Senior Manager, IT Risk

Scotiabank

Toronto

Hybrid

CAD 110,000 - 150,000

Full time

16 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Scotiabank is seeking a senior IT Risk professional to join the Cyber & IT Risk Management team in Toronto. The role focuses on second-line risk assurance, cross-functional collaboration, and developing/implementing risk policies to support global risk management objectives.

You will lead cyber risk assessments, challenge controls, and drive improvements in risk governance while partnering with first-line teams to ensure regulatory compliance and robust risk culture.

Qualifications

  • 5+ years of experience in Technology or Operational Risk Management, IT Audit, IT Compliance, regulatory supervision, consulting or advisory roles.
  • Experience with risk assessment, controls and regulatory frameworks (NIST, COBIT, OSFI, FFIEC, GDPR).
  • Spanish proficiency is required.

Responsibilities

  • Lead 2nd Line Challenge to identify threats and vulnerabilities across cyber and IT domains.
  • Manage annual RCSA plan and resource assignment with IT Risk and business partners.
  • Review inherent risk, control effectiveness, and residual risk assessments and follow up on actions.
  • Prepare IT risk reporting and monitor control effectiveness.

Skills

IT Risk Management
Regulatory Knowledge
Spanish proficiency
Data security
Risk analytics

Education

Master’s degree or higher in science, technology, engineering, business administration

Tools

GRC tools

Job description

Select how often (in days) to receive an alert:

Requisition ID: 266036

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Contributes to the overall success of Cyber & IT Risk Management, Global Risk Management (GRM) globally ensuring specific individual goals, plans, initiatives are executed/delivered in support of the team’s business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations, internal policies and procedures.

Leads expert technical risk assurance and control oversight to ensure the bank achieves its objectives while effectively managing risk. Collaborate with cross-functional teams across the first line of defense to identify, assess, and mitigate emerging risks and vulnerabilities. This role is crucial in fostering a robust risk culture and driving continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.

As part of the second line of defense, the Cybersecurity and IT Risk team provides independent oversight and challenge, and assists in developing methodologies, policies, processes, and tools to support the Cyber and IT Risk Management Framework.

Is this role right for you? In this role, you will:

  • Lead 2nd Line Challenge: Conduct comprehensive challenge to identify potential threats and vulnerabilities in the Bank’s processes, systems, and operations. Partner with 1st line of defense to develop risk mitigation strategies across key cyber and IT domains. Challenge IT and cybersecurity risks within scenario analysis and thematic reviews. Conduct cyber risk assessments, metrics, and controls within globally complex, dispersed, and diverse organizations.
  • RCSA Program Management. Define the annual plan, in collaboration with GOR, the business and IT Risk. Assign resources as needed on selected RCSAs. Review and challenge the scope for IT, participants, and IT Profile for RCSAs.
  • Risk Assessment and Identification. Objectively review & challenge the inherent risk, control effectiveness, and residual risk assessments & rationales, as well as related issues/APs, for technology specific risk/controls. Provide feedback and follow up on the technology specific risk/control responses.
  • Issue Management. Ensure all IT risks/controls have been properly documented and reflected in deliverables and applicable tracking systems, including suitable action plans.
  • Reporting and Monitoring. Prepare reports on IT components of RCSAs, including findings, track IT risk trends, and monitor the effectiveness of controls.
  • Training and Communication. Develop and deliver training programs to educate and support peers and stakeholders on IT processes of the RCSAs and best practices.
  • Stakeholder Management. Act as a liaison between business units, control owners, IT Risk and other stakeholders.
  • Champions a customer focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  • Understand how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabank’s Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champions a high performance environment and contributes to an inclusive work environment.

Do you have the skills that will enable you to succeed in this role? - We'd love to work with you if you have:

  • Strong expertise in IT Risk Management (e.g. Logical Access, Data Leakage, Disaster Recovery)
  • Master’s degree or higher in science, technology, engineering, business administration is an asset.
  • 5+ years of experience in Technology or Operational Risk Management, IT Audit, IT Compliance, regulatory-supervision, consulting or advisory roles.
  • 1+ years of experience in RCSAs as part of the 1LoD or 2LoD.
  • Advanced knowledge of relevant regulatory rules (OSFI, FFIEC, NYDFS 500) and frameworks (NIST, COBIT) is preferred
  • Experience using of GRC risk management tools.
  • Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
  • Proficiency in data security, risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
  • Advanced knowledge of data analytics and data literacy
  • Spanish proficiency is required.

What’s in it for you?

  • The opportunity to join a forward-thinking and collaborative team, surrounded by innovative thinkers.
  • A rewarding career path with diverse opportunities for professional development
  • Internal training to support your growth and enhance your skills.
  • An inclusive working environment that encourages creativity, curiosity, and celebrates success!

Location(s): Canada : Ontario : Toronto

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Technology Risk and Control Self-Assessment
Senior Manager, Technology Risk and Control Self-Assessment

Scotiabank • Toronto

On-site
CAD 120,000 - 160,000
Diversity, Equity, Inclusion & Allyship programs
Upskilling through online courses
Competitive Rewards program including bonuses
+1
Senior Manager, Issues Management
Senior Manager, Issues Management

Kibbi Technologies Inc. • Toronto

On-site
CAD 90,000 - 130,000
Bonus
Flexible vacation
Personal and sick days
+1
Senior Manager, Global Operational Risk Oversight (Contract)
Senior Manager, Global Operational Risk Oversight (Contract)

Scotiabank • Toronto

On-site
CAD 120,000 - 190,000
Performance bonus
Employee Share Ownership Program
Pension Plan Matching
+1
Associate Director, Business Risk Management - Toronto, ON
Associate Director, Business Risk Management - Toronto, ON

Scotiabank - Global Banking and Markets • Toronto

On-site
CAD 90,000 - 130,000
Director Strategy and Operations
Director Strategy and Operations

Kibbi Technologies Inc. • Toronto

On-site
CAD 120,000 - 160,000
Director Strategy and Operations
Director Strategy and Operations

Scotiabank • Toronto

On-site
CAD 140,000 - 190,000
Flexible vacation
Tuition assistance
Competitive rewards program
+2
Senior Audit Manager, Non Retail Credit Risk
Senior Audit Manager, Non Retail Credit Risk

Scotiabank • Toronto

On-site
CAD 120,000 - 180,000
Associate Director, Business Risk Management - Toronto, ON
Associate Director, Business Risk Management - Toronto, ON

Scotiabank • Toronto

On-site
CAD 120,000 - 160,000
Director, Wealth Management Technology
Director, Wealth Management Technology

Scotiabank • Toronto

On-site
CAD 150,000 - 210,000
Diversity & Inclusion
Accessibility & Accommodations
Upskilling opportunities
+3
Director Risk Run and Analytics
Director Risk Run and Analytics

Scotiabank • Toronto

On-site
CAD 180,000 - 260,000
Performance bonus
Pension matching
Generous vacation