Senior Manager, Risk and Controls

RBC

Toronto

On-site

CAD 110,000 - 170,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Total rewards program
Professional development
Diversity & inclusion

Job summary

RBC in Toronto seeks a senior risk and information security professional to oversee security programs, assess threats, and ensure regulatory risk reporting is completed across the enterprise. You will lead risk assessments, develop controls, coordinate with internal audits and various lines of defense, and advise on risk and controls.

Strong writing and stakeholder management are essential; experience with SOX/SOC1 is a plus.

Qualifications

  • Degree in IT or related field with security focus.
  • Security qualifications (CRISC/CISSP/CISA) or equivalent.
  • Experience with risk assessments and IT audit practices.
  • Strong written and verbal communication; able to explain complex security concepts to non-technical stakeholders.
  • Experience coordinating across 1LOD/2LOD/3LOD and audits.

Responsibilities

  • Lead development, implementation and enforcement of security risk standards and procedures.
  • Monitor business needs against security concerns and implement changes.
  • Ensure IT risks are controlled across server, network, and applications.
  • Develop security risk metrics training and coordinate with audits and suppliers.
  • Build relationships across units and act as trusted risk advisor for controls.

Skills

Security risk management
Stakeholder management
IT audit
Risk assessments
Information security
Project risk assessments

Education

Degree in IT or related field
CRISC / CISSP / CISA

Tools

DevOps tooling
Cloud concepts
ORM Framework
SOX/SOC1

Job description

WHAT IS THE OPPORTUNITY?

In this role you will manage the day-to-day operations and effectiveness of security-related programs and initiatives; assessing the costs associated with potential threats and solutions required to eliminate or minimize threats. You will apply extensive, in-depth knowledge, skills, and practices to perform complex assignments. This will require reviewing of risk-related standards, policies and regulations both internally and regional. You will also be responsible for the completion of regulatory risk reporting.

Job Description

In this role you will manage the day-to-day operations and effectiveness of security-related programs and initiatives; assessing the costs associated with potential threats and solutions required to eliminate or minimize threats. You will apply extensive, in-depth knowledge, skills, and practices to perform complex assignments. This will require reviewing of risk-related standards, policies and regulations both internally and regional. You will also be responsible for the completion of regulatory risk reporting.

WHAT WILL YOU DO?
  • Leading in the development, implementation and enforcement of organization-wide security risk assessment and control standards, policies and procedures.
  • Monitoring and assessing business needs against security concerns and recommending necessary changes to enhance information systems security.
  • Managing activities for IT risks control in business operations; ensuring that the server, network operations and applications are compliant with security procedures, systems, and policies.
  • Developing training on information security risk metrics, polices, risk migration and elimination procedures for staff, coordinating with audits and suppliers on information security improvement.
  • Establish and maintain strong working relationships across business units and segments. Collaborate with various groups to define and achieve deliverables, acting as a trusted advisor on risk and controls by liaising with 1 LoD, 2LOD, and 3LOD.
  • Deliver risk advisory and consulting, within Investor Services Business Technology, AI and Automation programs. Support our transformation programs and businesses on Project Risk Assessment (iITRA), Findings, Audits, KRI Compliance Monitoring, Reporting and Governance, and control activities.
  • Strong analytical and critical thinking, supported by solid writing skills are essential for documenting and communicating work effectively. You should be able to grasp stakeholder expectations and align your communication accordingly.
  • Ability to impact, influence and negotiate with key stakeholders in building a superior solution, and ultimately a strong stakeholder experience.
WHAT DO YOU NEED TO SUCCEED?
  • Excellent written & verbal communication skills, with the ability to convey complex technical concepts to general IT and business managers
  • Degree level education plus a relevant qualification in risk & information systems control (e.g. CRISC) or cybersecurity (e.g. CISSP) or (e.g. CISA), Deep IT technical knowledge and experience covering: operating systems (e.g. Unix, Windows, zOS); database systems (e.g. Oracle, SQL Server, Sybase, DB2) and software security architectures; Knowledge of MS Suite of Apps
  • Passion for technology risk management and a desire to continually develop personal and team knowledge
  • Experience managing multiple projects or internal service delivery, including service level management, process design and skills development planning
  • Internal or external IT audit qualification and experience; Operational Risk Management
Nice‑to‑have
  • Post graduate qualification in computing or cybersecurity or Information technology
  • Familiarity with DevOps & Cloud concepts, processes and tooling, ORM Framework, Audit; Access and change management processes; SOX/SOC1
WHAT’S IN IT FOR YOU?
  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • A world‑class training program in financial services
  • Opportunity to join a diverse and inclusive team to increase the awareness of risk initiatives within RBC
  • Opportunity to expand your limits and create a new future together at RBC
#TECHPJ
Job Skills
  • Business Continuity and Disaster Recovery (BCDR), Business Technology, Communication, Cyber Security Management, Firewall Management, Information Security, Information Security Auditing, Information Security Operation Center (ISOC), Information Security Risk, Information System Security, IT Network Security, Operational Delivery, Problem Management, Process Management, Project Risk Assessments, Risk Assessments, Security Risk, Security Risk Assessment, Threat Management
Additional Job Details

Address: RBC CENTRE, 155 WELLINGTON ST W:TORONTO

City: Toronto

Country: Canada

Work hours/week: 37.5

Employment Type: Full time

Platform: TECHNOLOGY AND OPERATIONS

Job Type: Regular

Pay Type: Salaried

Posted Date: 2026-06-09

Application Deadline: 2026-08-29

Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Operational Risk / IT Risk and Compliance
Senior Manager, Operational Risk / IT Risk and Compliance

RBC • Toronto

On-site
CAD 120,000 - 170,000
Total rewards program
Flexible work options
Stock options where applicable
+2
Director, Audit & Regulatory Liaison
Director, Audit & Regulatory Liaison

RBC • Toronto

On-site
CAD 140,000 - 190,000
Bonus program
Flexible benefits
Stock where applicable
Senior Manager, Risk and Controls GFT
Senior Manager, Risk and Controls GFT

RBC • Toronto

On-site
CAD 120,000 - 180,000
Bonuses and flexible benefits
Stock where applicable
Flexible work options
Senior Manager, BCRM Risk, Controls & Quality Assurance
Senior Manager, BCRM Risk, Controls & Quality Assurance

RBC • Toronto

On-site
CAD 120,000 - 150,000
Senior Manager, Risk and Controls GFT
Senior Manager, Risk and Controls GFT

RBC • Halifax

On-site
CAD 120,000 - 180,000
Total Rewards Program
Flexible benefits
Stock options
Director, IT Risk Reporting & Insights (Global Security)
Director, IT Risk Reporting & Insights (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 160,000
Senior Manager, Control Testing Reporting and Operations (Global Security)
Senior Manager, Control Testing Reporting and Operations (Global Security)

Socket.dev • Toronto

On-site
CAD 120,000 - 180,000
Bonus program
Stock options
Flexible benefits
+1
Senior Manager, BCRM Risk, Controls & Quality Assurance
Senior Manager, BCRM Risk, Controls & Quality Assurance

Socket.dev • Toronto

On-site
CAD 120,000 - 160,000
Total rewards program
Career development
Impact and growth
+4
Senior Manager, Technology Control Transformation
Senior Manager, Technology Control Transformation

RBC • Toronto

On-site
CAD 90,000 - 130,000
Total rewards program
Coaching and development opportunities
Opportunity to impact business
Senior Analyst, Data Risk and Control
Senior Analyst, Data Risk and Control

ODAIA • Halifax

On-site
CAD 90,000 - 120,000