Managing Director - Cybersecurity & Core Technology Audit

BMO U.S.

Toronto

On-site

CAD 160,000 - 215,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
Tuition reimbursement
Discretionary bonuses
Retirement savings plans

Job summary

BMO Financial Group seeks a senior leader to oversee enterprise-wide audit coverage across Cybersecurity and Core Technology, aligning testing priorities with the bank’s evolving tech landscape.

You will define risk-based audit strategy, lead specialized teams, and partner with regulators and executives to deliver coordinated assurance. This role drives analytics, automation, and continuous auditing to strengthen control environments.

Qualifications

  • 15+ years of experience in Internal Audit, Technology Audit, Cybersecurity, or Risk Management in large financial institutions.
  • Senior leadership experience overseeing complex technology domains including cybersecurity, cloud, and infrastructure.
  • Proven ability to lead integrated audit programs across multiple risk domains.
  • Experience engaging regulators and executive stakeholders (CIO, CISO).
  • Track record in driving audit transformation (analytics, automation, continuous auditing).
  • Experience leading geographically dispersed teams and capability uplift in specialized domains.
  • Strong understanding of technology risk management and emerging risks (AI, cloud, quantum, supply chain).
  • One or more professional certifications in information systems audit, cybersecurity, or technology risk management.

Responsibilities

  • Define and execute a risk-based, integrated audit strategy across Cybersecurity and Core Technology.
  • Lead ongoing risk assessments and development of audit coverage strategies.
  • Strengthen audit capabilities through workforce planning and methodology enhancement.
  • Maintain integrated coverage across cybersecurity, engineering, technology operations, and third-party ecosystems.
  • Partner with business, technology, control, and audit teams to support risk management and remediation.
  • Serve as senior audit relationship lead for technology executives and regulators.
  • Lead audit support for regulatory examinations and remediation activities.
  • Ensure quality and consistency of audit delivery through standardized methodologies.
  • Drive analytics, continuous assurance, and AI-enabled auditing for forward-looking risk insights.

Education

CISA / CISSP / related information security certifications

Tools

AI-enabled auditing

Job description

Application Deadline: 10/30/2026 Address: 100 King Street West Job Family Group: Audit, Risk & Compliance Provides strategic leadership and enterprise-wide oversight of audit coverage across Cybersecurity and Core Technology, ensuring robust, risk-based assurance aligned to the Bank’s evolving technology landscape. The role establishes the audit strategy, testing priorities, and integrated coverage approach for high-risk technology domains, including cybersecurity resilience, technology infrastructure, cloud platforms, engineering practices, software development, service management, technology operations, platform support, operational resilience, physical security, and technology-enabled transformation programs.

Operating within the Technology & Operations Audit mandate, the role identifies horizontal audit touchpoints, dependencies, and control considerations across the broader Corporate Audit ecosystem, partnering with LOB and Chief Auditor groups to deliver coordinated coverage. Define and execute a risk-based, integrated audit strategy across Cybersecurity and Core Technology that focuses on both current and future focused emerging risk reviews Lead ongoing risk assessment activities and development of audit coverage strategies to provide independent assurance over Cybersecurity and Core Technology risks, control effectiveness, and risk management practices. Strengthen audit capabilities across Cybersecurity and Core Technology through workforce planning, technical specialization, succession management, methodology enhancement, and targeted capability development in cyber, cloud, infrastructure, engineering, and technology operations risk domains. Maintain integrated, risk-based audit coverage across cybersecurity, engineering, technology operations, service management, platform support, cloud, infrastructure, software delivery, operational resilience, and third-party ecosystems, with a focus on identifying systemic risks, enterprise-wide control dependencies, and emerging technology risks. Proactively build partnerships across business, technology, control, and audit teams to support effective risk management, issue remediation, and sustainable control environment Serve as the senior audit relationship lead for technology executives, including CISOs, engineering, infrastructure, and operations leaders, while maintaining strategic partnerships with regulators, control functions, and other key stakeholders .Lead audit support for regulatory examinations, horizontal reviews, regulatory commitments, and remediation activities related to Cybersecurity and Core Technology. Ensure audit insights, thematic observations, and risk perspectives are communicated effectively to executive management and the Board. Provide strategic leadership and performance oversight of Directors responsible for portfolio execution and identify opportunities to strengthen ownership and risk alignment while expanding control-level, domain-specific coverage Ensure quality, consistency, and timeliness of audit delivery through standardized methodologies, reusable testing approaches, and continuous improvement practices. Establish proactive audit engagement and continuous monitoring across portfolios to enable real-time reprioritization and end-to-end risk visibility Drive adoption of analytics, continuous assurance, and AI-enabled auditing (e.g., AI-enabled threats, advanced cyber risks) for better forward-looking risk insights Deliver thematic insights, root-cause analysis, and enterprise-wide risk perspectives across technology domains. Within the mandate of this role, promotes and supports the Bank’s risk culture including ensuring employees understand their accountabilities for risk-taking activities, promoting an environment of open communication and effective challenge, and establishing the “tone from the top” through leading by example. Takes measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.

