Job DescriptionWhat is the opportunity?Reporting to the Director, Application Security, you will be responsible for overseeing the execution, compliance, and continuous improvement of RBC's enterprise-wide penetration testing program. You would ensure penetration tests are completed on schedule, manage vendor relationships, maintain regulatory compliance, and drive operational efficiency. You would also act as a critical liaison between external vendors, asset owners, risk teams, and senior leadership, while proactively addressing risks, escalations, and program evolution to align with industry standards and organizational growth.
What will you do:- Program Oversight: Manage the end-to-end execution of 250+ annual penetration tests, ensuring compliance with deadlines and regulatory requirements, while overseeing vendor performance and scoping.
- Stakeholder Reporting & Communication: Deliver bi-weekly status reports to senior management, highlighting program health, risks, and initiatives.
- Process & Control Management: Define, document, and maintain program processes, control frameworks, and evidence for audits, ensuring alignment with internal and external standards.
- Continuous Improvement: Drive program transformation to enhance efficiency, coverage, cost-effectiveness, and stakeholder experience, including integration of new subsidiaries.
- Risk & Relationship Management: Address escalations, proactively mitigate risks, and foster collaboration with vendors, asset owners, and risk/governance teams.
What do you need to succeed?Must have:- Cyber Security Program Management: 5+ years of experience in security testing, vulnerability management, or cybersecurity program management.
- Penetration testing: Experience in planning, executing, and overseeing penetration testing for internet-facing and internal applications.
- Regulatory & Control Frameworks: Expertise in maintaining compliance with regulatory requirements (e.g., NIST, ISO 27001) and managing control documentation/testing.
- Stakeholder & Vendor Management: Demonstrated ability to build relationships, manage escalations, and hold vendors accountable for deliverables.
- Process Documentation & Metrics: Strong skills in creating/maintaining process documentation and defining KPIs to measure program effectiveness.
- Risk Management & Reporting: Experience identifying, mitigating, and communicating risks to senior leadership, with a track record of driving operational improvements.
Nice to have: - Certifications in information security (e.g., CISSP, CCSP, CRISC, CIAM, ITIL)
- Previous work experience within the financial sector or other large enterprise industry.
- General knowledge of penetration testing methodologies, tools, and techniques, including web application penetration testing, mobile penetration testing and network penetration testing.
- Experience with agile methodologies and tools, such as Jira, for backlog management and sprint planning.
- PMP certification.
What's in it for you?- A comprehensive Total Rewards Program including bonuses, flexible benefits and competitive compensation.
- Leaders who support your development through coaching and managing opportunities.
- Opportunities to work with the best in the field.
- Ability to make a difference and lasting impact.
- Work in a dynamic, collaborative, progressive, and high-performing team.
- A world-class training program in financial services.
- Opportunities to do challenging work.
The expected salary range for this particular position is $130,000-$210,000, depending on your experience, skills, and registration status, market conditions and business needs.
You have the potential to earn more through RBC's discretionary variable compensation program which gives you an opportunity to increase your total compensation, provided the business meets its performance targets and you meet your individual goals.
RBC's compensation philosophy and principles recognize the importance of a highly qualified global workforce and plays a critical role in attracting, engaging and retaining talent that:
- Drives RBC's high-performance culture.
- Enables collective achievement of our strategic goals.
- Generates sustainable shareholder returns and above market shareholder value.
#LI-POST
Job SkillsApplication Security Testing, Collaboration, Communication, Decision Making, Infrastructure Penetration Testing, IT Security Management, Leadership, Penetration Testing, Program Management, Risk Management, Strategic Direction, Taking Initiative, Web Application Penetration Testing
Additional Job DetailsAddress:GOLDMAN SACHS TOWER, 30 HUDSON STREET:JERSEY CITY
City:Jersey City
Country:United States of America
Work hours/week:40
Employment Type:Full time
Platform:TECHNOLOGY AND OPERATIONS
Job Type:Regular
Pay Type:Salaried
Posted Date:2026-07-27
Application Deadline:2026-08-07
Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above