
Enable job alerts via email!
A global financial services provider is seeking an experienced Director of Cybersecurity Risk Oversight to manage independent oversight of cybersecurity risks. The role involves collaborating with various teams, conducting risk assessments, and developing comprehensive risk frameworks. The ideal candidate has 7-10 years in cybersecurity and strong communication skills, ensuring clarity in conveying complex risk concepts. This position is located in Southwestern Ontario, offering a dynamic work environment.
Manulife is seeking a strategic and experienced Director, Cybersecurity Risk Oversight, as a Line 2 leadership role responsible for independent oversight, challenge, and governance of enterprise systems. Reporting to the AVP Information Security, this position will participate in the design and execution of a fit-for-purpose risk oversight framework to ensure that technology solutions align with enterprise risk appetite, regulatory expectations, and secure software development best practices.
Key Responsibilities:
Lead the independent oversight of cybersecurity risks, ensuring robust alignment with Manulife’s standards and strategic objectives. Provide expert guidance to uphold the integrity of the cybersecurity framework.
Collaborate with multidisciplinary teams to gain a comprehensive understanding of Manulife’s technology strategy, operations, and regulatory environment. Proactively identify and assess areas of emerging and heightened risk related to information and cybersecurity.
Evolve and enhance Line 2 oversight frameworks to effectively manage and mitigate risks associated with information and cybersecurity, ensuring these frameworks remain agile and responsive to new challenges.
Oversee Line 1 risk, compliance, and operational metrics, and actively participate in the development and maintenance of Line 2’s information and cybersecurity risk measurement programs. Ensure these metrics are comprehensive and support strategic risk management initiatives.
Cyber & Technology Risk Assessment:
Conduct comprehensive and in-depth assessments of technology programs, particularly those with third-party dependencies, to ensure the safeguarding of organizational assets. Utilize advanced risk assessment methodologies to identify vulnerabilities and implement effective mitigation strategies.
Execute independent and objective challenges to existing cybersecurity measures across critical risk domains, including Identity & Access Management, Cloud Security, Network Security and Data Security. Ensure these challenges rigorously test the effectiveness and resilience of current risk management practices.
Maintain a forward-looking approach by continuously monitoring emerging risks and active threats in the cybersecurity landscape. Integrate these insights into assessments to enhance preparedness and adaptability to new challenges.
Provide unbiased and evidence-based oversight to ensure that risk assessments not only meet regulatory requirements but also align with Manulife's strategic objectives and risk appetite, fostering continuous improvement in the organization's cybersecurity posture.
Standards and Policy Framework Development:
Lead the research, development, and continuous enhancement of Manulife’s internal technology and cyber policies and standards. Ensure these policies are not only aligned with industry best practices but are also responsive to active threats, anticipate emerging risks, and adapt to evolving regulatory environments.
Develop a dynamic and comprehensive policy framework that fosters organizational resilience and promotes a proactive security culture. This framework should empower the organization to preemptively address vulnerabilities and remain agile in the face of new challenges.
Collaborate with cross-functional teams to integrate insights from threat intelligence and risk assessments into policy development processes, ensuring a holistic approach to risk management that supports strategic business objectives.
Champion a culture of security awareness and compliance across the organization by effectively communicating policy changes and their implications, thus reinforcing the importance of cybersecurity at every level.
Cyber Risk Reporting & Strategy:
Collaborate across first and second lines of defense to develop and report on Key Risk Indicators (KRIs).
Support leadership in preparing board-level cybersecurity materials, offering actionable insights on cyber and emerging risks, data security and operational resilience.
Key Qualifications:
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better.
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.