Cybersecurity - Financial Services (FSO) - Senior Consultant

EY

Calgary

On-site

CAD 90,000 - 136,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Mental health benefits
Employee Assistance Program
Group savings plans
Paid time off and holidays
Volunteer opportunities

Job summary

EY Calgary seeks a Senior Consultant to work with large organizations, evaluating how cybersecurity capabilities are designed, implemented, governed, measured, automated, and sustained within complex environments. You will lead assessments and translate findings into practical recommendations.

The role requires deep knowledge of cyber risk, governance, and multiple frameworks, plus strong written communication and stakeholder facilitation skills.

Qualifications

  • Hands‑on experience delivering cybersecurity maturity, capability, risk, controls, assurance, or transformation assessments.
  • Demonstrated ability to independently lead a workstream or assessment domain from information gathering through final reporting.
  • Working knowledge of common cyber and IT frameworks, with the ability to apply outcomes to real capabilities and environments.
  • Broad understanding across multiple cybersecurity domains with depth in two or three areas.
  • Experience facilitating stakeholder interviews or workshops and communicating with technical and senior leaders.
  • Strong analytical judgment and ability to form conclusions from incomplete or varied information.
  • Excellent written communication including findings, recommendations and executive summaries.

Responsibilities

  • Own assigned cybersecurity domains through assessment planning, artifact requests, document review, stakeholder workshops, maturity analysis, quality review, and reporting.
  • Translate framework outcomes into practical, capability-based assessment criteria for the client environment.
  • Review policies, standards, procedures, architectures, inventories, metrics and reports to understand the current state.
  • Plan and facilitate interviews and workshops with cybersecurity leaders, engineers, risk teams, and owners.
  • Draft concise current-state observations, maturity rationales and practical recommendations.
  • Prepare executive-ready materials and support client leadership presentations.
  • Guide Consultants, review workpapers and maintain cross-domain consistency; elevate issues early.
  • Contribute to refining assessment methodologies and reusable intellectual property.

Skills

Cybersecurity maturity
Assessment leadership
Framework knowledge
Stakeholder facilitation
Executive communication
Analytical judgment
Mentor/coach junior team

Education

CISSP/CISM/CRISC/CISA (certifications)

Tools

NIST CSF 2.0
NIST SP 800-53
ISO 27001/27002
COBIT

Job description

At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

The Senior Consultant will work with large, complex organizations to evaluate how effectively cybersecurity capabilities are designed, implemented, governed, measured, automated, and sustained. The role is broader than compliance mapping or control testing. It requires the ability to understand how people, process, technology, governance, and risk considerations work together across an enterprise cybersecurity program.

This job posting relates to an existing vacancy within our organization.

Key Responsibilities
  • Own assigned cybersecurity domains through assessment planning, artifact requests, document review, stakeholder workshops, maturity analysis, quality review, and reporting.
  • Translate framework outcomes and other industry guidance into practical, capability-based assessment criteria appropriate to the client environment.
  • Review policies, standards, procedures, operating models, architectures, inventories, metrics, reports, and technical documentation to understand the current state.
  • Plan and facilitate interviews and workshops with cybersecurity leaders, architects, engineers, risk teams, and control or capability owners.
  • Ask targeted follow‑up questions, appropriately challenge unsupported statements, and identify where further validation is required.
  • Synthesize stakeholder input, artifacts, metrics, and technical context into consistent and defensible maturity conclusions.
  • Draft concise current‑state observations, maturity rationales, opportunities for improvement, risk implications, and practical recommendations.
  • Connect detailed domain findings to broader themes, business impacts, target‑state considerations, and prioritized improvement actions.
  • Prepare clear, executive‑ready materials and support presentations to client leadership.
  • Guide Consultants, review draft analyses and workpapers, maintain consistency across domains, and elevate issues early.
  • Contribute to the refinement of assessment methodologies, capability libraries, reporting approaches, and reusable intellectual property.
To qualify for the role you must have
  • Hands‑on experience delivering cybersecurity maturity, capability, risk, controls, assurance, or transformation assessments.
  • Demonstrated ability to independently lead a workstream or assessment domain from information gathering through final reporting.
  • Working knowledge of common cyber and IT frameworks, with the ability to explain how framework outcomes apply to real cybersecurity capabilities and operating environments.
  • Broad understanding across multiple cybersecurity domains, with meaningful depth in at least two or three areas.
  • Experience facilitating stakeholder interviews or workshops and communicating with both technical practitioners and senior leaders.
  • Strong analytical judgment, including the ability to form supportable conclusions from incomplete, varied, or conflicting information.
  • Excellent written communication skills, including findings, recommendations, presentations, and executive summaries.
  • Ability to manage multiple domains, stakeholders, and deliverables while maintaining quality and consistency.
  • Experience coaching junior team members and reviewing their work.
Ideally, you’ll also have
  • Experience applying NIST CSF 2.0, including Functions, Categories, Subcategories, Current Profiles, and Target Profiles.
  • Familiarity with NIST SP 800‑53, CIS Controls, ISO/IEC 27001 and 27002, COBIT, CRI Profile, CSA CCM, or related cyber‑risk frameworks.
  • Experience in banking, insurance, payments, or another highly regulated and federated enterprise environment.
  • Familiarity with Canadian financial‑services expectations such as OSFI B‑13 or other relevant regulatory guidance.
  • Experience developing maturity models, target states, cyber roadmaps, benchmarking insights, or transformation recommendations.
  • Relevant cybersecurity or risk certification such as CISSP, CISM, CRISC, CISA, ISO 27001, CCSP, or equivalent credential. Certifications are considered supporting qualifications rather than a substitute for practical delivery experience.
Cybersecurity domain coverage

