Head of Audit and Risk
Top Benefits
About the role
Division
Regular, Full time Closing Date: August 14, 2026 The Ontario Securities Commission (OSC) is the statutory body responsible for regulating Ontario’s capital markets in accordance with the mandate established in the provincial Securities Act and the Commodity Futures Act. The mandate of the OSC is to provide protection to investors from unfair, improper or fraudulent practices, to foster fair, efficient and competitive capital markets and confidence in the capital markets, to foster capital formation, and to contribute to the stability of the financial system and the reduction of systemic risk. This mandate is performed through policy, operational, and enforcement activities. The OSC also contributes to national and global securities regulation development. We offer a diverse, fair, and flexible work environment and take pride in our challenging and rewarding work.
Summary
The Manager, Audit and Risk resides within the Audit and Risk function and is responsible for supporting the implementation of the division’s strategic direction and enhancing integration across internal audit, enterprise risk management, and operational resilience activities. Reporting to the Chief Audit and Risk Executive, the role provides leadership in the coordination, oversight, and continuous improvement of audit and risk planning, processes, reporting, stakeholder engagement and integrated assurance practices. The Manager, Audit and Risk will help ensure that outputs throughout the function are effectively coordinated, aligned to divisional priorities, and communicated in a manner that supports executive and Board-level oversight. The role will support the continued maturation of the organization’s risk management, assurance, and governance capabilities by promoting stronger alignment between audit, risk, resilience, and other assurance activities, while helping to foster a risk-aware culture and informed decision-making across the organization. The role will also provide support to the Chief Audit and Risk Executive in governance discussions, committee activities, and ongoing management of the function, while serving as a key point of continuity and leadership across audit and risk workstreams. The Manager, Audit and Risk will work closely with internal stakeholders across the organization to support implementation of the Audit and Risk roadmap, improve the quality and integration of planning and reporting, strengthen enterprise-wide engagement, and provide management oversight of key deliverables produced by the team. The role will contribute to the advancement of integrated assurance reporting, monitor emerging governance, regulatory, and industry developments, and support the use of data analytics, technology-enabled monitoring, and risk intelligence to enhance organizational insight, risk oversight, and decision-making.
Key Duties and Responsibilities
Strategic Leadership and Functional Integration Lead the implementation of the Audit and Risk division’s multi-year strategy and roadmap, translating strategic priorities into coordinated plans, activities, and reporting. Lead effective delivery of audit, risk and business continuity objectives, including providing advice on emerging risks, control effectiveness, governance matters, and strategic priorities. Facilitate informed decision-making by monitoring emerging regulatory, governance, risk and audit developments and assess implications for the organization for translating complex audit and risk information into practical insights and recommendations. Lead the development and maintenance for the integration and coordination of activities across internal audit, enterprise risk management, and operational resilience/business continuity to support a more cohesive functional approach. Develop and coordinate integrated workplans and reporting cadences across the function to improve alignment, consistency, and stakeholder experience. Promote the use of data analytics, risk intelligence, and technology-enabled monitoring to enhance audit coverage, risk insights and decision support. Support the Chief Audit and Risk Executive in setting priorities, monitoring progress, and identifying opportunities to strengthen the effectiveness and maturity of the function. Contribute to the development and management of the division’s budget, resource planning, and procurement services. Support management of external audit, co-source, consulting and technology service providers, including performance monitoring and contract oversight. Support the Chief Audit and Risk Executive in engaging senior stakeholders on strategic initiatives, functional performance, and organizational risk matters. Service as the primary management lead for day-to-day operations, providing leadership, decision-making, and stakeholder support; and ensuring continuity for the function, including acting as a delegate for the Chief Audit and Risk Executive, as required.
Audit Oversight and Internal Audit Operations
Oversee internal audit activities, including monitoring progress against plans, identifying issues requiring escalation, and ensuring deliverables are completed on a timely basis. Review audit deliverables, including draft reports, findings, and related materials, to ensure quality, consistency, completeness, and alignment with functional standards and objectives. Support the prioritization, coordination, and follow-up of audit findings, recommendations, and management action plans. Help ensure that internal audit outputs are appropriately connected to enterprise risk themes, control issues, and broader governance reporting. Lead the development and annual refresh of the internal audit plan in coordination with enterprise risk management activities, using risk insights, emerging themes, and organizational priorities to support a risk-informed and integrated assurance approach. Establish and maintain audit methodologies, quality assurance practices, and internal processes, tools and templates for internal audit consistency and reporting.