Qualifications
  • 15+ years of experience in Internal Audit, Technology Audit, Cybersecurity, or Risk Management within large financial institutions
  • Senior leadership experience overseeing complex technology domains, including cybersecurity, infrastructure, cloud, engineering, technology operations, and operational resilience
  • Deep expertise in cybersecurity, technology infrastructure, engineering practices, service management, operational resilience, and technology risk management, with proven ability to lead integrated audit programs across multiple risk domains
  • Proven ability to lead integrated audit programs across multiple risk domains
  • Strong experience engaging regulators and executive stakeholders (CIO, CISO, regulators)
  • Demonstrated track record of driving audit transformation (analytics, automation, continuous auditing)
  • Experience leading geographically dispersed teams, building and scaling high-performing teams, including capability uplift in specialized domains
  • Strong understanding technology risk management and emerging risks, including artificial intelligence, AI-enabled threats, quantum computing implications, technology transformation, evolving regulatory expectations, and advanced supply chain dependencies
  • One or more professional certifications in information systems audit, cybersecurity, or technology risk management required (e.g., CISA, CISSP)
  • Additional certifications in cloud platform/security, cybersecurity, network security, service management, or resilience preferred (e.g., CISM, CCSP, CCSK, GIAC, ITIL)
Compensation & Benefits
  • Pay in the base salary range of $160k-$215k Cdn Salary: Pay Type: Salaried
  • Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure
  • Salaries for part-time roles will be pro-rated based on number of hours regularly worked
  • For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position
  • Health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans
  • Performance-based incentives, discretionary bonuses, as well as other perks and rewards
  • To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
About BMO

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world. As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. To find out more visit us at https://jobs.bmo.com/ca/en.

BMO's Commitment to Diversity and Inclusion

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Managing Director Cyber and Technology Risk RSA
Managing Director Cyber and Technology Risk RSA

BMO • Toronto

On-site
CAD 170,000 - 200,000
Health insurance
Tuition reimbursement
Retirement savings plans
+1
Senior Manager, Information Security Risk
Senior Manager, Information Security Risk

BMO • Toronto

On-site
CAD 86,000 - 185,000
Health insurance
Tuition reimbursement
Accident and life insurance
+1
Senior IT Audit Manager
Senior IT Audit Manager

Bank of Montreal • Toronto

On-site
CAD 86,000 - 185,000
Health insurance
Retirement savings plans
Disability and life insurance
Senior Manager, Information Security Risk
Senior Manager, Information Security Risk

BMO U.S. • Toronto

On-site
CAD 121,000 - 261,000
Health insurance
Tuition reimbursement
Life insurance
+1
Senior IT Audit Manager
Senior IT Audit Manager

BMO • Toronto

On-site
CAD 86,000 - 185,000
Health insurance
Tuition reimbursement
Life insurance
+1
Audit Manager, Cybersecurity
Audit Manager, Cybersecurity

BMO • Toronto

Hybrid
CAD 76,000 - 142,000
Health insurance
Tuition reimbursement
Accident and life insurance
+1
Senior IT Audit Manager
Senior IT Audit Manager

BMO U.S. • Toronto

On-site
CAD 86,000 - 185,000
Health insurance
Tuition reimbursement
Accident & life insurance
+1
Audit Manager, Corporate Areas
Audit Manager, Corporate Areas

BMO • Toronto

On-site
CAD 70,000 - 150,000
Health insurance
Tuition reimbursement
Accident and life insurance
+1
Senior Manager- Fraud Risk Oversight
Senior Manager- Fraud Risk Oversight

BMO • Toronto

On-site
CAD 86,000 - 185,000
Health insurance
Tuition reimbursement
Accident and life insurance
+1
Analyst
Analyst

BMO • Toronto

On-site
CAD 45,000 - 100,000
Health insurance
Tuition reimbursement
Accident and life insurance
+1