Candidates are not expected to be specialists in every domain. The strongest profiles will demonstrate depth in selected areas and working fluency across several others.

Governance and risk

Cyber governance, policy and standards, security metrics, second‑line cyber risk, third‑party risk, privacy

Identity and data

IAM, PAM, customer identity, data protection, data security, cryptography

Applications and engineering

Application security, API security, DevSecOps, secure software development, cloud security, AI security

Infrastructure and operations

Network security, endpoint security, vulnerability management, configuration management, asset management

Detection and resilience

Security operations, threat management, incident response, insider risk, forensics, disaster recovery, business continuity

What We Look For

We’re interested in intellectually curious people with a genuine passion for cybersecurity. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.

What We Offer You

The EY benefits package is designed to support your physical, emotional, financial, and social wellbeing. Our extensive benefits include comprehensive medical, dental, and prescription drug coverage, as well as mental health benefits, a robust Employee Assistance Program and group savings plans to promote your overall wellbeing. We offer generous time off, including personal days, vacation days, and additional firm‑wide holidays, along with the option to purchase extra vacation days. Employees can take advantage of EY's exclusive learning programs tailored just for them. We also provide internal opportunities for career development and advancement, enabling you to grow within the firm. Get involved in meaningful volunteering through EY Ripples and make a positive impact in the community.

  • Toronto/Calgary/Vancouver/Edmonton/Montreal: $90,000 to 136,000 per year
Inclusiveness at EY

Inclusiveness is at the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.

Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience. While AI supports us in our process, human judgment and decision-making remain integral in our candidate experience. We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity - Financial Services (FSO) - Senior Consultant
Cybersecurity - Financial Services (FSO) - Senior Consultant

EY • Montreal (administrative region)

On-site
CAD 90,000 - 136,000
Cybersecurity - Financial Services (FSO) - Senior Consultant
Cybersecurity - Financial Services (FSO) - Senior Consultant

EY • Edmonton

On-site
CAD 90,000 - 136,000
Medical coverage
Dental coverage
Prescription drugs
+6
Cybersecurity - Financial Services (FSO) - Senior Consultant
Cybersecurity - Financial Services (FSO) - Senior Consultant

EY • Toronto

On-site
CAD 90,000 - 136,000
Medical insurance
Dental coverage
Mental health benefits
+2
Cybersecurity - Financial Services (FSO) - Senior Consultant
Cybersecurity - Financial Services (FSO) - Senior Consultant

Ernst & Young Advisory Services Sdn Bhd • Toronto

On-site
CAD 90,000 - 136,000
Medical coverage
Dental coverage
Employee Assistance Program
+2
Cybersecurity - Cloud Security - Senior Consultant
Cybersecurity - Cloud Security - Senior Consultant

EY • Calgary

On-site
CAD 90,000 - 136,000
Competitive compensation
Total Rewards package
Pension plan
+2
Cybersecurity - Cloud Security - Senior Consultant
Cybersecurity - Cloud Security - Senior Consultant

EY • Toronto

On-site
CAD 90,000 - 136,000
Competitive compensation
Medical, prescription drug and dental
Defined contribution pension plan
+2
Cybersecurity - Data Protection - Senior Consultant
Cybersecurity - Data Protection - Senior Consultant

EY • Vancouver

On-site
CAD 90,000 - 136,000
Cybersecurity - Data Protection - Senior Consultant
Cybersecurity - Data Protection - Senior Consultant

EY • Toronto

On-site
CAD 90,000 - 136,000
Cybersecurity - Data Protection - Senior Consultant
Cybersecurity - Data Protection - Senior Consultant

EY • Calgary

On-site
CAD 90,000 - 136,000
Support and coaching from some of the
Learning opportunities to develop new
The freedom and flexibility to handle
Cybersecurity - Cyber Threat Readiness - Manager
Cybersecurity - Cyber Threat Readiness - Manager

Socket.dev • Montreal (administrative region)

On-site
CAD 114,000 - 171,000
Medical coverage
Pension plan
Vacation policy