The Role Director Program Management, reports to the Director & Head, Portfolio Management, IT Risk, supporting the Enterprise Office of the CIO within technology. This role is integral to the ...
The Role Director Program Management, reports to the Director & Head, Portfolio Management, IT Risk, supporting the Enterprise Office of the CIO within technology. This role is integral to the ...
The Senior Director, Cyber and Technology Risk Management is responsible for leading governance and oversight of the cyber and technology risk management practices across RBC's business segments (P ...
The Senior Director, Cyber and Technology Risk Management is responsible for leading governance and oversight of the cyber and technology risk management practices across RBC's business segments (P ...
Business Continuity Management (BCM) / Business Impact Assessment (BIA) Governance - Provide ... Project Risk Assessment (IT Risk Triage) Governance - Lead governance of IT risk triage processes ...
Business Continuity Management (BCM) / Business Impact Assessment (BIA) Governance - Provide ... Project Risk Assessment (IT Risk Triage) Governance - Lead governance of IT risk triage processes ...
Key accountabilities (Risk) Advises and supports risk owners in day to day risk management ... Respond to requests for information technology assessments and questionnaires, providing ...
Key accountabilities (Risk) Advises and supports risk owners in day to day risk management ... Respond to requests for information technology assessments and questionnaires, providing ...
Own execution and accountability for Technology Risk Management and Internal Controls within the First Line of Defense (1B). * Provide direction and oversight to Technology 1A risk owners to ...
Own execution and accountability for Technology Risk Management and Internal Controls within the First Line of Defense (1B). * Provide direction and oversight to Technology 1A risk owners to ...
This role is part of a strategic and comprehensive IT Risk Management Function within the Global Technology Control Testing team and ensures design and implementation in accordance with regulatory ...
This role is part of a strategic and comprehensive IT Risk Management Function within the Global Technology Control Testing team and ensures design and implementation in accordance with regulatory ...
Director Cyber and Technology Risk - Cloud, Architecture, Emerging Technologies
Toronto, ON · Hybrid
As part of the Group Risk Management (GRM) Enterprise Resilience Risk team, the Director, Cyber & Technology Risk will be responsible for providing Cyber and IT Risk Management subject matter ...
Director Cyber and Technology Risk - Cloud, Architecture, Emerging Technologies
Toronto, ON · Hybrid
As part of the Group Risk Management (GRM) Enterprise Resilience Risk team, the Director, Cyber & Technology Risk will be responsible for providing Cyber and IT Risk Management subject matter ...
As part of the Group Risk Management team, the Associate Director, Cyber and Technology Risk will support IT/Cyber Risk Management leadership within Enterprise Resilience Risk team in delivering ...
As part of the Group Risk Management team, the Associate Director, Cyber and Technology Risk will support IT/Cyber Risk Management leadership within Enterprise Resilience Risk team in delivering ...
This role partners with technology leadership, risk management teams, and control owners to identify, assess, and mitigate technology risks while ensuring alignment with the bank's enterprise risk ...
This role partners with technology leadership, risk management teams, and control owners to identify, assess, and mitigate technology risks while ensuring alignment with the bank's enterprise risk ...
Support the Director IT Risk Governance, Standards and Controls and lead the governance and ... Own and maintain the Bank's technology and cyber issues management process * Lead the design and ...
Support the Director IT Risk Governance, Standards and Controls and lead the governance and ... Own and maintain the Bank's technology and cyber issues management process * Lead the design and ...
The purpose of this role is to enable proactive technology and cyber risk management-anticipating risk, identifying areas of weakness, and surfacing where risk can be better managed so leadership can ...
The purpose of this role is to enable proactive technology and cyber risk management-anticipating risk, identifying areas of weakness, and surfacing where risk can be better managed so leadership can ...
The incumbent will work closely with risk and technology teams across CPT and the broader ... Monitor vulnerability management reporting, server hygiene, and penetration test vulnerabilities ...
The incumbent will work closely with risk and technology teams across CPT and the broader ... Monitor vulnerability management reporting, server hygiene, and penetration test vulnerabilities ...
Cyber and Technology Risk Management * Third Party Cyber Risk Management * Cyber Strategy, Governance, and Delivery * Delivery Excellence: * Oversee multidisciplinary teams delivering cyber programs ...
Cyber and Technology Risk Management * Third Party Cyber Risk Management * Cyber Strategy, Governance, and Delivery * Delivery Excellence: * Oversee multidisciplinary teams delivering cyber programs ...
