Manulife is seeking a Director, Information Risk Management, as a Line 2 leadership role ... Ensure technology and data risks are clearly articulated, quantified where possible, and aligned to ...
Manulife is seeking a Director, Information Risk Management, as a Line 2 leadership role ... Ensure technology and data risks are clearly articulated, quantified where possible, and aligned to ...
Manager AI / Governance / Technology Risk
Toronto, ON ยท On-site
CA$90K - CA$110K/yr
You will play a key role in helping clients implement practical governance and risk management structures for AI and emerging technologies. Key Responsibilities * Lead and deliver engagements across ...
Manager AI / Governance / Technology Risk
Toronto, ON ยท On-site
CA$90K - CA$110K/yr
You will play a key role in helping clients implement practical governance and risk management structures for AI and emerging technologies. Key Responsibilities * Lead and deliver engagements across ...
Reporting to the Director, Technology Strategy within Group Risk Management Enterprise Resilience Risk (ERR), you will lead Second Line of Defense engagement across all Regulatory Examinations and ...
Reporting to the Director, Technology Strategy within Group Risk Management Enterprise Resilience Risk (ERR), you will lead Second Line of Defense engagement across all Regulatory Examinations and ...
Manager, Cyber & Technology Risk
CA$79K - CA$131K/yr
What you'll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units, the ...
Manager, Cyber & Technology Risk
CA$79K - CA$131K/yr
What you'll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units, the ...
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What youu2019ll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units ...
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What youu2019ll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units ...
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What youu2019ll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units ...
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What youu2019ll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units ...
The successful candidate will supervise Technology & Operations (1st Line of Defense) adherence to the Enterprise Third Party Risk Management Policy and Standards, lead the implementation of third ...
The successful candidate will supervise Technology & Operations (1st Line of Defense) adherence to the Enterprise Third Party Risk Management Policy and Standards, lead the implementation of third ...
IT Manager Compliance and Risk Management
CA$120K - CA$138K/yr
Advise management on control design and remediation strategies for operating control deficiencies. Audit & Advisory Projects * Plan and execute IT compliance and advisory projects, including risk ...
IT Manager Compliance and Risk Management
CA$120K - CA$138K/yr
Advise management on control design and remediation strategies for operating control deficiencies. Audit & Advisory Projects * Plan and execute IT compliance and advisory projects, including risk ...
Engagement risk management: quality assurance through file review, engagement planning, development and monitoring, engagement profitability - Simultaneously deliver multiple client engagements of ...
Engagement risk management: quality assurance through file review, engagement planning, development and monitoring, engagement profitability - Simultaneously deliver multiple client engagements of ...
This role is part of a strategic and comprehensive IT Risk Management Function within the Global Technology Control Testing team and ensures design and implementation in accordance with regulatory ...
This role is part of a strategic and comprehensive IT Risk Management Function within the Global Technology Control Testing team and ensures design and implementation in accordance with regulatory ...
The Technology Risk Consulting practice provides a variety of services to our clients. The ... Engagement risk management: quality assurance through file review, engagement planning, development ...
The Technology Risk Consulting practice provides a variety of services to our clients. The ... Engagement risk management: quality assurance through file review, engagement planning, development ...
... technology risk management. Executive Reporting: 3+ years of dedicated experience crafting ... executive-grade risk reports and presentations for C-suite or steering committees. Technical & Core ...
... technology risk management. Executive Reporting: 3+ years of dedicated experience crafting ... executive-grade risk reports and presentations for C-suite or steering committees. Technical & Core ...
System asset management tooling. * Supporting assessments for broader information security topics as well as IT General Controls (ITGCs). * Monitoring relevant technology risk standards and practices.
System asset management tooling. * Supporting assessments for broader information security topics as well as IT General Controls (ITGCs). * Monitoring relevant technology risk standards and practices.
System asset management tooling. * Supporting assessments for broader information security topics as well as IT General Controls (ITGCs). * Monitoring relevant technology risk standards and practices.
System asset management tooling. * Supporting assessments for broader information security topics as well as IT General Controls (ITGCs). * Monitoring relevant technology risk standards and practices.
The Senior Director partners closely with Technology, Legal/Privacy, Product, and Go-to-Market ... Manage third-party/vendor risk through due diligence, contractual requirements, and ongoing ...
The Senior Director partners closely with Technology, Legal/Privacy, Product, and Go-to-Market ... Manage third-party/vendor risk through due diligence, contractual requirements, and ongoing ...
Director, Risk Management
Burlington, ON ยท On-site
The Director, Risk Management will lead the core ERM processes, including the risk taxonomy, risk ... and technology risks. * Promote a strong risk culture by helping business teams understand ...
Director, Risk Management
Burlington, ON ยท On-site
The Director, Risk Management will lead the core ERM processes, including the risk taxonomy, risk ... and technology risks. * Promote a strong risk culture by helping business teams understand ...
Manager, Vendor & Risk Management
Toronto, ON ยท On-site
... Risk Management to add to our team in Toronto ... You'll be working as part of a small, innovative team to help enable technology enhancements within ...
Manager, Vendor & Risk Management
Toronto, ON ยท On-site
... Risk Management to add to our team in Toronto ... You'll be working as part of a small, innovative team to help enable technology enhancements within ...
Manager, Risk Management
Toronto, ON ยท On-site
You will lead, direct, and oversee operational risk management activities to ensure the risk ... TECHNOLOGY AND OPERATIONS Job Type: Regular Pay Type: Salaried Posted Date: 2026-06-11 Application ...
Manager, Risk Management
Toronto, ON ยท On-site
You will lead, direct, and oversee operational risk management activities to ensure the risk ... TECHNOLOGY AND OPERATIONS Job Type: Regular Pay Type: Salaried Posted Date: 2026-06-11 Application ...
