Senior Specialist Risk Management

TEEMA

Toronto

On-site

CAD 126,000 - 176,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TEEMA is seeking a Senior Specialist Risk Management to support the City of Toronto's cyber security program. You will identify and mitigate enterprise risks across divisions, develop governance and compliance frameworks, and guide senior leadership on risk-related decisions.

You will lead remediation, monitor regulatory changes, prepare risk dashboards, and deliver training to elevate risk awareness across the organization.

Qualifications

  • Post-secondary degree in Business or Technology or related discipline.
  • 6+ years of risk management experience focused on cyber risk.
  • Extensive knowledge of risk elements including vulnerability, threat, likelihood, impact, remediation.
  • Extensive expertise in Information Security or Governance, Risk & Compliance (GRC).
  • Experience in third-party assessments, especially on small and medium-sized service providers.
  • Experience with SOC 2 Type II and SOC 27001 Certification.
  • Experience conducting PCI assessments or preparing for PCI audits.
  • Experience developing and implementing cyber policies and standards across an enterprise.
  • Experience risk assessments based on NIST CSF and related standards.
  • Preferred certifications: CISSP, CISA, CISM, CRISC.

Responsibilities

  • Oversees risk remediation plans with timely implementation in collaboration with stakeholders.
  • Drives the GRC program by developing policies, frameworks, and controls to manage enterprise risks.
  • Provides guidance on regulatory compliance, internal controls, and risk mitigation strategies.
  • Monitors emerging risks, industry trends, and regulatory changes to adjust risk management strategies.
  • Prepares risk reports, dashboards, and presentations for executive leadership with key exposures and actions.
  • Develops and delivers training to promote risk awareness and a risk-conscious culture.
  • Collaborates with senior leaders to integrate risk management into strategic planning.

Skills

Risk Management
GRC
Regulatory compliance
Policy development
Stakeholder management
Communication skills
Strategic thinking
Analytics

Education

Post-secondary degree in Business or Technology

Tools

SOC 2 Type II
SOC 27001
PCI assessments

Job description

Job Title:Senior Specialist Risk Management
Job ID:90205
Location:Toronto, Ontario

Overview:

Job Title: Senior Specialist Risk Management

Division: Toronto Cyber Security

Reports To: Manager Risk Management Centre of Excellence

Hiring Manager

Salary Range: $126,000 – $176,140

Work Location: 55 John Street, Toronto

Job Type: Permanent Full Time

Shift Information: Monday to Friday, 35 hours work week

To support the Manager of Risk Management Centre of Excellence and the Chief Information Security Officer (CISO) in maintaining a City-wide cyber security program that enhances protection across the organization.To provide strategic cyber risk management expertise by identifying, assessing, and mitigating enterprise-wide risks across City divisions, agencies, and corporations.To lead the development and execution of governance, risk, and compliance (GRC) frameworks, ensuring alignment with regulatory requirements, industry best practices, and corporate policies.To oversee risk remediation planning, monitor compliance initiatives, and provide guidance to senior leadership on risk-related decisions to enhance the organization’s overall risk posture.

