Back to job search
Manulife logo
ManulifeVerified Job Source

Business Unit Security Officer

  • Toronto, ON
  • Hybrid
  • Posted Sep 27, 2026
  • 1 position

$86,100–$136,100 / year

Opens an external site

Sign in to save this job
Employment type
Full-time
Experience level
Senior · 5+ years
Minimum education
Professional degree
Apply by
Oct 16, 2026
Posting language
English
Working hours
40 hours per week

Job summary

The Business Unit Security Officer performs risk-based information security assessments for new and existing technologies to identify threats across cloud and on-premises infrastructure. They also consult with business and engineering teams to integrate security controls and manage incident response activities.

Job details

Join our Canadian Segment Security Technology Team! Reporting to our Director, Business Unity Security Officer; this role belongs to the First Line of Defense. Our team performs risk-based information security assessments for new technologies and changes to existing IT-based solutions; we are accountable to identify threats for both the cloud-based and on premises-based infrastructure, platform, and services: Perform Canadian Business Unit project and technology information risk assessments including assessing risks and define controls as well as tracking the implementation of controls. Build, document and/or implement BAU security controls applicable to the platform/services. Evaluate products for implementing security controls in the cloud or on-premises spaces. Position Responsibilities: Risk Assessment and Management: Conduct comprehensive risk assessments of technology systems, applications, and infrastructure to identify potential threats, vulnerabilities, and impacts on business operations. Understand and apply security policies and standards to identify gaps and ensure compliance. Application Security and Release Sign-Off: Review and sign off on application security measures during the software development lifecycle. Ensure security requirements are integrated into the DevOps pipeline and security tests. Consultation and Collaboration: Consult with business, engineering, and architect teams to integrate security practices into their workflows. Incident Response and Management: Provide domain expertise in security incident investigations and response. Ensure each information risk assessment completed is peer-reviewed & communicated to larger distribution to various partners. Team Development and Training: Deliver training to key team members around the IRM processes. Respond to audits, regulatory reviews, risk, and controls self-assessments. Continuous Improvement: Stay up to date on the latest security trends, threats, and technologies. Evaluate existing processes to redefine processes. Required Qualifications: Experience in cloud security, application security, and data protection. Familiarity with DevOps pipelines and security testing methodologies. 5+ years of experience in a combination of relevant technical disciplines in the field of Information Security: network security, application security, identity and access management, IT operations security, vulnerability management, information protection, physical security, cybersecurity. 5+ years of IT/Information Risk management experience: vendor risk management, project risk management, IT audit or IT controls assessment. Deep knowledge of cloud computing security and IaaS, PaaS, or SaaS environments. Knowledge of security frameworks, regulatory requirements and standards. Excellent business communication to lead presentation, facilitate discussion across all levels and audiences. Influence behavior to reduce risks and foster a strong information security risk management culture. Problem solving, analytical, and establish new way/processes to improve. Collaborative with a coaching and development approach. Strong time management and organizational skills to manage multiple tasks and changing priorities. Preferred Qualifications: Background in Computer Science, Information Technology, Software Engineering, Business Administration, or relevant educational and professional experience preferred. Knowledge and understanding of the financial industry are preferred. Relevant professional designations (e.g., CISSP, CRISC, CISM, CISA, GSEC) preferred. When you join our team: • We’ll empower you to learn and grow the career you want. • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. • As part of our global team, we’ll support you in shaping the future you want to see The role being advertised is an existing vacancy. About Manulife and John Hancock Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html. Manulife is an Equal Opportunity Employer At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law. It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact hr@manulife.com. Referenced Salary Location Waterloo, Ontario Working Arrangement Hybrid Salary range is expected to be between $86,100.00 CAD - $136,100.00 CAD Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. If you are applying for this role outside of the primary location, please contact hr@manulife.com for the salary range for your location. Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S., please contact hr@manulife.com for more information about U.S.-specific paid time off provisions. We use data and analytics technologies, such as artificial intelligence (AI), and automated processing tools, to analyze and process the information you provide to us or third parties in the application process. For more information, please refer to our personal information collection statement.

What you’ll do

The Business Unit Security Officer performs risk-based information security assessments for new and existing technologies to identify threats across cloud and on-premises infrastructure. They also consult with business and engineering teams to integrate security controls and manage incident response activities.

Requirements

Candidates must have 5+ years of experience in Information Security and IT/Information Risk management, with deep knowledge of cloud environments and security frameworks. Strong communication skills and the ability to influence security culture are essential for this role.

Benefits

• Health insurance • Dental insurance • Mental health support • Vision insurance • Short-term disability • Long-term disability • Life insurance • AD&D insurance • Adoption/surrogacy benefits • Wellness benefits • Employee/family assistance plans • Retirement savings plans • Pension • Global share ownership plan • Paid time off • Holidays • Vacation • Personal days • Sick days

Listed skills

  • Time management · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cloud security
  • Application security
  • Data protection
  • DevOps pipelines
  • Risk assessment
  • Information security
  • Network security
  • Identity and access management
  • Vulnerability management
  • Cybersecurity
  • Vendor risk management
  • IT audit
  • Cloud computing
  • Business communication
  • Analytical skills
  • Time management
  • Cloud Security Applications
  • Certified Information System Auditor (CISA)
  • Influencing Skills
  • Discussion Facilitation
  • Workplace Inclusivity
  • Pipelines
  • Security Risk Management
  • Influencing Without Authority
  • Business Operations
  • Workflow Management
  • Organizational Skills
  • Time Off Management
  • Information Gathering
  • Artificial Intelligence
  • Application Security
  • Auditing
  • Automation
  • Mental Health
  • Business Administration
  • Business Communication
  • Management
  • Certified Information Systems Security Professional
  • Certified Information Security Manager
  • Software As A Service (SaaS)
  • Cloud Security
  • Computer Science
  • Information Technology
  • Continuous Improvement Process
  • Security Controls
  • Certified In Risk And Information Systems Control
  • Cyber Security
  • Information Privacy
  • Software Development Life Cycle
  • DevOps

Job areas

  • Security & Safety
  • Technology
  • Finance & Accounting
  • Software
  • Management & Leadership
  • IT Security Officer
  • Business / Management Consultant
  • Management and Organization Analysts
  • Management Analysts

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Browse all Easy Apply jobs