Conduct access reviews and assessments to ensure appropriate high risk access management practices are being followed and address any gaps using IT risk management practices. * Lifecycle Risk ...
Conduct access reviews and assessments to ensure appropriate high risk access management practices are being followed and address any gaps using IT risk management practices. * Lifecycle Risk ...
Technology Risk Management information
What is a Technology Risk Management job?
A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.
What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?
To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.
What does technology risk management do?
What is the highest paying risk management job?
Is risk management a good career?
What are the typical daily responsibilities for someone working in Technology Risk Management?
Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.
How much do technology risk consultants make?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 11 days ago
Key responsibilities
Provide independent challenge and oversight to first-line technology and data leaders on risk design, control effectiveness, and residual risk exposure.
Drive adoption of workflow-based risk management and support the design of automated risk workflows and orchestration patterns.
Oversee risks across technology, data, infrastructure, platforms, and corporate function systems to ensure alignment with risk appetite, regulatory obligations, and governance directives.
Job description
Manulife is seeking a Director, Information Risk Management, as a Line 2 leadership role responsible for independent oversight, challenge, and governance of risks across Manulife's global technology enterprise. This position will participate in the design and execution of a fit-for-purpose risk oversight framework to ensure that technology, data, and corporate function platforms are designed, operated, and evolved in alignment with Manulife's risk appetite, regulatory obligations, and governance directives, while enabling speed, resilience, and innovation.
Position Responsibilities:
Independent Challenge & Oversight:
Provide credible, independent challenge to first-line technology and data leaders on risk design, control effectiveness, and residual risk exposure.
Assess and opine on the adequacy of technology, infrastructure, data, platform and application controls against internal standards, regulatory expectations, and industry best practices.
Ensure technology and data risks are clearly articulated, quantified where possible, and aligned to risk appetite.
Review and challenge material risk acceptances, control exceptions, and remediation plans.
Domain Level Challenge and Oversight:
Challenge operational resilience, capacity management, monitoring, patching, vulnerability, identity, and access control practices.
Oversight of risks related to cloud, on-prem infrastructure, networks, end-user computing, resilience, availability, disaster recovery, and third-party dependencies.
Ensure strong alignment between data governance, data risk, model risk, and information security
Oversight of data risk across data platforms, analytics, AI/ML, data quality, lineage, privacy, and regulatory data obligations.
Oversight of technology risks supporting Finance, HR, Legal, Compliance, Risk, and Internal Audit systems.
Challenge risks associated with financial reporting technology, regulatory reporting, and corporate data.
Ability to stay abreast of new and emerging regulatory requirements as well as emerging and evolving risks
GRC Workflow, Automation and Orchestration:
Drive adoption of workflow-based risk management, ensuring risks, controls, issues, exceptions, and attestations are consistent, adequate, reasonable and effective through standardized and automated practices that are traceable end-to-end
Support the design of event-driven risk workflows integrating automated control monitoring mechanisms from source systems (e.g, CI/CD, Observability, Ticketing, Lakes, Warehouses) to reduce manual assessments
Support the design of orchestration patterns that connect risk assessments, business continuity and disaster recovery, control testing, issue management, incident root cause analysis, vendor risk concurrences, regulatory obligations and audit and examination responses
Provide unbiased and evidence-based oversight to ensure that risk assessments not only meet regulatory requirements but also align with Manulife's strategic objectives and risk appetite, fostering continuous improvement in the organization's cybersecurity posture.
Key Deliverables and Outcomes:
Clear, consistent second-line risk opinions across infrastructure, data, and corporate technology.
Reduced manual risk processes through workflow automation and orchestration.
Improved timeliness, quality, and transparency of technology and data risk reporting.
Strong regulatory confidence in Manulife's technology risks governance model.
Demonstrable alignment between risk appetite, controls, and business outcomes.
Required Qualifications:
12+ years in Technology Risk, Information Risk Management, Cyber Risk, with 5+ years in a risk leadership or second-line oversight role.
Deep experience within financial services, insurance, or wealth management in a global context.
Proven ability to challenge senior technology and data leaders with credibility, capable of translating technical risks into business impact.
Experience leading or influencing globally distributed teams.
Demonstrated oversight of Infrastructure & Operations, Cloud and hybrid environments, Data platforms and analytics and corporate enterprise applications.
Strong understanding of GRC workflows, including business goals, governance, risk management, controls, compliance, audit and assurance and improvement
Familiarity with GRC platforms (e.g. Archer, ServiceNow, Fusion).
Working knowledge of Global Regulatory Guidelines and Control frameworks (CSA STAR for AI, CCM, ISO, NIST, COBIT, COSO).
Bilingualism (English and French) is a strong asset. If the successful candidate is in Quebec, proficiency in both languages will be required to support clients from various provinces outside of Quebec.
Preferred Qualifications:
Experience in applying engineering principles to risk management, exposure to automated control monitoring and evidence collection, and a background partnering closely with Operations and Platform teams.
When you join our team:
We'll empower you to learn and grow the career you want.
We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
As part of our global team, we'll support you in shaping the future you want to see.
#LI-Hybrid
The role being advertised is an existing vacancy.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact hr@manulife.com.
Referenced Salary Location
Toronto, OntarioWorking Arrangement
Salary range is expected to be between
$113,260.00 CAD - $210,340.00 CADEmployees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. If you are applying for this role outside of the primary location, please contact hr@manulife.com for the salary range for your location.
Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S., please contact hr@manulife.com for more information about U.S.-specific paid time off provisions.
We use data and analytics technologies, such as artificial intelligence (AI), and automated processing tools, to analyze and process the information you provide to us or third parties in the application process. For more information, please refer to our personal information collection statement.