, ensuring organizational resilience and regulatory compliance.

What are some typical challenges operations risk specialists face when implementing risk controls across departments?

Operations Risk Specialists often encounter challenges such as resistance to change from staff, differing risk appetites among departments, and difficulties in standardizing procedures across diverse business units. Effective communication and collaboration are key, as the role requires educating teams on risk management best practices while ensuring compliance with organizational policies. Navigating these challenges helps drive a culture of risk awareness and continuous improvement throughout the company.

What is the difference between Operations Risk Specialist vs Compliance Analyst?

AspectOperations Risk SpecialistCompliance Analyst
Required CredentialsBachelor's degree, certifications like FRM or CRM often preferredBachelor's degree, certifications like CCEP or CAMS common
Work EnvironmentFinancial institutions, banks, or corporations focusing on risk managementRegulatory agencies, financial firms, or corporations ensuring compliance
Employer & Industry UsageUsed in banking, finance, and insurance sectorsCommon in banking, finance, and corporate compliance departments
Search & Comparison IntentOften compared for risk management roles within operationsCompared for regulatory and compliance roles in finance

The Operations Risk Specialist focuses on identifying and mitigating operational risks within organizations, especially in financial sectors. In contrast, a Compliance Analyst ensures adherence to laws and regulations. While both roles require similar credentials and work in related environments, their core responsibilities differβ€”risk management versus regulatory compliance.

How much does an Operations Risk Specialist earn?

An Operations Risk Specialist typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Senior roles or those with specialized certifications may earn higher salaries, and the job often requires strong analytical skills and knowledge of risk management tools.

Is operations risk specialist a good entry level job?

An operations risk specialist role can be suitable for entry-level candidates with strong analytical skills and attention to detail. It often requires understanding risk management principles and may involve using tools like Excel or risk assessment software. However, some positions may prefer candidates with relevant internships or certifications, making it important to review specific job requirements.

What cities near Toronto, ON are hiring for Operations Risk Specialist jobs?

Cities near Toronto, ON with the most Operations Risk Specialist job openings:

Infographic showing various Operations Risk Specialist job openings in Toronto, ON as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 9% Part Time, 1% Temporary, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution.

Senior Manager, Technology Risk

Toronto, ON β€’ On-site

Full-time

Re-posted 29 days ago


Job description

Why DUCA? 

We’re a vibrant, exciting credit union that lives its "profits with a purpose" philosophy in every financial transaction, product, interest rate, and community initiative we offer. Founded in 1954, DUCA has grown from a single branch credit union in Toronto to 19 branches across Southern Ontario with over 85,000 Members we are proud to serve.  

We exist to help People, Businesses and Communities Do More, Be More, and Achieve More™

DUCA (www.duca.com) is distinguished for the following: 

  • Positive, un-big bank like service experience delivered through Member-facing staff in branch, on the phone (Member-Connect) and via our Mobile mortgage specialists, Wealth Management advisors and Commercial and Business Banking Account Managers. 
  • Competitive rates.
  • Personalized financial solutions, guidance, and service with the lowest possible fees for both Personal and Business Members.
  • Profit sharing among Members.
  • Multiple ways to bank—online, mobile app, phone/full-service Member Connect Contact Centre, and, of course, in-branch—DUCA is accessible 24/7 
  • A community philosophy of “profits with a purpose” culminating in the creation of the DUCA Impact Lab (www.ducaimpactlab.com), a charitable foundation committed to helping the credit challenged and underbanked.  This led to DUCA's designation as a B-Corp certified organization, the first ever credit union to receive this global recognition.

A career with DUCA means you’ll find endless opportunities to make a difference with your unique abilities and perspectives. Our people live their purpose while helping others Do more, Be more and Achieve more with their money and their lives.  At DUCA, you’ll be part of a vibrant and collaborative team where you’ll be supported to excel and make an impact, no matter what role you play. 


Senior Manager, Technology Risk

DUCA is looking for a Senior Manager, Technology Risk to join our growing team! 

Job Purpose & Summary

As an integral part of DUCA’s Risk Management team, the Senior Manager, Technology Risk is responsible for supporting the effective management and independent risk oversight of Information Technology (IT), Information Security, Cybersecurity, Operational Resilience, and Emerging Technology risks across the organization. The role provides second line of defense to technology risk management practices, ensuring technology risks are identified, assessed, monitored, mitigated, and reported in accordance with DUCA’s risk appetite, internal policies, and regulatory expectations.

 The Senior Manager, Technology Risk partners closely with Technology, Information Security, business stakeholders, Internal Audit, and regulators to support the management of risks related to cybersecurity, cloud services, operational resilience, AI and emerging technologies, IT operations, third-party technology providers, system availability, change management, technology currency, and data protection.

 This position supports the ongoing enhancement of DUCA’s Technology Risk Management Framework and contributes to compliance with applicable FSRA guidance, cybersecurity expectations, operational resilience requirements, and industry best practices.

Key Accountabilities & Duties

Technology Risk Governance & Oversight

  • Support the development, implementation, maintenance, and continuous enhancement of DUCA’s Technology Risk Management Framework, policies, standards, procedures, methodologies, and reporting processes. Provide independent risk oversight and effective challenge of first-line technology and cybersecurity risk management activities to ensure technology risks are identified, assessed, managed, monitored, and reported within approved risk appetite and regulatory expectations.
  • Partner with Technology, Information Security, Internal Audit, Compliance, and business stakeholders to strengthen governance processes, promote sound risk management practices, and support a strong risk culture across the organization.

