Enable job alerts via email!

Director, Cyber Risk Governance & Regulatory Oversight

Manulife

Southwestern Ontario

On-site

CAD 120,000 - 160,000

Full time

Today
Be an early applicant

Job summary

A leading financial services company in Ontario is seeking a Director of Cyber Risk Governance. This role involves overseeing cybersecurity compliance and risk management, ensuring alignment with global regulations. The ideal candidate will have extensive experience in cybersecurity risk management and the ability to influence diverse stakeholders. Competitive compensation and an inclusive work environment are provided.

Qualifications

  • 7–10 years in cybersecurity risk management required.
  • Experience with cyber due diligence over mergers and acquisitions needed.
  • Ability to analyze cybersecurity trends essential.

Responsibilities

  • Lead oversight of cybersecurity risks according to company standards.
  • Oversee adherence to cybersecurity regulatory requirements.
  • Collaborate on developing Key Risk Indicators.

Skills

Cybersecurity risk management
Technical acumen in IAM
Cloud security
Network security
Data protection
Incident response
Threat intelligence
Communication skills
Job description

Manulife is seeking a highly experienced Director of Cyber Risk Governance & Regulatory Oversight to join our Global Information & Cybersecurity Risk function as part of our second line oversight. Reporting to the AVP, Cyber Risk Governance & Regulatory Oversight, this position will lead the design and execution of independent oversight activities of our cybersecurity and regulatory compliance programs. The successful candidate will play a vital role in ensuring Manulife’s adherence to global regulations from bodies such as OSFI, SEC, MAS, HKMA and SWIFT. The Director will leverage recognized industry framework such as NIST and ISO to safeguard our operations and support our strategic objectives across all regions.

Key Responsibilities:

  • Independent Oversight:
    • Lead the independent oversight of cybersecurity risks, ensuring alignment with Manulife’s standards and strategic objectives.
    • Conduct independent assessments against industry frameworks such as NIST and SWIFT.
  • Cyber Regulatory Oversight:
    • Oversee and challenge adherence to cybersecurity regulatory requirements.
    • Ensure accurate interpretation and compliance by first-line teams with global regulators including OSFI, SEC, HKMA, MAS, and others.
    • Stay current on emerging technologies and regulatory changes to maintain a robust cybersecurity posture.
  • Cyber Risk Reporting & Strategy:
    • Collaborate across first and second lines of defense to develop and report on Key Risk Indicators (KRIs).
    • Support leadership in preparing board-level cybersecurity materials, offering actionable insights on cyber and emerging risks, data security and operational resilience.
    • Partner with the Information Risk team to drive oversight roadmaps and strategies. Ensure efficient and effective processes are in place to provide comprehensive coverage across the enterprise. Identify opportunities to enhance governance practices, improve oversight maturity, and strengthen risk management capabilities.

Key Qualifications:

  • 7–10 years in cybersecurity risk management, with strong technical acumen across domains such as identity and access management (IAM), cloud security, network security, and data protection.
  • Experience with performing cyber due diligence over mergers and acquisitions
  • Experience with designing, implementing and running data protection capabilities including DLP and insider threat prevention
  • Experience in different aspects of cyber operations including incident response, threat intelligence /detection, red/blue/purple teaming and threat hunting
  • Demonstrated ability to provide strategic oversight, challenge and governance in cybersecurity risk management.
  • Experience interpreting and governing cybersecurity regulations from bodies such as OSFI, SEC, HKMA, MAS, and SWIFT.
  • Strong understanding of industry recognized frameworks including NIST CSF, ISO27001/27002 and PCI DSS.
  • Demonstrated ability to conduct technical cybersecurity assessments against regulatory and industry standards.
  • Ability to analyze cybersecurity trends and emerging risks to identify opportunities for improving the organization’s security posture.
  • Experience building out strategies and roadmaps related to cybersecurity governance.
  • Strong relationship-building skills with the ability to influence and build credibility across diverse stakeholder groups.
  • Excellent verbal and written communication skills, with the ability to produce high-quality deliverables for executive and board-level audiences.

Manulife is an Equal Opportunity Employer. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.