In this role, you will: IT Risk Management and Assessment * Identify, evaluate, and prioritize IT risks across OpenTable's operations. * Oversee regular risk assessments and control certification ...
In this role, you will: IT Risk Management and Assessment * Identify, evaluate, and prioritize IT risks across OpenTable's operations. * Oversee regular risk assessments and control certification ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
This is an exciting opportunity to contribute to a robust risk management framework, collaborate ... Professional technology risk designations i.e. CISA, CRISC, CISSP Nice-to-have * Experience in ...
This is an exciting opportunity to contribute to a robust risk management framework, collaborate ... Professional technology risk designations i.e. CISA, CRISC, CISSP Nice-to-have * Experience in ...
Manager AI / Governance / Technology Risk
Toronto, ON · On-site
CA$90K - CA$110K/yr
You will play a key role in helping clients implement practical governance and risk management structures for AI and emerging technologies. Key Responsibilities * Lead and deliver engagements across ...
Manager AI / Governance / Technology Risk
Toronto, ON · On-site
CA$90K - CA$110K/yr
You will play a key role in helping clients implement practical governance and risk management structures for AI and emerging technologies. Key Responsibilities * Lead and deliver engagements across ...
Assess control design and operating effectiveness across key technology domains (e.g., access management, change management, resiliency, third-party risk). * Identify control gaps, emerging risks ...
Assess control design and operating effectiveness across key technology domains (e.g., access management, change management, resiliency, third-party risk). * Identify control gaps, emerging risks ...
IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data ... Operational experience with Canadian or US regulations for technology risk, e.g. OSFI B13, E21, etc.
IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data ... Operational experience with Canadian or US regulations for technology risk, e.g. OSFI B13, E21, etc.
Technology Risk Management information
See Ontario salary details
$28.5K - $42K
5% of jobs
$42K - $55.5K
6% of jobs
$55.5K - $69K
4% of jobs
$69K - $82.5K
5% of jobs
$89.3K is the 25th percentile. Wages below this are outliers.
$82.5K - $96K
8% of jobs
$96K - $109.5K
11% of jobs
The median wage is $114.8K / yr.
$109.5K - $123K
24% of jobs
$132K is the 75th percentile. Wages above this are outliers.
$123K - $136.5K
16% of jobs
$136.5K - $150K
8% of jobs
$150K - $163.5K
7% of jobs
$163.5K - $177K
4% of jobs
$28.5K
$112.1K
$177K
How much do technology risk management jobs pay per year?
What is a Technology Risk Management job?
A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.
What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?
To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.
What are the typical daily responsibilities for someone working in Technology Risk Management?
Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.
Other
Medical, Dental, Vision, Retirement, PTO
Posted 7 days ago
Job description
Requisition ID: 263253Â
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
The Role
Director Program Management, reports to the Director & Head, Portfolio Management, IT Risk, supporting the Enterprise Office of the CIO within technology. This role is integral to the delivery of project and program portfolio and is accountable primarily for leading the provision of risk management guidance and oversight to Internal Audit and regulatory remediation projects.
With in-depth knowledge of Operational IT Risk and regulatory remediation experience, the Director Program Management brings a risk management mindset to Audit and regulatory remediation projects and drives increased quality of risk remediation project deliverables and achieve greater alignment with QA processes, Internal Audit and regulatory expectations.
This dynamic position provides opportunities for the ideal candidate to collaborate with cross-functional teams across the enterprise and work to deliver complex enterprise-wide initiatives as part of Scotiabank's ongoing plan to improve IT Risk Management and governance.Â
What will you do?
  Risk Management Leadership: Provide risk management leadership for assigned portfolio and serve as a key advisor to executive leadership and project teams on technology risk management within IT risk remediation projects. Â
  Enterprise Risk Awareness: Maintaining a thorough understanding of Scotiabank's policies and standards, internal controls and IT control testing methodologies as well as related regulatory and industry compliance standards.  Understand how the Bank's risk appetite and risk culture should be considered in day-to-day risk remediation initiatives and decisions.
  Strategic Planning: Provide strategic direction and leadership to cross-functional teams, ensuring alignment with ScotiaTech's strategic goals and business objectives, while cultivating a consistent and standardized approach to producing risk aligned audit and regulatory project deliverables.
  Project Support: Provide operational risk expertise support to regulatory projects   Provide risk management support for planning and prioritizing initiatives across portfolios that support business strategy.
 Support the remediation of regulatory and compliance gaps, including the creation and maintenance of artifacts related to regulatory compliance, such as process documentation, narratives, and metrics.