 Technology Risk Assessment & Monitoring

  • Provide risk oversight, guidance, and effective challenge of technology and information security risk assessments conducted by Technology, Information Security, and business stakeholders across IT infrastructure, applications, cloud and SaaS environments, cybersecurity controls, AI and emerging technologies, third-party technology providers, operational resilience activities, disaster recovery capabilities, and technology change initiatives to ensure risks are appropriately identified, assessed, and managed.
  • Evaluate risks related to system availability, operational stability, technology currency and end-of-life platforms, cybersecurity threats, data protection, access management, privacy, operational disruptions, and technology transformation initiatives. Assess the design and operating effectiveness of controls, challenge risk mitigation strategies and risk acceptance decisions, and maintain technology risk registers, issues, and remediation plans to support ongoing risk management and reporting.

 Cybersecurity & Operational Resilience Risk Oversight

  • Provide risk oversight and effective challenge of key technology and cybersecurity risk management processes, including IT incident management, cybersecurity incident response, vulnerability management, privileged access management, patch management, IT change management, technology currency management, technical debt management, and risks associated with end-of-support and end-of-life technologies.
  • Assist in the oversight of operational resilience, business continuity, and disaster recovery programs by reviewing resilience assessments, recovery capabilities, technology dependencies, scenario testing results, and remediation activities designed to strengthen the organization’s ability to withstand and recover from disruptive events.

 Third-Party Technology & Cloud Risk Management

  • Review and challenge technology vendor, cloud service provider, and outsourced technology risk assessments, including security reviews, SOC reports, operational resilience capabilities, disaster recovery arrangements, data protection controls, and contractual risk provisions to ensure risks are appropriately identified, assessed, and managed throughout the vendor lifecycle.
  • Partner with vendor relationship managers, Technology teams, and Information Security stakeholders to support the effective management of technology vendor risks and ensure compliance with DUCA’s Vendor Management Framework, Technology Risk Framework, and regulatory expectations

 Regulatory Compliance, Reporting & Stakeholder Management

  • Monitor and report on Key Risk Indicators (KRIs), Key Control Indicators (KCIs), technology incidents, vulnerabilities, outages, emerging risks, and remediation activities.
  • Develop and maintain technology and cybersecurity risk reporting for Senior Management, Executive Leadership, Risk Committees, and the Board highlighting key risk indicators, trends, and their business impact and implications.
  • Support compliance with applicable FSRA guidance, cybersecurity and operational resilience expectations, privacy requirements, internal policies and standards, and recognized industry frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and ITIL.
  • Track and monitor remediation activities related to audit findings, regulatory observations, risk assessments, control deficiencies, cybersecurity reviews, and technology risk issues while maintaining effective working relationships with regulators, auditors, external stakeholders, and business partners.

Occupational Experience & Education Requirements

  • Undergrade degree in Information Technology, Computer Science, Cybersecurity, Business, Finance, Risk Management, or a related discipline.
  • Minimum 5 to 8 years of progressive experience in Technology Risk Management, Information Security, Cybersecurity Risk, Operational Risk, IT Governance, or related disciplines within a financial institution, credit union, banking, insurance, or other regulated environment.
  • Demonstrated experience conducting risk assessments, evaluating control effectiveness, facilitating issue remediation, and preparing risk reporting for senior management and governance committees.
  • Experience working within a Three Lines of Defense governance model and supporting interactions with regulators, auditors, and external assessors.
  • Experience applying regulatory expectations and industry frameworks, including FSRA guidance and regulatory expectations, NIST Cybersecurity Framework, ISO 27001, COBIT, ITIL, CIS Critical Security Controls, Privacy and data protection requirements.

 Knowledge, Skills & Attributes

  • Strong understanding of IT infrastructure, cloud computing, SaaS solutions, cybersecurity controls, IT service management, operational resilience, business continuity, disaster recovery, and technology lifecycle management.
  • Strong analytical, critical thinking, and problem-solving skills with the ability to assess complex technology and cybersecurity risks and translate technical concepts into business impacts.
  • Ability to provide independent challenge and influence stakeholders across Technology, Information Security, and business functions while maintaining collaborative working relationships.
  • Strong understanding of technology risk management, cybersecurity, operational resilience, cloud risk, third-party risk, and governance frameworks.
  • Excellent organizational skills with the ability to manage multiple priorities, projects, deadlines, and competing stakeholder demands within a fast-paced environment.
  • Strong written and verbal communication skills, including experience preparing executive-level reports, committee materials, and presentations.
  • Demonstrated ability to build effective relationships across all levels of the organization and interact professionally with regulators, auditors, vendors, and external stakeholders.
  • Strong attention to detail, professional judgement, governance discipline, and risk awareness.
  • Experience with governance, risk and compliance (GRC) platforms, reporting tools, data analytics, process mapping, and dashboard development considered an asset.

Working Conditions

Normal office environment with the potential for extended hours during significant technology incidents, cybersecurity events, regulatory reviews, audits, project implementations, business continuity exercises, and reporting deadlines.


Department: Retail Credit 

Primary Location: Corporate Office 

Employment Status: Full-Time 

Hours per Week: 38

Salary: The annual salary range for this position is $92,798 to $115,998.  Actual annual base salaries will vary depending on relevant job-related factors such as experience, knowledge, skills, qualifications, and education/training. This position may be eligible for discretionary bonuses.

Number of Existing Vacancies: 1


DUCA is committed to employment equity and encourages applications from all qualified candidates. Recruitment related accommodations will be provided upon request.

Our hiring process includes AI screening for keywords and minimum qualifications. Talent Acquisition Partners review all results.

Qualified applicants are encouraged to submit their application. Applications must include a resume.

We thank all applicants but only those considered for an interview will be contacted.