Title: Senior Manager, U.S. Cyber and IT Risk Management
Requisition ID: 250996
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
Purpose
The role will contribute to the implementation of the U.S. Cyber and IT Risk Management Framework across the second line of defense. The framework encompasses oversight, reporting, governance, communications, and education. As part of the second line of defense for businesses in the United States, IT Risk provides independent oversight and challenge as well as assists in the development of the methodologies, policies, process, and tools to support the U.S. Cyber and IT Risk Management Framework.
Contributes to the overall success of Cyber and IT Risk Management in the United States, ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team’s business strategies and objectives. Ensures all activities conducted are in compliance with governing regulations, internal policies and procedures.
What You’ll Do
-
Maintains the U.S. Cyber and IT Risk Management Framework and best practices within the Bank while acting as a center of excellence for IT and Cyber Risk in the U.S.
-
Collaborates with the lines of business by acting in a consultative capacity to advise on IT risks that influence their business and ability to meet established strategic objectives, while maintaining oversight and objective challenge.
-
Challenges the IT Risk components of the first line in the Risk & Control Self-Assessment (RCSA) process for the U.S., covering Legal Entities, Processes and Business Lines.
-
Challenges investigation of IT Incidents to define root causes and provides input into remediation actions.
-
Performs Deep Dives and Independent Reviews to assess the effectiveness of controls surrounding key processes, and to identify remediation for gaps to actively and demonstrably mitigate IT and Cybersecurity risks.
-
Challenges IT and Cybersecurity risks within scenario analysis.
-
Monitors Cybersecurity risks and the controls in place within the bank, as well as external Cyber security reporting which may impact the bank.
-
Monitors compliance with IT Risk Policies, Standards and Guidelines.
-
Prepares monthly and quarterly IT and Cyber Risk reporting for U.S. committees and senior management
-
Has good knowledge of risk management practices required to create a culture of risk management compliance.
-
Identifies, assesses, and monitors IT and Cybersecurity related risks based on risk management policies and procedures.
-
Reviews and challenges work of first line of defense for risk management purposes.
-
Exhibits best practice risk management skills through effective internal risk controls, risk monitoring, risk assessment and improvement of risk management processes.
-
Understands how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
-
Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank’s Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
-
Champions a high-performance environment and contributes to an inclusive work environment.
What You’ll Bring
- Strong understanding of IT risk management frameworks in a global banking environment.
- Able to convey complex concepts and ideas on issues requiring interpretation and opinion.
- Independent in judgment and with a high standard of conduct and ethics. Able to challenge and be challenged while maintaining the highest levels of professionalism.
- Good negotiation skills and ability to resolve conflict between teams or individuals so that functional / organizational objectives are achieved.
- Excellent analytical skills; critical thinking and problem solving skills.
- Strong oral and written skills on a business level in English, good presentation skills, and an ability to work with all levels of the organization.
- Good interpersonal skills
- Strong expertise in IT Risk Management (e.g. Logical Access, Data Leakage, Disaster Recovery)
- Experience with Cybersecurity Risk Management is preferred
- A minimum of 7 years of experience in technology departments and/or risk management, preferably in a financial institution
- Industry certifications desirable (e.g., ISACA CRISC)
- Advanced knowledge of relevant regulatory rules (FFIEC, NYDFS 500) and frameworks (NIST, COBIT) is preferred
Interested?
If your experience is closely related but doesn’t align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank!
At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. That’s why we work to grow and diversify talent and engage employees in a performance-oriented culture.
What's in it for you?
Scotiabank wants you to be able to bring your best self to work – and life, every day. With a focus on holistic well-being, our many flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.
#GBMAuditRisk
Location(s): United States : Texas : Dallas
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth
Job Segment:
Risk Management, Cyber Security, Compliance, Investment Banking, Technical Support, Finance, Security, Legal, Technology