Enterprise Risk Management and Risk Insight
Support enterprise risk reporting and the collection, analysis, and synthesis of risk information from across the organization. Work with business leaders and stakeholders to identify key risk themes, emerging issues, gaps, and trends requiring management attention. Strengthen alignment between branch-level and enterprise-level risk reporting, audit findings, and related governance discussions. Support the ERM Lead in management discussions incorporating relevant audit and assurance inputs to challenge management assumptions, and support a current and credible view of enterprise risk exposures. Support the continued evolution of risk management practices, reporting, and risk governance in alignment with the division’s roadmap and priorities. Contribute to the development of integrated risk and assurance reporting that provides meaningful insight to senior management and Board committees. Support the ERM Lead with the resolution of cross-functional issues, competing priorities and risk-related matters through effective consultations and negotiations.
Governance, Committee Leadership, and Reporting
Coordinate the preparation of quarterly materials, briefings, presentations, and reports for senior management, management committees (i.e. Risk Steering Committee), and Board committees (i.e. Audit and Finance Committee and the Risk Committee of the Board) ensuring reporting is clear, integrated and responsive to governance priorities. Enhance the quality of quarterly and ad hoc reporting by ensuring it includes clear analysis of residual risk, implications, themes, gaps, and priorities. Support the Chief Audit and Risk Executive in the effective functioning of the committee through agenda planning, coordination of inputs, facilitation of discussions, and follow-up on action items working closely with the Branch Administrator to support effective coordination. Participate and present in governance forums, steering committees, and working groups to provide accurate, concise and actionable information on audit, risk and resilience, along with supporting early identification and escalation of risk and control matters. Represent the Audit and Risk function in internal discussions and committees, as required, and support external interactions with relevant stakeholders, and sector forums.
Stakeholder Engagement and Coordination
Develop and maintain effective working relationships with governance committees, management forums, and the Board/board oversight committees. Build and maintain effective working relationships with senior leaders, including managers, Vice Presidents, Senior Vice Presidents, and other stakeholders across the organization. Support a coordinated and strategic approach to stakeholder engagement across the Audit and Risk function to reduce fragmentation and improve the effectiveness of business interactions. Work with internal stakeholders to support understanding of audit, risk, governance, and control matters, and to facilitate coordinated responses to issues and priorities.
People Leadership and Team Effectiveness
Provide oversight, guidance, and support to direct reports and contribute to effective coordination across the team. Review deliverables produced by team members across internal audit, enterprise risk, and related streams, providing direction and feedback as appropriate. Support employee development, collaboration, and the effective management of priorities across a small and specialized team.
Continuous Improvement and Strategic Enablement
Support strategic initiatives to enhance tools, processes, and information management practices across the Audit and Risk function, including governance, risk, and compliance (GRC) initiatives. Identify and advance opportunities to improve reporting, coordination, efficiency, and the overall effectiveness of audit and risk activities. Contribute to the maturation of integrated assurance practices, thematic reporting, and lessons learned across the function. Support the modernization of the function in accordance with evolving organizational needs, regulatory expectations, and industry practices.
Required Qualifications
At least one professional certification in audit, risk, or governance, such as: Certified Internal Auditor (CIA) Certification in Risk Management Assurance (CRMA) Chartered Professional Accountant (CPA) Certified Information Systems Auditor (CISA) Certified in Risk and Information Systems Control (CRISC) Canadian Risk Management designation (CRM) or other relevant audit, risk, governance, or controls-related designations University degree in business, finance, accounting, risk management, public administration, or a related field. Minimum 10 years of progressive experience in internal audit, enterprise risk management, governance, compliance, internal control, or related areas. Demonstrated experience supporting strategic planning, governance processes, and cross-functional coordination in a complex organizational environment. Strong knowledge of audit, risk management, internal control, and governance frameworks and practices. Experience preparing or reviewing reporting and briefing materials for senior management, executive committees, and/or Board committees. Demonstrated ability to review and synthesize complex information and provide clear, relevant, and actionable insight for decision-making purposes. Strong written, verbal, and presentation skills, with the ability to communicate effectively with senior leaders and specialized stakeholders. Strong analytical, judgment, and problem-solving skills, with the ability to manage competing priorities and exercise sound discretion. Demonstrated leadership or supervisory experience, including coordinating work, reviewing deliverables, and supporting team performance and development.
