Enable job alerts via email!

Senior Manager, U.S. Information Security & Control

Scotiabank

New York (NY)

On-site

USD 117,000 - 225,000

Full time

20 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a dynamic team at a leading bank where you will play a crucial role in safeguarding the organization from cybersecurity threats. As a Senior Manager in Information Security & Control, you will leverage your extensive experience in risk management and regulatory compliance to manage audits and oversee cybersecurity programs. This is an exciting opportunity to contribute to a high-performing culture focused on innovation and inclusivity, ensuring the bank meets its regulatory obligations while protecting its assets. If you are passionate about cybersecurity and eager to make a significant impact, this role is perfect for you.

Benefits

Flexible Benefit Programs
Holistic Well-being Support
Inclusive Work Environment

Qualifications

  • 8+ years of experience in Information Security or related cybersecurity field.
  • Strong background in risk management and regulatory compliance.
  • Experience with NYSDFS, FFIEC, or other US financial regulatory audits.

Responsibilities

  • Manage regulatory engagements and compliance for cybersecurity.
  • Monitor and report on cybersecurity requirements against US regulations.
  • Oversee risk assessments and provide updates to executive leadership.

Skills

Information Security
Cybersecurity Risk Management
Regulatory Compliance
Audit Management
Risk Assessment
Communication Skills
Project Management

Education

University Degree in Cybersecurity
Cybersecurity Certifications (CISSP, CCSP, CRISC, CISM)

Tools

GCP
Azure

Job description

Press Tab to Move to Skip to Content Link

Select how often (in days) to receive an alert:

Title: Senior Manager, U.S. Information Security & Control

Requisition ID: 223587

Salary Range:117,400.00-224,700.00

Please note that the Salary Range shown is a guideline only. Salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience.

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Global Banking and Markets

Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank’s strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world.

Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group.

Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries! We work together to drive ambition for every future!

Purpose

The Information Security and Control (IS&C) Senior Manager will participate and manage various aspects of information security and contribute to the overall success of the U.S. IS&C’s governance, regulatory compliance, and risk program.

This role requires a seasoned professional with a strong background in information security, risk management, cybersecurity/technology risk, audit, regulatory compliance, and governance. The IS&C Senior Manager will lead and oversee all regulatory examinations, audit requests pertaining to information security, and various cybersecurity risk assessments, cybersecurity maturity assessments, recommend risk mitigation strategies, and safeguard the Bank from potential informational security threats. The person will also play a pivotal role in reviewing and managing technology and cybersecurity risks and controls to protect the organization's data, systems, and networks.

The role will be expected to work closely with the senior management teams to establish and maintain a robust cybersecurity and technology risk management program to proactively safeguard the organization from security threats by ensuring that technology and cybersecurity risks are identified, monitored, and treated, as well as ensuring the Bank meets regulatory compliance. The candidate will be required to create or update presentations based on specific assessments, regulatory compliance, and security topics for various working groups and committees.


What You'll Do

  • Regulatory and Compliance Management (specific to cybersecurity):
    • Manages engagements with external regulatory auditors/examiners and internal/3rd party auditors for information security and cybersecurity.
    • Monitors, analyzes, and reports on cybersecurity requirements against relevant U.S. regulations and cybersecurity standards, such as NYSDFS, FFIEC, and NIST CSF.
    • Provides support to IT&S auditors and compliance with respect to regulatory and audit information requests.
    • Continuously monitors and assesses the effectiveness of security controls and processes.
    • Manages and updates cybersecurity control library.
  • Cybersecurity and Technology Risk Governance:
    • Understands how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
    • Supports security control/risk reporting in various forms such as deep dive presentations, assessment reports, gap analysis, etc.
    • Identifies and assesses cybersecurity and technology risks to ensure compliance with regulations and internal policies.
    • Performs cybersecurity risk assessments and provide updates to executive leadership and collaborate with various departments to manage risks effectively.
    • Provides oversight and advisory on cloud security, application security, attack surface management, and cloud posture management on platforms such as GCP and Azure
  • Risk and Issues Management:
    • Reports and tracks all cybersecurity-related issues that pertains to audits, regulatory requirements, control testing, and other issues.
    • Provides guidance to internal stakeholders on cybersecurity best practices.
    • Prepares regular reports and presentation decks on risk management, gap assessment, cybersecurity-related issues for senior management and stakeholders.
    • Provides insights and recommendations for continuous improvement.
    • Monitors and tracks the progress of risk mitigation efforts related to cybersecurity.
  • Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank’s Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champions a high-performance environment and contributes to an inclusive work environment.

What You’ll Bring

  • Required 8+ years of experience in Information Security or related cybersecurity field.
  • Experience in IT key security controls/mechanisms and risk assessment concepts pertaining to complex data, application, and networking environments.
  • Prior experience and knowledge managing cybersecurity program.
  • Prior experience and knowledge with NYSDFS, FFIEC, or other US financial regulatory audits.
  • Have strong verbal and written communication skills in English with excellent individual project management and tracking skills.
  • Cybersecurity related certification is preferred (CISSP, CCSP, CRISC, CISM).
  • University degree or college diploma in a cybersecurity related field is preferred.


Interested?


If your experience is closely related but doesn’t align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank!

At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. That’s why we work to grow and diversify talent and engage employees in a performance-oriented culture.


What's in it for you?

Scotiabank wants you to be able to bring your best self to work – and life, every day. With a focus on holistic well-being, our many flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.

Location(s): United States : New York : New York City

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here . Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Engineering Manager

Mark43

New York

Remote

USD 180,000 - 220,000

Yesterday
Be an early applicant

Senior Cybersecurity Project Manager

AttainX, Inc.

New York

Remote

USD 120,000 - 160,000

2 days ago
Be an early applicant

Sr Manager of Project Controls

Chobani

New York

Remote

USD 120,000 - 150,000

2 days ago
Be an early applicant

Director of Solution Engineering - Northeast region (Remote in New England or New York Metro)

GuidePoint Security, LLC

New York

Remote

USD 120,000 - 180,000

9 days ago

Transfer Pricing - Director and Senior Manager

Ryan, Inc

Woodcliff Lake

Remote

USD 120,000 - 160,000

5 days ago
Be an early applicant

Senior Manager - Control Management , Process Risk Reduction

American Express

New York

On-site

USD 90,000 - 165,000

Yesterday
Be an early applicant

Client Strategy Senior Manager - Integrated Media

PMG

Fort Worth

On-site

USD 100,000 - 130,000

5 days ago
Be an early applicant

Enterprise Change Management Office Program Senior Manager (Hybrid)

Citi

Remote

USD 170,000 - 300,000

Yesterday
Be an early applicant

Sales Engineer - Northeast

SpyCloud

New York

Remote

USD 90,000 - 150,000

19 days ago