What you will be doing:
  • Oversees risk remediation plans, ensuring timely implementation of mitigation strategies in collaboration with stakeholders.
  • Drives the governance, risk, and compliance (GRC) program by developing policies, frameworks, and controls to manage enterprise risks effectively.
  • Provides expert guidance on regulatory compliance, internal controls, and risk mitigation strategies to support business objectives.
  • Monitors emerging risks, industry trends, and regulatory changes to proactively adjust risk management strategies.
  • Prepares risk reports, dashboards, and presentations for executive leadership, identifying key risk exposures and recommended actions.
  • Develops and delivers training programs to enhance risk awareness and promote a risk-conscious culture across the organization.
  • Collaborates with senior leaders and cross-functional teams to integrate risk management into strategic planning and decision-making.
What you must have:
  • Post-secondary degree in Business or Technology or a related discipline.
  • Over six years of experience in Risk Management primarily focused on cyber risk management.
  • Extensive knowledge of elements of risk, including vulnerability, threat, likelihood, impact, mitigation, and remediation
  • Extensive expertise in Information Security or Governance, Risk & Compliance (GRC).
  • Extensive experience in conductingthird-party assessments, especially on small and medium-sized service providers.
  • Must have extensive experience in aSoc 2 Type II report and SOC 27001 Certification
  • Experience in conductingPCI assessments or preparing an organization for PCI audits
  • Must have experiencedeveloping and implementing cyber policies and standardsacross an enterprise.
  • Must have experience conducting risk assessments based onNIST cyber security frameworkand related standards.
  • Preferred Certifications (at least two in the list): CISSP, CISA, CISM, CRISC
Skills
  • Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership and vendors).
  • A creative, critical, and strategic thinker.
  • Ability to assess communications gaps and opportunities and to develop new content strategies that deliver on business objectives.
  • Ability to create content, toolkits and awareness materials that support the success of transformative divisional programs.
  • Ability to lead efficient communication between all project stakeholders, including internal divisional teams, corporate partners, clients and external partners.
  • Ability to achieve business objectives through influencing and effectively working with key stakeholders.
  • Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership and vendors.
  • Excellent problem-solving skills with capability to identify solutions to unusual and complex problems.
  • Keen attention to detail and strong organizational skills.
  • Highly organized, proactive, self-motivated team player who takes initiative and is able to work independently.
  • Ability to work in a fast-paced environment, managing multiple priorities with proven time management skills.
  • Strong analytical skills with the ability to prioritise and multitask.
  • Ability to prioritize and effectively manage competing priorities and projects.
  • Ability to manage multiple initiatives while adhering to strict deadlines.
  • Able to work extremely well under pressure while maintaining a high level of professionalism
  • Self-motivated person with desire to go above and beyond required tasks.
  • Transferable skills, including business transformation and decision-making, are equally important. Being able to think on your feet and show good judgment are especially valuable in this field. Professionals in cyber security must be able to react quickly and strategically to cyber-related incidents.
Other Information:
  • A normal work week is 35 hours, however, unforeseen situation may require extended hours of work with little or no prior notice. In case of a cyber incident or breach, rotation shift, continuous extended hours may be required with little or no prior notice.
  • *Subject to a police check, background check, psychological assessment and/or any other checks on a regular basis as the Toronto Cyber Security handles highly sensitive and confidential information.
  • Equity, Diversity and Inclusion:The City is an equal opportunity employer, dedicated to creating a workplace culture of inclusiveness that reflects the diverse residents that we serve. Learn more about the City’s commitment to employment equity.
  • Accomodation:The City of Toronto is committed to creating an accessible and inclusive organization. We are committed to providing barrier-free and accessible employment practices in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Should you require Code-protected accommodation through any stage of the recruitment process, please make them known when contacted and we will work with you to meet your needs. Disability-related accommodation during the application process is available upon request. Learn more about the City’s Hiring Policies and Accommodation Process.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior, Cyber Analytics
Senior, Cyber Analytics

ipss inc. • Toronto

On-site
CAD 112,000 - 149,000
Senior Specialist Risk Management - Confirmation Program
Senior Specialist Risk Management - Confirmation Program

City of Toronto • Toronto

On-site
CAD 110,000 - 150,000
Senior Specialist Risk Management - Confirmation Program
Senior Specialist Risk Management - Confirmation Program

TES The Employment Solution • Toronto

On-site
CAD 126,000 - 176,140
Specialist Cyber Service Management
Specialist Cyber Service Management

City of Toronto • Toronto

On-site
CAD 116,000 - 161,000
Senior Manager, Information Security Defense and Operation
Senior Manager, Information Security Defense and Operation

TCHC • Canada

Hybrid
CAD 143,000 - 157,000
Pension plan with OMERS
Health, dental, and vision benefits
Vacation: 4 weeks/year
+5
SENIOR SPECIALIST Cyber Architecture
SENIOR SPECIALIST Cyber Architecture

City of Toronto • Toronto

On-site
CAD 100,000 - 130,000
Senior Security Specialist - Cloud (Global Security)- EN
Senior Security Specialist - Cloud (Global Security)- EN

RBC • Montreal (administrative region)

Hybrid
CAD 95,000 - 130,000
Total Rewards Program (bonuses, stock)
Annual training budget
Hybrid-remote flexibility
+1
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

RBC • Toronto

Hybrid
CAD 120,000 - 180,000
Total Rewards program with bonuses and
Annual training budget
Coaching & development
+3
Senior Manager, Information Security & IT
Senior Manager, Information Security & IT

Talent Minded • Toronto

Hybrid
CAD 150,000 - 165,000
Senior Manager, Technology Risk Governance & Compliance
Senior Manager, Technology Risk Governance & Compliance

Corus Entertainment • Toronto

Hybrid
CAD 85,000 - 110,000