Preferred Qualifications
Knowledge of securities regulation, capital markets, and market conduct frameworks.
Successful completion of the Canadian Securities Course (CSC)
Experience in a public sector, regulatory, or similarly complex governance environment. Experience supporting Board or Board committee processes and reporting. Familiarity with governance, risk, and compliance tools and related implementation initiatives. Exposure to information technology risk, cybersecurity risk, AI risk, or operational resilience. This opportunity is considered to be a business-critical role supporting the CARE department. Grow your career and make a difference working at the OSC.
- OSC Employees: please apply in Workday using the Browse Jobs feature within your Jobs Hub *
We thank all applicants for their interest in the Ontario Securities Commission. We will contact those selected for an interview. The OSC is committed to diversity and providing an inclusive workplace and providing accommodation in accordance with the Accessibility for Ontarians with Disabilities Act and the Human Rights Code. It is our priority to ensure employment opportunities are visible and barrier-free to all under-represented groups including but not limited to, Indigenous, Black and racialized groups, people with disabilities, women and people from the 2SLGBTQI+ community, to achieve an employee demographic profile reflective of the demographic profile of Ontarians. The OSC is a proud partner with the following organizations: Ascend Canada, BlackNorth Initiative, Canadian Centre for Diversity and Inclusion, and Pride at Work Canada If you require an accommodation during the recruitment process, please let us know by contacting our confidential inbox HRRecruitment@osc.gov.on.ca. Visit Accessibility at the OSC to review the OSC’s policies on accessibility and accommodation in the workplace.
Not the right fit? Search for Audit and Risk jobs in Toronto, Ontario, Canada
About Ontario Securities Commission
The Ontario Securities Commission administers and enforces securities law in the province of Ontario. The mandate of the OSC is to provide protection to investors from unfair, improper or fraudulent practices, to foster fair, efficient and competitive capital markets and confidence in the capital markets, to foster capital formation, and to contribute to the stability of the financial system and the reduction of systemic risk.
Similar Jobs
Head of Audit and Risk
Top Benefits
About the role
Division
Regular, Full time Closing Date: August 14, 2026 The Ontario Securities Commission (OSC) is the statutory body responsible for regulating Ontario’s capital markets in accordance with the mandate established in the provincial Securities Act and the Commodity Futures Act. The mandate of the OSC is to provide protection to investors from unfair, improper or fraudulent practices, to foster fair, efficient and competitive capital markets and confidence in the capital markets, to foster capital formation, and to contribute to the stability of the financial system and the reduction of systemic risk. This mandate is performed through policy, operational, and enforcement activities. The OSC also contributes to national and global securities regulation development. We offer a diverse, fair, and flexible work environment and take pride in our challenging and rewarding work.
Summary
The Manager, Audit and Risk resides within the Audit and Risk function and is responsible for supporting the implementation of the division’s strategic direction and enhancing integration across internal audit, enterprise risk management, and operational resilience activities. Reporting to the Chief Audit and Risk Executive, the role provides leadership in the coordination, oversight, and continuous improvement of audit and risk planning, processes, reporting, stakeholder engagement and integrated assurance practices. The Manager, Audit and Risk will help ensure that outputs throughout the function are effectively coordinated, aligned to divisional priorities, and communicated in a manner that supports executive and Board-level oversight. The role will support the continued maturation of the organization’s risk management, assurance, and governance capabilities by promoting stronger alignment between audit, risk, resilience, and other assurance activities, while helping to foster a risk-aware culture and informed decision-making across the organization. The role will also provide support to the Chief Audit and Risk Executive in governance discussions, committee activities, and ongoing management of the function, while serving as a key point of continuity and leadership across audit and risk workstreams. The Manager, Audit and Risk will work closely with internal stakeholders across the organization to support implementation of the Audit and Risk roadmap, improve the quality and integration of planning and reporting, strengthen enterprise-wide engagement, and provide management oversight of key deliverables produced by the team. The role will contribute to the advancement of integrated assurance reporting, monitor emerging governance, regulatory, and industry developments, and support the use of data analytics, technology-enabled monitoring, and risk intelligence to enhance organizational insight, risk oversight, and decision-making.
Key Duties and Responsibilities
Strategic Leadership and Functional Integration Lead the implementation of the Audit and Risk division’s multi-year strategy and roadmap, translating strategic priorities into coordinated plans, activities, and reporting. Lead effective delivery of audit, risk and business continuity objectives, including providing advice on emerging risks, control effectiveness, governance matters, and strategic priorities. Facilitate informed decision-making by monitoring emerging regulatory, governance, risk and audit developments and assess implications for the organization for translating complex audit and risk information into practical insights and recommendations. Lead the development and maintenance for the integration and coordination of activities across internal audit, enterprise risk management, and operational resilience/business continuity to support a more cohesive functional approach. Develop and coordinate integrated workplans and reporting cadences across the function to improve alignment, consistency, and stakeholder experience. Promote the use of data analytics, risk intelligence, and technology-enabled monitoring to enhance audit coverage, risk insights and decision support. Support the Chief Audit and Risk Executive in setting priorities, monitoring progress, and identifying opportunities to strengthen the effectiveness and maturity of the function. Contribute to the development and management of the division’s budget, resource planning, and procurement services. Support management of external audit, co-source, consulting and technology service providers, including performance monitoring and contract oversight. Support the Chief Audit and Risk Executive in engaging senior stakeholders on strategic initiatives, functional performance, and organizational risk matters. Service as the primary management lead for day-to-day operations, providing leadership, decision-making, and stakeholder support; and ensuring continuity for the function, including acting as a delegate for the Chief Audit and Risk Executive, as required.
Audit Oversight and Internal Audit Operations
Oversee internal audit activities, including monitoring progress against plans, identifying issues requiring escalation, and ensuring deliverables are completed on a timely basis. Review audit deliverables, including draft reports, findings, and related materials, to ensure quality, consistency, completeness, and alignment with functional standards and objectives. Support the prioritization, coordination, and follow-up of audit findings, recommendations, and management action plans. Help ensure that internal audit outputs are appropriately connected to enterprise risk themes, control issues, and broader governance reporting. Lead the development and annual refresh of the internal audit plan in coordination with enterprise risk management activities, using risk insights, emerging themes, and organizational priorities to support a risk-informed and integrated assurance approach. Establish and maintain audit methodologies, quality assurance practices, and internal processes, tools and templates for internal audit consistency and reporting.
Enterprise Risk Management and Risk Insight
Support enterprise risk reporting and the collection, analysis, and synthesis of risk information from across the organization. Work with business leaders and stakeholders to identify key risk themes, emerging issues, gaps, and trends requiring management attention. Strengthen alignment between branch-level and enterprise-level risk reporting, audit findings, and related governance discussions. Support the ERM Lead in management discussions incorporating relevant audit and assurance inputs to challenge management assumptions, and support a current and credible view of enterprise risk exposures. Support the continued evolution of risk management practices, reporting, and risk governance in alignment with the division’s roadmap and priorities. Contribute to the development of integrated risk and assurance reporting that provides meaningful insight to senior management and Board committees. Support the ERM Lead with the resolution of cross-functional issues, competing priorities and risk-related matters through effective consultations and negotiations.
Governance, Committee Leadership, and Reporting
Coordinate the preparation of quarterly materials, briefings, presentations, and reports for senior management, management committees (i.e. Risk Steering Committee), and Board committees (i.e. Audit and Finance Committee and the Risk Committee of the Board) ensuring reporting is clear, integrated and responsive to governance priorities. Enhance the quality of quarterly and ad hoc reporting by ensuring it includes clear analysis of residual risk, implications, themes, gaps, and priorities. Support the Chief Audit and Risk Executive in the effective functioning of the committee through agenda planning, coordination of inputs, facilitation of discussions, and follow-up on action items working closely with the Branch Administrator to support effective coordination. Participate and present in governance forums, steering committees, and working groups to provide accurate, concise and actionable information on audit, risk and resilience, along with supporting early identification and escalation of risk and control matters. Represent the Audit and Risk function in internal discussions and committees, as required, and support external interactions with relevant stakeholders, and sector forums.
