Title: Manager, Cyber Security & IT Risk
Requisition ID: 270421
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
Manager, Cyber Security and IT Risk will contribute to the overall success of Cyber Security and IT Risk Management within Global Risk Management by supporting independent Second Line of Defense oversight, review, and challenge of cybersecurity risk management activities across the Bank. The role is focused on conducting cybersecurity risk assessments and thematic reviews, challenging First Line of Defense risk identification and remediation activities, monitoring key cyber risk indicators, supporting issue management oversight, and preparing concise risk reporting for senior management and governance committees.
As part of the Second Line of Defense, the role provides objective challenge and advice to First Line teams while maintaining independence from control ownership and execution. The role helps assess whether IT and cyber risks are appropriately identified, measured, monitored, reported, and remediated in alignment with the Bank’s risk appetite, internal standards, regulatory expectations, and the Cyber and IT Risk Management Framework.
Is this role right for you? In this role, you will:
- Conduct risk-based cybersecurity assessments, thematic reviews, and targeted challenge activities across key cybersecurity domains.
- Independently assess whether cyber risks are appropriately identified, measured, monitored, reported, and remediated by the First Line of Defense.
- Evaluate the effectiveness of risk management processes, control environments, remediation activities, and governance practices, and provide objective challenge, recommendations, and escalation where material risks or control weaknesses exist.
- Support monthly and quarterly cyber and IT risk reporting for senior management and risk governance committees.
- Analyze and challenge KRIs, control metrics, issue trends, assessment results, emerging threats, and remediation progress to develop clear, concise, and decision-useful risk insights.
- Escalate material risks, deteriorating trends, and persistent control gaps through appropriate governance channels.
- Support Second Line oversight of cyber and IT risk issues throughout the issue lifecycle, including issue identification, severity assessment, root cause review, management action plan challenge, remediation progress monitoring, evidence review, and closure readiness assessment.
- Provide challenge where remediation actions do not appear sufficient, timely, sustainable, or aligned to the underlying risk. This also includes IT and Cyber Risk Acceptance oversight.
- Review and challenge the appropriateness, completeness, and effectiveness of cybersecurity standards, procedures, methodologies, and governance frameworks developed by the First Line of Defense.
- Assess alignment with regulatory requirements, industry frameworks, emerging risks, and the Bank's cyber and IT risk management framework, and provide recommendations to address gaps or strengthen control expectations.
- Contribute to the ongoing development and maturation of the Cyber Security and IT Risk Management function by enhancing challenge methodologies, assessment approaches, reporting capabilities, issue management processes, governance practices, and supporting tools.
- Support the development of frameworks, procedures, templates, and guidance that strengthen the effectiveness, consistency, and scalability of Second Line oversight activities.
Do you have the skills that will enable you to succeed? We’d love to work with you if you have experience with:
- Minimum 5 years of experience in cybersecurity, technology risk, information security, internal audit, risk advisory, or related disciplines, preferably within a financial services or highly regulated environment.
- Experience conducting cybersecurity assessments, thematic reviews, control evaluations, or independent challenge activities across key cybersecurity domains.
- Strong understanding of cybersecurity risk management practices and control frameworks, including areas such as identity and access management, vulnerability management, data protection, security monitoring, incident response, third-party risk, cloud security, and technology resilience.
- Experience reviewing evidence, assessing control effectiveness, identifying control gaps, and communicating risk implications to business and technology stakeholders.
- Experience supporting issue management and Risk acceptance processes, including issue identification, root cause analysis, remediation plan review, evidence assessment, and closure validation. Including Risk Acceptance adjudication and oversight.
- Experience analyzing risk indicators, assessment results, issue trends, and emerging threats to generate meaningful risk insights and management reporting.
- Ability to prepare concise, executive-level reporting and present cybersecurity risks, control weaknesses, and remediation concerns to senior stakeholders.
- Experience reviewing cybersecurity standards, methodologies, procedures, or governance frameworks and assessing alignment with regulatory requirements and industry expectations.
- Experience contributing to the enhancement of risk management methodologies, assessment frameworks, governance processes, reporting capabilities, or oversight practices.
- Strong written and verbal communication skills with the ability to influence stakeholders and provide effective challenge while maintaining professional relationships.
What’s in it for you?
- The opportunity to join a forward-thinking company surrounded by a collaborative team of innovative thinkers.
- A rewarding career path with diverse opportunities for professional development.
- Internal development to support your growth and enhance your skills.
- A competitive compensation and benefits package.
- An organization committed to making a difference in our communities– for you and our customers.
- We have an inclusive and collaborative working environment that encourages creativity, curiosity, and celebrates success!
Location(s): Canada : Ontario : Toronto
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
Job Segment:
Cyber Security, Risk Management, Corporate Security, Internal Audit, Investment Banking, Security, Finance