Scotiabank

Manager, Cyber Security & IT Risk

Scotiabank$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity, technology risk, information security, or related fields, ideally in financial services.
  • Experience with cybersecurity assessments, thematic reviews, and independent risk challenge activities.
  • Strong grasp of cybersecurity risk management practices, including identity access management and incident response.
  • Skilled in assessing control effectiveness and communicating risks to stakeholders.
  • Proficient in issue management, including identification, root cause analysis, and remediation oversight.
  • Ability to analyze risk indicators and report on cybersecurity insights effectively.
  • Excellent written and verbal communication skills with stakeholder influence.

Responsibilities

  • Conduct risk-based cybersecurity assessments and thematic reviews.
  • Independently evaluate First Line of Defense effectiveness in identifying and remediating risks.
  • Challenge risk management processes and control environments with objective recommendations.
  • Prepare monthly and quarterly cyber risk reports for governance committees.
  • Analyze and provide insights on key risk indicators and emerging threats.
  • Escalate significant risks and control gaps through proper channels.
  • Support oversight of cybersecurity risk issues throughout their lifecycle.

Benefits

  • Opportunity to join a collaborative and forward-thinking company.
  • Diverse opportunities for professional development.
  • Internal development programs to aid skill enhancement.
  • Comprehensive benefits package offering competitive rewards.
  • Commitment to community impact for employees and clients.
  • Inclusive environment promoting creativity, curiosity, and success.
Full Job Description
Manager, Cyber Security and IT Risk will contribute to the overall success of Cyber Security and IT Risk Management within Global Risk Management by supporting independent Second Line of Defense oversight, review, and challenge of cybersecurity risk management activities across the Bank. The role is focused on conducting cybersecurity risk assessments and thematic reviews, challenging First Line of Defense risk identification and remediation activities, monitoring key cyber risk indicators, supporting issue management oversight, and preparing concise risk reporting for senior management and governance committees.

As part of the Second Line of Defense, the role provides objective challenge and advice to First Line teams while maintaining independence from control ownership and execution. The role helps assess whether IT and cyber risks are appropriately identified, measured, monitored, reported, and remediated in alignment with the Bank's risk appetite, internal standards, regulatory expectations, and the Cyber and IT Risk Management Framework.

Is this role right for you? In this role, you will:

  • Conduct risk-based cybersecurity assessments, thematic reviews, and targeted challenge activities across key cybersecurity domains.
  • Independently assess whether cyber risks are appropriately identified, measured, monitored, reported, and remediated by the First Line of Defense.
  • Evaluate the effectiveness of risk management processes, control environments, remediation activities, and governance practices, and provide objective challenge, recommendations, and escalation where material risks or control weaknesses exist.
  • Support monthly and quarterly cyber and IT risk reporting for senior management and risk governance committees.
  • Analyze and challenge KRIs, control metrics, issue trends, assessment results, emerging threats, and remediation progress to develop clear, concise, and decision-useful risk insights.
  • Escalate material risks, deteriorating trends, and persistent control gaps through appropriate governance channels.
  • Support Second Line oversight of cyber and IT risk issues throughout the issue lifecycle, including issue identification, severity assessment, root cause review, management action plan challenge, remediation progress monitoring, evidence review, and closure readiness assessment.
  • Provide challenge where remediation actions do not appear sufficient, timely, sustainable, or aligned to the underlying risk. This also includes IT and Cyber Risk Acceptance oversight.
  • Review and challenge the appropriateness, completeness, and effectiveness of cybersecurity standards, procedures, methodologies, and governance frameworks developed by the First Line of Defense.
  • Assess alignment with regulatory requirements, industry frameworks, emerging risks, and the Bank's cyber and IT risk management framework, and provide recommendations to address gaps or strengthen control expectations.
  • Contribute to the ongoing development and maturation of the Cyber Security and IT Risk Management function by enhancing challenge methodologies, assessment approaches, reporting capabilities, issue management processes, governance practices, and supporting tools.
  • Support the development of frameworks, procedures, templates, and guidance that strengthen the effectiveness, consistency, and scalability of Second Line oversight activities.


