In this role, you will: IT Risk Management and Assessment * Identify, evaluate, and prioritize IT risks across OpenTable's operations. * Oversee regular risk assessments and control certification ...
In this role, you will: IT Risk Management and Assessment * Identify, evaluate, and prioritize IT risks across OpenTable's operations. * Oversee regular risk assessments and control certification ...
You will own the end-to-end delivery of high-impact risk reports to executive and management ... * Support the investigation of emerging risks, taking initiative to engage with SMEs to create ...
You will own the end-to-end delivery of high-impact risk reports to executive and management ... * Support the investigation of emerging risks, taking initiative to engage with SMEs to create ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Access Management * IT governance reviews * IT Third party risk management. * Business continuity and disaster recovery * Cloud security * Data governance assessments and reviews * ERP controls and ...
Manager, Technology Risk and Controls
Toronto, ON ยท On-site
CA$124K - CA$155K/yr
Strong stakeholder management skills, with the ability to influence and build consensus. * Intellectual curiosity and commitment to ongoing learning in technology and risk governance. * Understanding ...
Manager, Technology Risk and Controls
Toronto, ON ยท On-site
CA$124K - CA$155K/yr
Strong stakeholder management skills, with the ability to influence and build consensus. * Intellectual curiosity and commitment to ongoing learning in technology and risk governance. * Understanding ...
This is an exciting opportunity to contribute to a robust risk management framework, collaborate ... Professional technology risk designations i.e. CISA, CRISC, CISSP Nice-to-have * Experience in ...
This is an exciting opportunity to contribute to a robust risk management framework, collaborate ... Professional technology risk designations i.e. CISA, CRISC, CISSP Nice-to-have * Experience in ...
Apply software engineering and architectural expertise to improve risk management. Evaluate technology and operational incidents with a focus on response effectiveness, root cause rigor, and ...
Apply software engineering and architectural expertise to improve risk management. Evaluate technology and operational incidents with a focus on response effectiveness, root cause rigor, and ...
Reporting to the Director, Technology Strategy within Group Risk Management Enterprise Resilience Risk (ERR), you will lead Second Line of Defense engagement across all Regulatory Examinations and ...
Reporting to the Director, Technology Strategy within Group Risk Management Enterprise Resilience Risk (ERR), you will lead Second Line of Defense engagement across all Regulatory Examinations and ...
... Risk Management, plays a critical role in supporting regulatory readiness by leading and ... You will also provide independent Line 2 oversight across Technology and Cyber Security Risk ...
... Risk Management, plays a critical role in supporting regulatory readiness by leading and ... You will also provide independent Line 2 oversight across Technology and Cyber Security Risk ...
Strong understanding of technology and cyber risk management, control effectiveness, risk metrics, and enterprise risk management principles. * Knowledge of cybersecurity concepts, including threats ...
New
Strong understanding of technology and cyber risk management, control effectiveness, risk metrics, and enterprise risk management principles. * Knowledge of cybersecurity concepts, including threats ...
New
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What you'll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units, the ...
Manager, Cyber & Technology Risk
Toronto, ON ยท On-site
CA$79K - CA$131K/yr
What you'll do Reporting to the AVP, Cyber & Technology Risk, and working closely with key stakeholders across Enterprise Risk Management, Cybersecurity, IT, Privacy and other key Business Units, the ...
The successful candidate will supervise Technology & Operations (1st Line of Defense) adherence to the Enterprise Third Party Risk Management Policy and Standards, lead the implementation of third ...
The successful candidate will supervise Technology & Operations (1st Line of Defense) adherence to the Enterprise Third Party Risk Management Policy and Standards, lead the implementation of third ...
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
Sr IT Auditor
Toronto, ON ยท On-site
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
Sr IT Auditor
Toronto, ON ยท On-site
The Senior IT Auditor works closely with business, technology, risk management, compliance, and internal audit stakeholders to identify control gaps, assess technology and cyber risks, and support ...
Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions. * Assess security, compliance, operational, vendor, and ...
New
Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions. * Assess security, compliance, operational, vendor, and ...
New
IT Manager Compliance and Risk Management
Toronto, ON ยท On-site
CA$120K - CA$138K/yr
Advise management on control design and remediation strategies for operating control deficiencies. Audit & Advisory Projects * Plan and execute IT compliance and advisory projects, including risk ...
IT Manager Compliance and Risk Management
Toronto, ON ยท On-site
CA$120K - CA$138K/yr
Advise management on control design and remediation strategies for operating control deficiencies. Audit & Advisory Projects * Plan and execute IT compliance and advisory projects, including risk ...
Engagement risk management: quality assurance through file review, engagement planning, development and monitoring, engagement profitability - Simultaneously deliver multiple client engagements of ...
Engagement risk management: quality assurance through file review, engagement planning, development and monitoring, engagement profitability - Simultaneously deliver multiple client engagements of ...
The role operates across multiple resilience disciplines, including Business Continuity, Disaster Recovery, Technology Resilience, Third Party Risk Management, Crisis Management, Data, Cyber Risk ...
The role operates across multiple resilience disciplines, including Business Continuity, Disaster Recovery, Technology Resilience, Third Party Risk Management, Crisis Management, Data, Cyber Risk ...
The Technology Risk Consulting practice provides a variety of services to our clients. The ... Engagement risk management: quality assurance through file review, engagement planning, development ...
The Technology Risk Consulting practice provides a variety of services to our clients. The ... Engagement risk management: quality assurance through file review, engagement planning, development ...
... Cyber Risk Management & Transformation practice. The successful candidate will support ... This role offers exposure to a broad range of industries, technologies, and strategic initiatives ...
... Cyber Risk Management & Transformation practice. The successful candidate will support ... This role offers exposure to a broad range of industries, technologies, and strategic initiatives ...
Technology Risk Management information
What is a Technology Risk Management job?
A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.
What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?
To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.
What are the typical daily responsibilities for someone working in Technology Risk Management?
Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.

Other
Medical, Dental, Life, Retirement, PTO
Re-posted 19 days ago
Job description
Location: Toronto, Canada (Hybrid Position, in office 2 days per week)
With millions of diners, 60,000+ restaurant partners and 25+ years of experience, OpenTable, part of Booking Holdings, Inc. (NASDAQ: BKNG), is an industry leader with a passion for helping restaurants thrive. Our world-class technology empowers restaurants to focus on what matters most - their team, their guests, and their bottom line - while enabling diners to discover and book the perfect restaurant for every occasion.ย
Every employee at OpenTable has a tangible impact on what we do and how we do it. You'll also be part of a global team and its portfolio of metasearch brands. Hospitality is all about taking care of others, and it defines our culture.
The Role:OpenTable's Finance team is looking for a Manager, IT Risk and Controls! The Manager, IT Risk & Controls is a leadership role responsible for overseeing the design, implementation, and ongoing monitoring of IT risk management and control activities. The purpose is to ensure OpenTable's systems, processes, and data are secure, compliant with regulatory and corporate requirements, and supportive of the company's strategic objectives. This leader acts as a subject matter expert on IT controls, collaborates with internal teams (such as Technology Operations, Security, and Finance), and partners with internal and external auditors.
In this role, you will:
IT Risk Management and Assessment
- Identify, evaluate, and prioritize IT risks across OpenTable's operations.
- Oversee regular risk assessments and control certification/validation activities.
- Monitor emerging IT risks and propose mitigation strategies.
Controls Design and Effectiveness
- Lead the design and implementation of internal controls over technology systems and processes, particularly those supporting financial reporting (e.g., SOX compliance).
- Guide teams in the execution of user access reviews, segregation of duties monitoring, change management controls, and other standard IT controls.
- Maintain documentation of controls, processes, and evidence required for internal and external audits.
Controls Certification and Audit Support
- Manage quarterly and annual control certification and user access review cycles.
- Serve as a liaison between IT, the Finance organization, and external auditors.
- Support ITGC (IT General Controls) management testing.
Remediation and Process Improvement
- Investigate any identified control deficiencies, oversee remediation efforts, and work to strengthen and automate internal controls as appropriate.
- Continuously improve risk management processes using technology, analytics, and cross-functional input.
Stakeholder Engagement
- Partner with cross-functional leaders at OpenTable, supporting business objectives while ensuring a risk-aware culture.
- Present risk and control status updates to senior leadership as needed.
Policy, Governance & Program Management
- Develop and maintain IT risk management policies, control standards, and governance frameworks.
- Ensure alignment with Booking Holdings (BKNG) group policies and broader compliance requirements.
Please apply if you have:
- Bachelor's degree (or above) in IT, Engineering, or Accounting/Finance.
- 7+ years of progressive experience coordinating IT SOX compliance activities and maintaining IT Risk and Control Matrices/Frameworks.
- Leadership experience in IT risk management, audit, compliance, or a related field.
- Deep knowledge of internal controls over financial reporting, information security, and regulatory standards (e.g., SOX, COSO, COBIT, NIST).
- Strong analytical, communication, and stakeholder management skills.
- Experience working with auditors and managing audit processes.
- Ability to collaborate with both technical and non-technical stakeholders.
- Professional certifications (such as CISA, CISSP, CRISC, CIA, or similar) preferred.
- Experience in Big 4 Accounting/Professional Services is preferred.
- Work from (almost) anywhere for up to 20 days per year
- Focus on mental health and well-being:
- Company-paid therapy sessions through SpringHealth
- Company-paid subscription to Headspace
- Annual company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)
- Paid parental leave
- Generous paid vacation + time off for your birthday
- Paid volunteer time
- Focus on your career growth:
- Development Dollars
- Leadership development
- Access to thousands of on-demand e-learnings
- Travel Discounts
- Employee Resource Groups
- 20 days of paid time off
- Private health and dental insurance
- Life and Disability insurance
The best connections happen face-to-face, whether you're sitting down to dinner or having coffee with a coworker. That's why OpenTable has adopted a hybrid workplace model. This role aligns with that approach, with an expectation of coming into the office two days a week-giving employees the best of both worlds: in-person collaboration and flexibility.
The expected range of compensation for this position based in Toronto, Canada, is $120,000-$135,000 CAD. There are a variety of factors that go into determining a compensation range, including but not limited to external market benchmark data, geographic location, and years of experience sought/required.
We offer a competitive base salary and benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits. This role is eligible to be considered for an annual bonus.
Work Environment & Flexibility
At OpenTable, we pride ourselves on fostering a global and dynamic work environment. As a team member with us, you will benefit from a schedule tailored to accommodate a global workforce operating across multiple time zones. While the majority of your responsibilities may align with conventional business hours, there will be instances where you are expected to manage communications - via calls, Slack messages, or emails - outside of regular working hours to effectively collaborate with international colleagues, respond to restaurant partners, and/or address urgent matters. OpenTable will always abide by and consider local laws and regulations.
Inclusion
We're committed to creating a workplace where everyone feels they belong and can thrive. We know the best ideas come when we bring different voices to the table, so we're building a team as dynamic as the diners and restaurants we serve-and fostering a culture where everyone feels welcome to be themselves.
If you need accommodations during the application or interview process, or on the job, we're here to support you. Please reach out to your recruiter to request any accommodations.
#LI-BR1
About OpenTable
Sourced by ZipRecruiter
Industry
Internet and it
Company size
1,001 - 5,000 Employees
Headquarters location
San Francisco, CA, US
Year founded
1998