JOB SUMMARY
The Information Risk Management Analyst III is responsible for managing IT risk through the identification, evaluation, integration, and documentation of risks and controls. This role involves risk analysis and research, risk program coordination, and consultation on risk mitigation plans. A primary focus is serving as the Group Functions Technology contact for business continuity and operational resilience requirements, empowering business and technology partners to effectively identify and manage their risks. The analyst will collaborate with teams to achieve business goals while safeguarding critical operations and services during disruptions, coordinate and facilitate business impact assessments and simulation exercises, and develop strategies and plans to ensure organizational continuity during emergencies. This involves working with process and technology owners to design and implement recovery documentation, advising on risk management, and providing training on resilience topics, as well as assessing disruption risks and developing mitigation strategies.
Key Responsibilities
• Serve as the Group Functions Technology contact for business continuity and operational resilience requirements.
• Empower business and technology partners to identify and manage their business continuity and operational resilience risks effectively.
• Collaborate with business and technology teams to achieve business goals while safeguarding our ability to deliver critical operations and services during disruptions.
• Coordinate and facilitate business impact assessments, business continuity tabletops and realistic simulation exercises.
• Development of strategies and plans to ensure the organization can continue running effectively in the event of an emergency.
• Work with process and technology owners to design and implement customized recovery documentation including, but not limited to, business continuity plans and relevant documents such as vendor exit plans and test/simulation reports.
• Advice on risk management and provides training and education on resilience topics.
• Assess the risks of disruption and develop strategies to reduce the impact of such an event.
• Provide advice and guidance on the leading practices for Business Continuity planning, review existing plans for their effectiveness, and make recommendations for improvements.
• Support L2 and L3 reviews of BCM program practices.
• Partner closely with business stakeholders to conduct Business Impact Assessments (BIA).
• Engage stakeholders to document comprehensive Business Continuity Plans (BCPs), ensuring all critical processes and recovery strategies are clearly defined.
• Organize and facilitate realistic simulation exercises and tests (e.g., OSFI-aligned scenarios) to validate the effectiveness of continuity plans.
• Collaborate with second and third line of defense partners, ensuring alignment with risk management, compliance, and audit requirements.
Required Qualifications
• At least 5 years of experience in Business Continuity, Operational Resilience, and Project Management from a large, complex organization.
• Strong personal computing skills (MS Office) and familiarity with BCM Planning tools and/or relational databases (e.g., Fusion Risk Management, Archer, PowerBI).
• Good understanding of Business Resilience tools and techniques.
• Good communication skills, including the ability to develop and deliver effective user education sessions and presentations to all interpersonal levels.
• Demonstrable ability to build relationships, engage, and influence others.
• Experience developing and implementing recovery documentation including, but not limited to, business continuity plans and relevant documents such as vendor exit plans and test/simulation reports.
• Experience in facilitating and developing simulation recovery exercises.
• Must-have skills: Business continuity/operation experience, Manage stakeholders, Strong Computer skills, Fusion and Archer, Leading simulation experience.
Preferred Qualifications
• University Degree
• Financial Services industry experience
• Strong "automation-first" mindset
• Good understanding of information technology concepts such as cloud computing, computing infrastructure is a plus
• Able to work independently when needed
Certifications
• Professional certification in BCM (ABCP, CBCP, MBCI, or MBCP) or working towards acquiring certification.