Bank of Montreal

Managing Director - Cybersecurity & Core Technology Audit

Bank of Montreal • $200K — $260K *
Finance & Insurance
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 15+ years in Internal Audit, Technology Audit, Cybersecurity, or Risk Management in large financial institutions
  • Senior leadership experience in complex technology domains including cybersecurity and operational resilience
  • Proven ability to lead integrated audit programs across multiple risk domains
  • Strong experience working with regulators and executive stakeholders
  • Demonstrated success in audit transformation involving analytics and automation
  • Experience building and managing geographically dispersed teams
  • Deep understanding of technology risk management, particularly with emerging risks like AI and quantum computing
  • Professional certifications in information systems audit or cybersecurity required (e.g., CISA, CISSP)

Responsibilities

  • Define and implement a risk-based audit strategy for Cybersecurity and Core Technology
  • Lead risk assessments and audit coverage strategy development
  • Enhance audit capabilities through specialized workforce planning and methodology improvements
  • Maintain comprehensive audit coverage across high-risk technology domains
  • Serve as primary audit liaison for technology executives and regulatory bodies
  • Ensure standardized, high-quality audit delivery with a focus on continuous improvement
  • Leverage analytics and AI in audit processes for proactive risk insights
  • Promote a strong risk culture within the Bank and enforce accountability in risk management

Benefits

  • Health insurance
  • Tuition reimbursement
  • Accident and life insurance
  • Retirement savings plans
  • Performance-based incentives and discretionary bonuses
Full Job Description

Application Deadline:

10/30/2026

Address:

320 S Canal Street

Job Family Group:

Audit, Risk & Compliance

Provides strategic leadership and enterprise-wide oversight of audit coverage across Cybersecurity and Core Technology, ensuring robust, risk-based assurance aligned to the Bank’s evolving technology landscape. The role establishes the audit strategy, testing priorities, and integrated coverage approach for high-risk technology domains, including cybersecurity resilience, technology infrastructure, cloud platforms, engineering practices, software development, service management, technology operations, platform support, operational resilience, physical security, and technology-enabled transformation programs. Operating within the Technology & Operations Audit mandate, the role identifies horizontal audit touchpoints, dependencies, and control considerations across the broader Corporate Audit ecosystem, partnering with LOB and Chief Auditor groups to deliver coordinated coverage.

  • Define and execute a risk-based, integrated audit strategy across Cybersecurity and Core Technology that focuses on both current and future focused emerging risk reviews
  • Lead ongoing risk assessment activities and development of audit coverage strategies to provide independent assurance over Cybersecurity and Core Technology risks, control effectiveness, and risk management practices.
  • Strengthen audit capabilities across Cybersecurity and Core Technology through workforce planning, technical specialization, succession management, methodology enhancement, and targeted capability development in cyber, cloud, infrastructure, engineering, and technology operations risk domains.
  • Maintain integrated, risk-based audit coverage across cybersecurity, engineering, technology operations, service management, platform support, cloud, infrastructure, software delivery, operational resilience, and third-party ecosystems, with a focus on identifying systemic risks, enterprise-wide control dependencies, and emerging technology risks. Proactively build partnerships across business, technology, control, and audit teams to support effective risk management, issue remediation, and sustainable control environment
  • Serve as the senior audit relationship lead for technology executives, including CISOs, engineering, infrastructure, and operations leaders, while maintaining strategic partnerships with regulators, control functions, and other key stakeholders .Lead audit support for regulatory examinations, horizontal reviews, regulatory commitments, and remediation activities related to Cybersecurity and Core Technology. Ensure audit insights, thematic observations, and risk perspectives are communicated effectively to executive management and the Board. Provide strategic leadership and performance oversight of Directors responsible for portfolio execution and identify opportunities to strengthen ownership and risk alignment while expanding control-level, domain-specific coverage
  • Ensure quality, consistency, and timeliness of audit delivery through standardized methodologies, reusable testing approaches, and continuous improvement practices. Establish proactive audit engagement and continuous monitoring across portfolios to enable real-time reprioritization and end-to-end risk visibility
  • Drive adoption of analytics, continuous assurance, and AI-enabled auditing (e.g., AI-enabled threats, advanced cyber risks) for better forward-looking risk insights
  • Deliver thematic insights, root-cause analysis, and enterprise-wide risk perspectives across technology domains.
  • Within the mandate of this role, promotes and supports the Bank’s risk culture including ensuring employees understand their accountabilities for risk-taking activities, promoting an environment of open communication and effective challenge, and establishing the tone from the top through leading by example.
  • Takes measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.

People / Culture Leadership Language:

  • Role models driving simplicity and productivity enhancements for optimization across groups, driving continuous improvement on key measures.
  • Activates our winning culture, aligned with Purpose. Ignites engagement by aligning our culture to our strategy and fueling exceptional execution.
  • Fosters an inclusive environment for all employees by eliminating barriers to inclusion.
  • Develops leaders, plans for succession, and fosters a high-performance culture.
  • Drives top talent acquisition and retention, developing organizational capabilities to drive competitive advantage.
  • Leads and mentors a team with diverse risk and business experience, skills, and orientation.
  • Leads, promotes, and reinforces the Bank’s Ambition; personally, role models One Bank leadership; drives sustainable improvements in customer loyalty and business growth; adheres and supports enterprise customer experience and brand standards.

Qualifications:

  • 15+ years of experience in Internal Audit, Technology Audit, Cybersecurity, or Risk Management within large financial institutions
  • Senior leadership experience overseeing complex technology domains, including cybersecurity, infrastructure, cloud, engineering, technology operations, and operational resilience.
  • Deep expertise in cybersecurity, technology infrastructure, engineering practices, service management, operational resilience, and technology risk management, with proven ability to lead integrated audit programs across multiple risk domains. Proven ability to lead integrated audit programs across multiple risk domains
  • Strong experience engaging regulators and executive stakeholders (CIO, CISO, regulators)
  • Demonstrated track record of driving audit transformation (analytics, automation, continuous auditing)
  • Experience leading geographically dispersed teams, building and scaling high-performing teams, including capability uplift in specialized domains
  • Strong understanding technology risk management and emerging risks, including artificial intelligence, AI-enabled threats, quantum computing implications, technology transformation, evolving regulatory expectations, and advanced supply chain dependencies.
  • One or more professional certifications in information systems audit, cybersecurity, or technology risk management required (e.g., CISA, CISSP).
  • Additional certifications in cloud platform/security, cybersecurity, network security, service management, or resilience preferred (e.g., CISM, CCSP, CCSK, GIAC, ITIL).
  • undefined

Please note this role will be targeting a base salary range of $200k-$260k USD per annum

Salary:

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Bank of Montreal

The Bank of Montreal is a Canadian multinational investment bank and financial services company. It provides a wide range of personal and commercial banking, wealth management, and investment banking products and services. The bank had revenues of CAD 23.6 billion in 2020.
Learn more about Bank of Montreal
Size
45,454 employees
Market Cap
$60.9 billion
Industry
Founded
1817
5 Year Trend
+9.1%
NASDAQ

Similar Jobs

More Jobs at Bank of Montreal

More Finance & Insurance Jobs

Find similar Managing Director - Cybersecurity & Core Technology Audit jobs: