Please be advised that our Careers site will be unavailable from November 28 at 12am ET to November 29 12am ET for scheduled system maintenance.

Title:  Senior Manager, Cyber Security and IT Risk

 

 

 

Requisition ID: 270013 

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

 

Contributes to the overall success of Cyber & IT Risk Management, Global Risk Management (GRM) globally ensuring specific individual goals, plans, and initiatives are executed/delivered in support of the team's business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations, internal policies and procedures. 

 

Collaborates with Technology and Operations teams, Enterprise Technology Risk Management, Regulatory Relations, Internal Audit, Compliance, and business-aligned risk stakeholders to support the effective management of technology and cyber risk issues, regulatory commitments, audit activities, remediation efforts, and governance processes. As part of the Second Line of Defense, the Cybersecurity and IT Risk Management team provides independent oversight and challenge and assists in the development and maintenance of methodologies, policies, standards, processes, and tools supporting the Enterprise Cyber and Technology Risk Management Framework. 

 

The role focuses on audit and regulatory support, issue remediation governance, closure package quality assurance, policy and standards governance processes, management response development, and executive communications. The role also provides independent challenge and risk perspectives on technology and cyber risk matters where warranted by risk exposure, audit observations, regulatory expectations, or control weaknesses. 

 


Is this role right for you? In this role, you will:  

  • Champions a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  • Audit and Stakeholder Engagement: Manage constructive working relationships with Internal Audit, external assurance providers, Regulatory Relations, Technology, Operations, Compliance, and risk stakeholders. Support audit and regulatory activities through preparation of risk perspectives, briefing materials, evidence coordination, management responses, and issue updates.
  • Independent Challenge of Audit and Risk Issues: Review audit observations, issue statements, management responses, remediation plans, closure criteria, and supporting evidence. Provide independent challenge and recommendations to ensure risk positions are balanced, accurate, supportable, and aligned with the underlying risk exposure.
  • Management Response Development and Issue Negotiation: Support the development and review of management responses, action plans, remediation strategies, and closure narratives. Challenge issue wording, remediation approaches, and closure assumptions, as appropriate, to ensure clarity, accuracy, and defensibility.
  • Remediation Governance and Coordination: Coordinate remediation activities, issue management efforts, and closure submissions primarily across the Cyber & IT Risk Management organization. Monitor progress against committed actions, facilitate alignment across risk teams, identify dependencies, and escalate delivery risks as appropriate.
  • Cross-Functional Issue Coordination: Support engagement with First Line (1A), Technology Risk Officer (1B), and other stakeholders on an exception basis where issue remediation requires broader coordination, governance alignment, evidence aggregation, or cross-functional execution.
  • Closure Package Preparation and Quality Assurance: Perform quality assurance reviews of remediation closure packages to ensure evidence is complete, relevant, current, and appropriately mapped to regulatory or audit recommendations, management action plans, regulatory commitments, and closure narratives.
  • Evidence Traceability and Audit Readiness: Validate that closure submissions clearly demonstrate remediation activities, control improvements, evidence traceability, and issue resolution outcomes. Challenge unsupported assertions and identify documentation or evidence gaps prior to submission.
  • Process Design and Continuous Improvement: Design, implement, and continuously improve remediation governance processes, quality assurance procedures, issue management routines, evidence standards, stakeholder engagement processes, and reporting mechanisms supporting Cyber & IT Risk Management activities.
  • Policy, Standard Governance: Coordinate governance processes for the challenge of supporting technology policies and standards. Facilitate stakeholder engagement, review cycles, governance approvals, and tracking of required updates and QA of challenge deliverables. Provide independent challenge and recommendations on policies, standards when required.
  • Reporting and Executive Communications: Prepare clear, concise, and evidence-based reporting for senior management, risk committees, audit meetings, governance forums, and remediation oversight activities. Develop independent risk opinions, challenge memoranda, management presentations, briefing notes, and issue status reporting.
  • Technology Resilience and Operational Process Oversight: Assess the design and operating effectiveness of key technology management processes including resiliency management, availability management, change management, configuration management, release management, incident management, problem management, monitoring, observability, and recovery management.
  • Risk Monitoring and Thematic Analysis: Monitor issue portfolios, remediation progress, overdue actions, recurring control weaknesses, and emerging risk themes. Identify trends and systemic concerns requiring escalation, enhanced challenge, or management attention.
  • Emerging Risk Awareness: Maintain awareness of evolving technology and cyber risks, emerging regulatory expectations, audit focus areas, industry developments, and operational resilience requirements that may impact the Bank’s risk profile.
  • Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champions a high-performance environment and contributes to an inclusive work environment. 

 

Do you have the skills that will enable you to succeed? We’d love to work with you if you have:   

  • University degree, preferably in Computer Science, Computer Engineering, Information Systems, Business, Risk Management, or a related field
  • Cybersecurity, technology, audit, regulatory, or risk management certification preferred (e.g., CISSP, CISM, CRISC, CISA, CGEIT, CCSP, ITIL, COBIT, ISO 27001, or equivalent experience)
  • Strong understanding of technology and cyber security regulatory frameworks and guidance (e.g., OSFI B-13, DORA, FFIEC, NIST Cybersecurity Framework 2.0, COBIT, ITIL, ISO 27001, ISO 22301, ISO 27031, and related industry practices)
  • A minimum of 7 years’ experience in technology risk management, cyber risk, technology audit, regulatory engagement, remediation governance, information security, technology operations, operational resilience, or related disciplines preferably in a financial institution.
  • 5+ years of experience or equivalent expertise in technology risk management, technology audit, regulatory remediation, control assurance, information security oversight, or an equivalent independent risk management function
  • Strong expertise in regulatory and audit engagement, including issue assessment, management response development, scope negotiation, remediation planning, evidence evaluation, and closure package preparation.
  • Experience assessing and challenging findings, issue wording, root cause, severity, management action plans, due dates, closure criteria, and evidence sufficiency.
  • Strong understanding of technology and cyber risk domains including IAM/PAM, data protection, cloud, infrastructure, technology resilience, incident/problem management, change management, asset management, third-party technology risk, and control governance.
  • Experience performing independent reviews of technology controls, remediation plans, policies, standards, procedures, control requirements, and closure submissions.
  • Experience designing or improving governance processes, QA standards, issue management routines, reporting mechanisms, escalation protocols, evidence standards, and remediation oversight practices.
  • Strong knowledge of enterprise technology management processes including incident management, problem management, change management, configuration management, monitoring, service management, access management, and control lifecycle management.
  • Experience developing risk opinions, challenge memoranda, thematic reviews, executive reporting, audit/regulatory briefing materials, governance presentations, and remediation closure narratives. 

 

What’s in it for you?

  • An inclusive & collaborative working environment that encourages creativity, curiosity, and celebrates success!
  • We offer a competitive rewards package: Performance bonus, Employee Share Ownership Program, and Pension Plan Matching, Health Benefits from day one!
  • Your career matters! You will have access to career development and progression opportunities.

 

Location(s):  Canada : Ontario : Toronto 

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.  

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our  Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.


Job Segment: Risk Management, Quality Assurance, QA, Cyber Security, Compliance, Finance, Quality, Technology, Security, Legal