Information Technology Risk Manager
Lead complex IT audit engagements from planning through reporting, focusing on various technology risks. Prepare and present executive-level reports to senior management and the Audit Committee.
- Hybrid
- Ontario
- Posted Jul 10, 2026
- Apply by Aug 9, 2026
- 1 position
Job summary
Title: IT Risk Manager - Internal Audit Location: Hybrid ( 1-2 days per week) Duration: TBD Clearance: Must have a valid or be eligible for Reliability Clearance. ( Candidates must have resided in Canada for a minimum of five consecutive years.) Objective Provide independent IT Audit Services to support the Internal Audit function by assessing technology risks, controls, and governance practices. Key Responsibilities Lead complex IT audit engagements from planning through reporting, focusing on cybersecurity, cloud, data/privacy, IAM, AI, third-party technology, and emerging risks. Perform risk assessments, control evaluations, testing, and evidence-based analysis. Review and challenge audit work to ensure quality, consistency, and sound conclusions. Develop clear audit findings outlining root causes, risks, and improvement opportunities. Prepare and present executive-level reports to senior management and the Audit Committee. Engage with Director- and VP-level stakeholders on audit objectives, issues, and findings. Identify systemic risk themes and support improvements to IT audit practices. Use data analytics and Generative AI to improve risk sensing, testing coverage, efficiency, and reporting. Top Skills Required Strong knowledge of cloud, cybersecurity, identity, networks, endpoint security, data platforms, and Agile delivery. Experience with frameworks such as NIST, CIS Controls, COBIT, ISO 2700x, and IIA Standards. Expertise in technology risk areas such as cybersecurity, cloud/IAM security, data governance, third-party risk, and technology resilience. Experience using analytics tools such as Power BI, ACL/HighBond, IDEA, Python, or SQL for audit and risk analysis. Strong executive communication and stakeholder management skills. Professional certification such as CISA, CISSP, CISM, CRISC, or CGEIT.
What you’ll do
Lead complex IT audit engagements from planning through reporting, focusing on various technology risks. Prepare and present executive-level reports to senior management and the Audit Committee.
Requirements
Candidates should have strong knowledge of technology risk areas and experience with relevant frameworks. Professional certifications such as CISA, CISSP, or similar are preferred.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cloud
- Cybersecurity
- Identity
- Networks
- Endpoint Security
- Data Platforms
- Agile Delivery
- NIST
- CIS Controls
- COBIT
- ISO 2700x
- IIA Standards
- Data Governance
- Third-Party Risk
- Technology Resilience
- Power BI
Job areas
- Technology
- Consulting
- Data & Analytics
- Management & Leadership
- Security & Safety
Additional details
- Minimum experience
- 5+ years
- Apply by
- Aug 9, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 2 days per week
- Seniority
- Mid-Senior level
- Application method
- Direct apply is available
