We9re looking for a
Director, IT & Operational Resiliency to join our
Risk team.
Job SummaryReporting to the SVP & Chief Risk Officer, the Director, Technology & Operational Resiliency is responsible for the oversight, development and continuous enhancement of the organization9s technology risk, cybersecurity risk, operational resilience and third-party risk management programs. The role provides independent challenge and oversight of technology, cybersecurity, business continuity, disaster recovery and critical third-party risks, ensuring alignment with regulatory expectations, risk appetite and strategic objectives.
Key Responsibilities- Provide independent oversight and challenge of technology and cybersecurity risks, including material systems, infrastructure, cloud services, data, architecture and critical technology dependencies.
- Monitor technology resilience and recovery capabilities, including disaster recovery testing, RTO/RPO performance, backup and restoration, and recoverability of critical systems.
- Challenge the adequacy of cyber resilience, incident response, recovery planning and remediation for material services and critical operations.
- Oversee implementation and ongoing compliance with OSFI expectations related to technology risk, cybersecurity risk, operational resilience and third-party risk management.
- Lead the continued development and enhancement of the Operational Risk Management & Resiliency Framework and related oversight practices.
- Coordinate the identification, mapping and maintenance of critical operations and their supporting people, processes, technology, data and third-party dependencies.
- Lead operational resilience scenario testing and assess the organization9s ability to remain within approved disruption tolerances.
- Oversee business continuity, disaster recovery and crisis management programs, including testing, lessons learned and remediation activities.
- Maintain and enhance operational risk and third-party risk programs, including RCSAs, process inventories, operational risk events, KRIs, due diligence, ongoing monitoring and contingency planning.
- Report to Senior Management, and Board and Board Committees (ad-hoc basis) on operational, technology, cyber and third-party risks, and translate complex issues into clear, actionable business insights.
Preferred Qualifications- 7+ years of experience in technology risk, cybersecurity risk, operational risk, operational resilience, business continuity, third-party risk management or a related discipline.
- Big 4 consulting Experience is preferred.
- Experience within a federally regulated financial institution or other regulated industry.
- Strong knowledge of OSFI Guidelines E-21, B-13 and B-10.
- Demonstrated leadership and people management experience.
Candidate Backgrounds of Interest- Technology Risk
- Cyber Risk
- IT Audit
- Operational Risk
- Business Continuity / Operational Resilience
- Third-Party Risk Management
This posting is intended to attract candidates with strong technology and cybersecurity risk fluency, combined with operational resilience and governance experience.
Regular in-office collaboration is an important part of how we work, learn, and succeed together, and we believe great work thrives through in-person connection. Our hybrid model is designed to bring teams together in a modern office environment where collaboration, mentorship, and creativity naturally flourish, while still providing flexibility for focused remote work. While schedules may vary by team and role, successful candidates should expect a consistent in-office presence as part of our hybrid approach.
We thank all applicants for their interest but only those selected for further consideration will be contacted.