Share this Job

Senior Audit Manager Cyber Security - Toronto, ON

Date: Mar 16, 2019

Location: Toronto, ON, CA

Company: Scotiabank


Requisition ID: 50669

Join the Global Community of Scotiabankers to help customers become better off.

Position Title: Senior Audit Manager Cyber Security


Purpose of Job

This position is responsible for leading and conducting risk based information and cyber security audit assessments of medium to high complexity following the bank's audit methodology.


Key Accountabilities


  • Plan and lead collaborative risk-based Information and Cyber Security audits of moderate to high complexity in a local and global context and conclude whether risks are appropriately managed through the existence of effective control or other techniques. 
  • When assuming a supervisory role, the auditor is expected to develop a comprehensive audit plan clearly outlining the objective, scope, deliverables, approach, resourcing and schedule.
  • Ensure quality of assignments through effective application of the Audit Standard Methodology of the Bank and appropriate use of specific applications and tools.
  • Strive for efficient use of audit resources by monitoring execution of audits assigned, timely escalation, and management of conflicts. The incumbent is expected to seek and obtain direction, perspective and resources as required in order to complete the assigned audit on time and within budget.
  • Prepare and deliver effective presentations to clients at audit opening and closing meetings as a means of communicating and gaining their agreement and understanding of audit plans and audit results.
  • Provide value-adding and effective audit recommendations to client senior management identifying significant issues in a business context, working with audit clients to identify and recommend feasible solutions.
  • Present audits conclusions and reports in a relevant context and applicable to the Bank by ensuring they are supported by an orderly accumulation and analysis of documented audit evidence and that the content is clear and concise.
  • Perform accountabilities with minimal supervision and provide audit management and audit client with regular status updates of assignments. 
  • Actively seek to be informed of industry and corporate initiatives and trends in order to support effective audit continuous monitoring of the Banks proper management of information and cyber security risks.



  • Maintain information security competency through ongoing professional development and staying abreast of emerging technologies, risks and controls in information and cyber security.
  • Provide direction, guidance and expert advice to audit teams globally to allow definition of effective assessments on information and cyber security risk management.
  • When required, prepare and deliver effective presentations on various audit and information security related matters to Audit senior management and relevant stakeholder across the Bank as a means to demonstrate expertise.
  • Identify and advise Audit teams on the use of data analytics and other advanced techniques and tools in order to improve efficiency and effectiveness of audit assessments.
  • Establish and maintain solid relationship with audit clients to serve a catalyst of positive change and improvement of information and cyber security risk management.


Functional Competencies

  • 7 years of information and cyber security experience.
  • Excellent written and verbal communication skills.
  • Experience in the assessment of threats and risks over IT processes and assets.
  • Knowledge and experience with security assessment tools (exploit tools, vulnerability assessment) and Security Operations Centre software (IDS, IPS, SIEM, etc).
  • Knowledgeable in areas such as network security architecture, penetration testing, Red Team  testing, vulnerability assessments, Data Loss Prevention, web application security, secure coding assessment, cloud security, DDoS protection, encryption, and malware protection.
  • Working knowledge of primary Bank business areas (e.g. retail banking, wealth management) would be an asset.



  • Bachelor's degree in Information Technology, Computer Science or equivalent required.
  • One or more of the following certifications: CISA, CISM, CISSP, GCIA, CEH, OSCP, OSCE is required.


Miscellaneous Comments

  • Some travel may be required within Canada and international bank locations.
  • Fluency in Spanish would be an asset.

Location(s):  Canada : Ontario : Toronto

As Canada’s International Bank, we are a leader when it comes to inclusion. We are a diverse and global team, speaking more than 100 languages with backgrounds from more than 120 countries. We value the unique skills and experiences each individual brings to the bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly.  If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.



Job Segment: Audit, Corporate Security, Bank, Banking, Finance, Security