Stakeholder Engagement and Coordination
Develop and maintain effective working relationships with governance committees, management forums, and the Board/board oversight committees. Build and maintain effective working relationships with senior leaders, including managers, Vice Presidents, Senior Vice Presidents, and other stakeholders across the organization. Support a coordinated and strategic approach to stakeholder engagement across the Audit and Risk function to reduce fragmentation and improve the effectiveness of business interactions. Work with internal stakeholders to support understanding of audit, risk, governance, and control matters, and to facilitate coordinated responses to issues and priorities.
People Leadership and Team Effectiveness
Provide oversight, guidance, and support to direct reports and contribute to effective coordination across the team. Review deliverables produced by team members across internal audit, enterprise risk, and related streams, providing direction and feedback as appropriate. Support employee development, collaboration, and the effective management of priorities across a small and specialized team.
Continuous Improvement and Strategic Enablement
Support strategic initiatives to enhance tools, processes, and information management practices across the Audit and Risk function, including governance, risk, and compliance (GRC) initiatives. Identify and advance opportunities to improve reporting, coordination, efficiency, and the overall effectiveness of audit and risk activities. Contribute to the maturation of integrated assurance practices, thematic reporting, and lessons learned across the function. Support the modernization of the function in accordance with evolving organizational needs, regulatory expectations, and industry practices.
Required Qualifications
At least one professional certification in audit, risk, or governance, such as: Certified Internal Auditor (CIA) Certification in Risk Management Assurance (CRMA) Chartered Professional Accountant (CPA) Certified Information Systems Auditor (CISA) Certified in Risk and Information Systems Control (CRISC) Canadian Risk Management designation (CRM) or other relevant audit, risk, governance, or controls-related designations University degree in business, finance, accounting, risk management, public administration, or a related field. Minimum 10 years of progressive experience in internal audit, enterprise risk management, governance, compliance, internal control, or related areas. Demonstrated experience supporting strategic planning, governance processes, and cross-functional coordination in a complex organizational environment. Strong knowledge of audit, risk management, internal control, and governance frameworks and practices. Experience preparing or reviewing reporting and briefing materials for senior management, executive committees, and/or Board committees. Demonstrated ability to review and synthesize complex information and provide clear, relevant, and actionable insight for decision-making purposes. Strong written, verbal, and presentation skills, with the ability to communicate effectively with senior leaders and specialized stakeholders. Strong analytical, judgment, and problem-solving skills, with the ability to manage competing priorities and exercise sound discretion. Demonstrated leadership or supervisory experience, including coordinating work, reviewing deliverables, and supporting team performance and development.
Preferred Qualifications
Knowledge of securities regulation, capital markets, and market conduct frameworks.
Successful completion of the Canadian Securities Course (CSC)
Experience in a public sector, regulatory, or similarly complex governance environment. Experience supporting Board or Board committee processes and reporting. Familiarity with governance, risk, and compliance tools and related implementation initiatives. Exposure to information technology risk, cybersecurity risk, AI risk, or operational resilience. This opportunity is considered to be a business-critical role supporting the CARE department. Grow your career and make a difference working at the OSC.
- OSC Employees: please apply in Workday using the Browse Jobs feature within your Jobs Hub *
We thank all applicants for their interest in the Ontario Securities Commission. We will contact those selected for an interview. The OSC is committed to diversity and providing an inclusive workplace and providing accommodation in accordance with the Accessibility for Ontarians with Disabilities Act and the Human Rights Code. It is our priority to ensure employment opportunities are visible and barrier-free to all under-represented groups including but not limited to, Indigenous, Black and racialized groups, people with disabilities, women and people from the 2SLGBTQI+ community, to achieve an employee demographic profile reflective of the demographic profile of Ontarians. The OSC is a proud partner with the following organizations: Ascend Canada, BlackNorth Initiative, Canadian Centre for Diversity and Inclusion, and Pride at Work Canada If you require an accommodation during the recruitment process, please let us know by contacting our confidential inbox HRRecruitment@osc.gov.on.ca. Visit Accessibility at the OSC to review the OSC’s policies on accessibility and accommodation in the workplace.
Not the right fit? Search for Audit and Risk jobs in Toronto, Ontario, Canada
About Ontario Securities Commission
The Ontario Securities Commission administers and enforces securities law in the province of Ontario. The mandate of the OSC is to provide protection to investors from unfair, improper or fraudulent practices, to foster fair, efficient and competitive capital markets and confidence in the capital markets, to foster capital formation, and to contribute to the stability of the financial system and the reduction of systemic risk.