  Review remediation plans and corrective actions to ensure that they are designed to reduce risk. Verify that control deficiencies are remediated according to the remediation plans.Â
 Review project deliverables and artefacts, including project closure packages to ensure they meet internal IQA standards and expectations, and adhere to industry best practices and regulatory requirements.  Provide feedback to drive alignment and compliance.
 Work with project teams throughout all phases of program and project management including planning, execution, monitoring, and closure to ensure successful delivery of expected outcomes.
  Effective Communication: Consistently interact with stakeholders to manage technology risk management expectations and deliverables within allocated project timelines and budget.
  Champion Risk Awareness: Champion the adoption of industry risk management best practices in project delivery and drive operational IT risk awareness culture.  Identify and implement continuous improvements to IT risk management practices, tools, and processes within EDO delivery and portfolio management group.
  Industry Risk Awareness: Keep abreast of external cyber security trends, technologies and cyber risk management approaches, control hygiene of the environment, and often collaborate with other teams on IT risk-related initiatives to provide subject-matter recommendations and guidance to achieve a risk posture within the organization's overall risk appetite
  Manage Priorities: Manage multiple priorities in a fast-paced environment. Identify, de-escalate, and manage actual or perceived conflict, if any, among your team or with the stakeholders.Â
  Decision Making: Assess complex scenarios and use your subject matter expertise and professional judgement to make decisions with proper rationale and documentation. Support your team member during complex or tough discussions with stakeholders to achieve the desired outcome.Â
  Stakeholder Engagement: Build and maintain strong relationships with key stakeholders, including business leaders, technology teams, and external partners, to ensure alignment and transparency throughout project lifecycles.
  Talent Development: Manage a team of risk management and documentation professionals, mentor and develop talent within the team, fostering a culture of growth and excellence. Build a high-performance environment and implement a people strategy that attracts, retains, develops, and motivates the team by fostering an inclusive work environment and using a coaching mindset and behaviors.  Communicate vison/values/business strategy and manage succession and development planning for the team
  Team Environment: Create an environment in which their team pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk. Â
What do you need to succeed?
  Bachelor's degree in Business, Technology, Engineering or related fields, or equivalent experience.
  10+ years of experience in IT Risk Management, risk assurance, audit, or cybersecurity leadership roles, preferably in the financial services industry
  Working knowledge of key IT infrastructure, including good understanding of the risks associated with the platforms.Â
  Knowledge of IT Risk frameworks, methodologies and industry standards related to IT and Cyber Risk management, including emerging trends and issues. Demonstrated expertise in a broad range of Information Security and Risk Management principles and practices.Â
  Industry recognized qualifications and certifications in Information Security and/or Risk Management (CISA/CISM/CISSP /CRISC/CISSP) is a plus
  Maturity level and skill/judgment to deal effectively with senior management and operational risk groups throughout the organization.Â
  Exceptional communication, negotiation, and stakeholder management skills, including strong appreciation of relationship management;Â
  Strong analytical and data-driven decision-making skills, including sound problem solving, research, and quantitative skills.Â
  Deadline-driven and results-oriented; able to meet consistently high-quality standards while handling a variety of tasks and deadlines simultaneously.Â
  Proven ability to navigate ambiguity, drive strategic change, and influence senior stakeholders.
  Experience working across cross-functional teams and collaborating with stakeholders at all levels of the organization.
  Experience leading, design and execution of IT risk management frameworks, policies, and procedures.
  Proven ability with monitoring regulatory changes and industry trends to ensure ongoing compliance and best practices.
  7+ years managing and developing high-performing teams
  Self-discipline and organized with proven time management skills
  Ability to thrive in a fast-paced, dynamic, and changing environment
        Â
What's in it for you?
We have an inclusive and collaborative working environment that encourages creativity and curiosity and celebrates success
  We provide you with the tools and technology needed to create meaningful customer experiences
  You'll get to work with and learn from diverse industry leaders, who have hailed from top technology companies around the world
  We hire you for your talent - not just a job - so you can grow with us. We'll equip you for success not only in your role, but also in your career as a whole
  Dress codes don't apply here: being comfortable does
  Access to thousands of online and in-person courses so you can hone your current skills, or learn new ones
  A competitive rewards package that includes a base salary, a performance bonus, company matching programs on pension and profit sharing, paid vacation, personal & sick days, medical, vision, and dental and much more
Location(s): Â Canada : Ontario : TorontoÂ
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets. Â
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
About Scotiabank
Sourced by ZipRecruiter
Industry
Banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
New York, NY, US