Penetration Testing Program Manager (Global Security)

RBC

Toronto

On-site

CAD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RBC in Toronto is seeking a Senior Security Program Manager to oversee the enterprise-wide penetration testing program. You will ensure tests are completed on schedule, manage vendor relationships, and maintain regulatory compliance while driving efficiency across the organization.

You will liaise with external vendors, asset owners, risk teams, and senior leadership to address risks and evolve the program to industry standards and organizational growth.

Qualifications

  • 5+ years of security testing, vulnerability management, or cybersecurity program management experience.
  • Experience planning, executing, and overseeing penetration testing for internet-facing and internal apps.

Responsibilities

  • Oversee end-to-end execution of 250+ annual penetration tests, ensuring deadlines and regulatory requirements are met.
  • Deliver bi-weekly status reports to senior management highlighting program health, risks, and initiatives.
  • Define, document, and maintain program processes, control frameworks, and audit evidence.
  • Drive program transformation to improve efficiency, coverage, cost-effectiveness, and stakeholder experience, including new subsidiaries.
  • Address escalations, mitigate risks, and collaborate with vendors, asset owners, and risk/governance teams.

Skills

Cyber Security Program Management
Penetration Testing
Regulatory & Control Frameworks
Stakeholder & Vendor Management
Process Documentation & Metrics
Risk Management & Reporting

Job description

What is the opportunity?

Reporting to the Director, Application Security, you will be responsible for overseeing the execution, compliance, and continuous improvement of RBC’s enterprise-wide penetration testing program. You would ensure penetration tests are completed on schedule, manage vendor relationships, maintain regulatory compliance, and drive operational efficiency. You would also act as a critical liaison between external vendors, asset owners, risk teams, and senior leadership, while proactively addressing risks, escalations, and program evolution to align with industry standards and organizational growth.

Job Description
What is the opportunity?

Reporting to the Director, Application Security, you will be responsible for overseeing the execution, compliance, and continuous improvement of RBC’s enterprise-wide penetration testing program. You would ensure penetration tests are completed on schedule, manage vendor relationships, maintain regulatory compliance, and drive operational efficiency. You would also act as a critical liaison between external vendors, asset owners, risk teams, and senior leadership, while proactively addressing risks, escalations, and program evolution to align with industry standards and organizational growth.

What will you do:
  • Program Oversight: Manage the end-to-end execution of 250+ annual penetration tests, ensuring compliance with deadlines and regulatory requirements, while overseeing vendor performance and scoping.
  • Stakeholder Reporting & Communication: Deliver bi-weekly status reports to senior management, highlighting program health, risks, and initiatives.
  • Process & Control Management: Define, document, and maintain program processes, control frameworks, and evidence for audits, ensuring alignment with internal and external standards.
  • Continuous Improvement: Drive program transformation to enhance efficiency, coverage, cost-effectiveness, and stakeholder experience, including integration of new subsidiaries.
  • Risk & Relationship Management: Address escalations, proactively mitigate risks, and foster collaboration with vendors, asset owners, and risk/governance teams.
What do you need to succeed?
Must have:
  • Cyber Security Program Management: 5+ years of experience in security testing, vulnerability management, or cybersecurity program management.
  • Penetration testing: Experience in planning, executing, and overseeing penetration testing for internet-facing and internal applications.
  • Regulatory & Control Frameworks: Expertise in maintaining compliance with regulatory requirements (e.g., NIST, ISO 27001) and managing control documentation/testing.
  • Stakeholder & Vendor Management: Demonstrated ability to build relationships, manage escalations, and hold vendors accountable for deliverables.
  • Process Documentation & Metrics: Strong skills in creating/maintaining process documentation and defining KPIs to measure program effectiveness.
  • Risk Management & Reporting: Experience identifying, mitigating, and communicating risks to senior leadership, with a track record of driving operational improvements.
Nice to have:
  • Certifications in information security (e.g., CISSP, CCSP, CRISC, CIAM, ITIL)
  • Previous work experience within the financial sector or other large enterprise industry.
  • General knowledge of penetration testing methodologies, tools, and techniques, including web application penetration testing, mobile penetration testing and network penetration testing.
  • Experience with agile methodologies and tools, such as Jira, for backlog management and sprint planning.
  • PMP certification.
What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses, flexible benefits and competitive compensation.
  • Leaders who support your development through coaching and managing opportunities.
  • Opportunities to work with the best in the field.
  • Ability to make a difference and lasting impact.
  • Work in a dynamic, collaborative, progressive, and high-performing team.
  • A world-class training program in financial services.
Job Skills

Application Security, Application Security Testing, Collaboration, Communication, Cyber Security Management, Decision Making, Information Security Management, Infrastructure Penetration Testing, IT Security Management, Leadership, Mobile Penetration Testing, Network Penetration Testing, Penetration Testing, Program Management, Risk Management, Strategic Direction, Taking Initiative, Taking Ownership, Web Application Penetration Testing

Additional Job Details
Address

16 YORK ST:TORONTO

City

Toronto

Country

Canada

Work hours/week

37.5

Employment Type

Full time

Platform

TECHNOLOGY AND OPERATIONS

Job Type

Regular

Pay Type

Salaried

Posted Date

2026-07-27

Application Deadline

2026-08-31

Note

Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

RBC • Toronto

On-site
CAD 110,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

RBC • Vancouver

On-site
CAD 120,000 - 160,000
Senior Program Manager, Physical Security Technology (Global Security)
Senior Program Manager, Physical Security Technology (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 180,000
Senior Security Engineer (Global Security)
Senior Security Engineer (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 160,000
Total rewards program
Stock options (where applicable)
Bonuses
Senior Manager, Risk and Controls
Senior Manager, Risk and Controls

RBC • Toronto

On-site
CAD 110,000 - 170,000
Total rewards program
Professional development
Diversity & inclusion
Senior Manager SaaS Security (Global Security)
Senior Manager SaaS Security (Global Security)

RBC • Vancouver

On-site
CAD 120,000 - 180,000
Bonuses
Flexible benefits
Stock options
+1
Senior Manager SaaS Security (Global Security)
Senior Manager SaaS Security (Global Security)

RBC • Toronto

On-site
CAD 140,000 - 190,000
Total Rewards Program
Flexible benefits
Stock where applicable
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Bedford

On-site
CAD 110,000 - 160,000
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Toronto

On-site
CAD 100,000 - 150,000
Total rewards program
Flexible benefits
Stock options
Senior Security Detection Engineer (Global Security)
Senior Security Detection Engineer (Global Security)

Socket.dev • Toronto

On-site
CAD 120,000 - 160,000
Total rewards program
Flexible work options
World-class training