Technology Risk Manager
- Toronto, ON
- Hybrid
- Posted Sep 26, 2026
- 1 position
Opens an external site
- Employment type
- Full-time
- Experience level
- Lead · 10+ years
- Apply by
- Oct 14, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 2 days per week
- Seniority
- Mid-Senior level
Job summary
Advise business and technology partners on security programs, technology controls, risk assessments, regulatory compliance, audits, and incident response. Lead or contribute to control assessments, risk reporting, remediation planning, and the development of security governance and risk management practices.
Job details
Key Accountabilities MUST HAVE: Cyber security experience Information security risk management experience Able to translate complex technical information for Business stakeholders to consume. NICE TO HAVE Security Architecture CUSTOMER: Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable Contribute to the definition, development, oversight, and advancement of a global security management strategy and framework Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the banks overall Enterprise Architecture, and any control gaps are addressed effectively and efficiently. Consult on Regulatory compliance requirements, reporting and questions Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team SHAREHOLDER: Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise Remain informed of emerging issues, industry trends and/or relevant changes Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required Maintain a culture of risk management and control, supported by effective processes and sound infrastructure an in alignment with risk appetite Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to identify risk / provide guidance May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level EMPLOYEE / TEAM: Continuously enhance knowledge / expertise in own area Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques Prioritize and manage own workload to deliver quality results and meet assigned timelines Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency Establish effective relationships across multiple business and technology partners, program and project managers Participate in knowledge transfer within the team and business units BREADTH & DEPTH: Expert knowledge of IT security and risk disciplines and practices Advanced knowledge of of organization, technology controls / security/ risk issues May participate on complex, comprehensive or large projects and initiatives Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors Hybrid: In office 2 days a week
What you’ll do
Advise business and technology partners on security programs, technology controls, risk assessments, regulatory compliance, audits, and incident response. Lead or contribute to control assessments, risk reporting, remediation planning, and the development of security governance and risk management practices.
Requirements
Requires cybersecurity and information security risk management experience, along with the ability to explain complex technical information to business stakeholders. The role calls for expert knowledge of IT security and risk disciplines and advanced knowledge of technology controls, security, and organizational risk issues.
Listed skills
- Regulatory Compliance · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity
- Information Security Risk Management
- Technology Controls
- Risk Assessment
- Control Design
- Vulnerability Assessment
- Security Architecture
- Enterprise Architecture
- Regulatory Compliance
- Audit Support
- Incident Response
- Risk Reporting
- Risk Mitigation
- Stakeholder Consultation
- Security Governance
Job areas
- Technology
- Security & Safety
- Management & Leadership
- Finance & Accounting
- Consulting
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
The Properties Group Management Ltd.
Real Estate Law Clerk
SponsoredDirect employerEasy Apply- On-site
- Ottawa, ON
- Posted Sep 24, 2026
Bédard Ressources Humaines
ITAD Services Representative #1265
SponsoredDirect employerEasy Apply- On-site
- Mississauga, ON
- Posted Sep 16, 2026
TUAC 501
Adjoint juridique
SponsoredDirect employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 24, 2026
