Enable job alerts via email!

Third Party Security Risk Manager

EQ Bank | Equitable Bank

Toronto

Hybrid

CAD 90,000 - 120,000

Full time

Today
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading bank is seeking a Third-Party Security Risk Manager to enhance security measures against third-party risks. The role involves risk assessments, compliance monitoring, and collaboration with technology teams to ensure secure banking operations. Join a dynamic team committed to redefining banking experiences in Canada.

Benefits

Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
Employee Share Purchase Plan
Maternity/Parental top-up
Generous vacation policy and personal days
Annual professional development allowance

Qualifications

  • At least five years of information security experience.
  • Three years of third-party risk management experience.

Responsibilities

  • Perform third-party security risk assessments.
  • Monitor third-party compliance program.
  • Lead security risk management initiatives.

Skills

Information Security
Risk Management
Compliance
Cloud Security

Education

Bachelor of Computer Science

Job description

Join a Challenger

Being a traditional bank just isn’t our thing. We are big believers in innovating the banking experience because we believe Canadians deserve better options, and we challenge ourselves and our teams to creatively transform what’s possible in banking. Our team is made up of inquisitive and agile minds that find smarter ways of doing things. If you’re not afraid of taking on big challenges and redefining the future, you belong with us. You’ll get to work with people who will encourage you to reach new heights. We like to keep things fun, ask questions, and learn together.

We are a big (and growing!) family. Overall, we serve more than 670,000 people across Canada through Equitable Bank, Canada's Challenger Bank, and have been around for more than 50 years. Equitable Bank's wholly-owned subsidiary, Concentra Bank, supports credit unions across Canada that serve more than six million members. Together, we have over $125 billion in combined assets under management and administration, with a clear mandate to drive change in Canadian banking to enrich people's lives. Our customers have named our EQ Bank digital platform (eqbank.ca) one of the top banks in Canada on the Forbes World's Best Banks list since 2021.

Purpose of Job

The Third-Party Security Risk Manager will work closely with the technology teams and line of business teams to mitigate the risk of security attacks emanating from partners, vendors, and other related third parties while enabling the business to grow the bank and serve our customers efficiently and securely.

Main Activities:

  • Perform Third-Party security risk assessments
  • Monitor and report on third-party security risk action plans, engaging with third-party contacts as well as business stakeholders
  • Maintain third-party security risk management framework ensuring alignment with Risk management framework (2nd Line of defense) and Privacy requirements
  • Provide security input to third-party contracts by ensuring alignment with cyber security regulatory requirements and Company cyber security policies
  • Identify supplier-related cyber risk threat scenarios and evaluate risk rating based on a thorough review of the third party’s security program and technical architecture
  • Monitor third-party compliance program, ensuring continuous compliance and evidence collection, validation, and recording

Knowledge/Skill Requirements:

  • A college diploma or university degree is required. Higher accreditation (e.g., Bachelor of Computer Science) is preferred
  • At least five (5) years of information security and information risk experience
  • At least three (3) years of third-party risk management experience (including hands-on experience conducting third-party risk assessments)
  • Understanding of Cloud Shared responsibility models and risk mitigation approach/techniques
  • Experience in performing organization-wide/entity security risk assessments or audits is required
  • Understanding and experience with security compliance frameworks such as PCI DSS, BSIMM, Cloud Security Alliance, NIST, ISO 27K series is required
  • Understanding of Canadian Financial industry regulations relevant to third-party security and privacy expectations e.g., OSFI, OPC
  • The following certifications are preferred: CCSP, CCSK, CISM, CISSP, CISA, or CRISC
  • Experience working in a banking or financial services environment is an asset

Accountability

  • The incumbent works under the direct management of the Senior Manager, Information Security Risk Management. They will be expected to lead and provide guidance to others in the department.
  • The incumbent is accountable for formulating, developing, and drafting security policies, procedures, and other relevant documents while liaising with stakeholders to ensure that the Information Security concerns are addressed and buy-in is obtained. This facilitates smooth implementation.
  • The incumbent manages security risk throughout its lifecycle, from identification to stakeholder communication, remediation, and tracking closure of weaknesses/risks.
  • The incumbent ensures the accuracy of periodic compliance reports submitted by IT functions, avoiding non-compliance issues with regulators.
  • Responsible for performing penetration testing as per plan, compiling reports, and working with stakeholders for remediation or risk acceptance. Maintains a register for penetration testing results and vulnerabilities.
  • Administers and manages the GRC solution implemented in the Bank, seeking improvements and resolving stakeholder queries.
  • Works with internal and external audit and compliance teams as needed.
  • Ensures security controls are properly implemented and embedded within IT systems and operations to prevent cyber threats.

What we offer [For full-time permanent roles]

  • Competitive discretionary bonus
  • Market-leading RRSP match program
  • Medical, dental, vision, life, and disability benefits
  • Employee Share Purchase Plan
  • Maternity/Parental top-up
  • Generous vacation policy and personal days
  • Virtual events to connect colleagues
  • Annual professional development allowance and Career Development program
  • A chance to join a top FinTech and help create a new banking experience

The incumbent will work in a hybrid model, based at 2200-25 Ontario Street, Toronto, ON.

Equitable Bank is committed to inclusion and providing a barrier-free recruitment process. Please inform us of any accommodations needed. All candidates must pass criminal background and credit checks. Only closely matched candidates will be contacted.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Third Party Security Risk Manager

ZipRecruiter

Toronto

Hybrid

CAD 90,000 - 120,000

Today
Be an early applicant

Third Party Security Risk Manager

Equitable Group

Toronto

Hybrid

CAD 90,000 - 120,000

4 days ago
Be an early applicant

Digital Risk Manager

EY

Toronto

On-site

CAD 90,000 - 120,000

Today
Be an early applicant

Sr. Manager, Third Party Risk Data Analytics

Canadian Imperial Bank of Commerce

Toronto

Hybrid

CAD 100,000 - 130,000

4 days ago
Be an early applicant

Manager, Risk Insights

Capital One Canada

Toronto

Hybrid

CAD 90,000 - 120,000

4 days ago
Be an early applicant

Manager, Risk Insights

Capital One Canada

Toronto

Hybrid

CAD 80,000 - 120,000

Today
Be an early applicant

Enterprise Financial Crimes Compliance Risk Manager

U.S. Bank

Toronto

Hybrid

CAD 80,000 - 120,000

7 days ago
Be an early applicant

Manager Information Security, Governance & Risk

CareRx Corporation

Toronto

On-site

CAD 105,000 - 114,000

Yesterday
Be an early applicant

Manager - Technology Risk Services - IT Assurance

KPMG LLP Canada

Toronto

Hybrid

CAD 90,000 - 120,000

Yesterday
Be an early applicant