Do you have the skills that will enable you to succeed? We'd love to work with you if you have experience with:

  • Minimum 5 years of experience in cybersecurity, technology risk, information security, internal audit, risk advisory, or related disciplines, preferably within a financial services or highly regulated environment.
  • Experience conducting cybersecurity assessments, thematic reviews, control evaluations, or independent challenge activities across key cybersecurity domains.
  • Strong understanding of cybersecurity risk management practices and control frameworks, including areas such as identity and access management, vulnerability management, data protection, security monitoring, incident response, third-party risk, cloud security, and technology resilience.
  • Experience reviewing evidence, assessing control effectiveness, identifying control gaps, and communicating risk implications to business and technology stakeholders.
  • Experience supporting issue management and Risk acceptance processes, including issue identification, root cause analysis, remediation plan review, evidence assessment, and closure validation. Including Risk Acceptance adjudication and oversight.
  • Experience analyzing risk indicators, assessment results, issue trends, and emerging threats to generate meaningful risk insights and management reporting.
  • Ability to prepare concise, executive-level reporting and present cybersecurity risks, control weaknesses, and remediation concerns to senior stakeholders.
  • Experience reviewing cybersecurity standards, methodologies, procedures, or governance frameworks and assessing alignment with regulatory requirements and industry expectations.
  • Experience contributing to the enhancement of risk management methodologies, assessment frameworks, governance processes, reporting capabilities, or oversight practices.
  • Strong written and verbal communication skills with the ability to influence stakeholders and provide effective challenge while maintaining professional relationships.


What's in it for you?

  • The opportunity to join a forward-thinking company surrounded by a collaborative team of innovative thinkers.
  • A rewarding career path with diverse opportunities for professional development.
  • Internal development to support your growth and enhance your skills.
  • A competitive compensation and benefits package.
  • An organization committed to making a difference in our communities- for you and our customers.
  • We have an inclusive and collaborative working environment that encourages creativity, curiosity, and celebrates success!


Location(s): Canada : Ontario : Toronto

About Scotiabank

Scotiabankers are committed to helping individuals, companies, and communities to thrive in a changing world. From personal and business banking, brokerage, and insurance, to private wealth, and the most sophisticated commercial, corporate and institutional services, they serve the diverse needs of some 21 million customers in more than 55 countries. Founded in 1832 in Halifax, Nova Scotia, their growth has always been fuelled by the success of their customers and their longevity secured by an unshakable commitment to carefully and expertly managing risk and capital. That focus on doing what's right for customers—short- andlong-term—has made us a global financial services leader. Headquartered in Canada, they are over 86, 000 Scotiabankers strong. Each of us are committed to being the best at understanding their customers' needs and all of us working together to deliver practical advice and relevant solutions that help their customers become financially better off.

Scotiabank Careers

Join Scotiabank, a premier financial institution, and become part of a diverse and inclusive team that’s leading the way in global banking. At Scotiabank, we offer more than just job opportunities; we provide a platform for professional growth and innovation in the financial services industry.

Work You’ll Do

At Scotiabank, we’re not just filling positions; we’re cultivating leaders. Dive into a workplace where diversity training and leadership development shape the path to your future. Our commitment to professional growth is evident in our robust training programs and continuous learning opportunities that foster innovation and strategic thinking.

Explore a World of Opportunities

Whether you’re looking for a full-time position, an internship, or a leadership role, Scotiabank has a spectrum of opportunities to fit your career ambitions. Our team is composed of individuals who bring a wealth of skills and perspectives to our company, driving us forward with their creativity and strategic insights.

Innovative Work Environment

Scotiabank’s culture is one of collaboration and respect, where each team member’s contribution is valued. Engage in meaningful work that challenges you to leverage your skills and push the boundaries of what’s possible in the banking sector. Our innovative projects not only support the growth of the company but also ensure our position as a leader in the industry.

Benefits and Growth

Choosing a career at Scotiabank means opting for a life of growth and opportunity. Our employees enjoy competitive benefits, including comprehensive health coverage, retirement plans, and flexible working conditions, all designed to support your career and personal life. We believe in nurturing our team’s potential by providing them with the tools they need to succeed both professionally and personally.

Join Our Team

Ready to take the next step in your career? Explore the job opportunities at Scotiabank by searching our open positions that match your skills and interests. We are continuously hiring and looking for passionate, curious, and solution-driven team players.

Networking and Professional Development

Stay connected and advance your career through Scotiabank’s extensive networking opportunities. Participate in events that connect you with other professionals and leaders within the industry. Our career resources will help you prepare your resume, ace your interviews, and land the job that best suits your career goals.

Stay Ahead

Keep up to date with the latest in career tips, industry insights, and company news—all from the people who work here at Scotiabank. Personalize your experience by subscribing to job alert emails tailored to your preferences and be the first to know about new openings and exciting developments. Join Scotiabank and be part of a team that values integrity, respect, and accountability. Discover how your career can flourish in an environment committed to your professional development and personal growth.
Learn more about Scotiabank
Size
90,619 employees
Market Cap
$57.5 billion
Industry
5 Year Trend
+7%
NASDAQ

Similar Jobs

More Jobs at Scotiabank

More Information Technology Jobs

Find similar Manager, Cyber Security & IT Risk jobs: