Scotiabank

Senior Manager, Cyber Security and IT Risk

Scotiabank$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • University degree in relevant field such as Computer Science or Business
  • Preferred cybersecurity or risk management certifications (e.g., CISSP, CISM)
  • 7+ years of experience in technology risk management or related fields
  • 5+ years in regulatory remediation or technology audit
  • Strong knowledge of regulatory frameworks like NIST and ISO
  • Expertise in assessing audit findings and developing management responses
  • Experience in designing or enhancing risk governance processes

Responsibilities

  • Champion a customer-focused culture in risk management activities
  • Manage relationships with various stakeholders including Internal Audit and Compliance
  • Provide independent challenge to audit observations and risk issues
  • Support development of management responses and remediation strategies
  • Coordinate issue management and remediation efforts across teams
  • Prepare quality assurance reviews of remediation packages before submission
  • Monitor and report on risk portfolios, overdue actions, and emerging trends

Benefits

  • Inclusive and collaborative work environment
  • Competitive rewards including performance bonus and share ownership program
  • Pension plan matching
  • Health benefits from day one
  • Access to career development opportunities
Full Job Description
Requisition ID: 270013

Contributes to the overall success of Cyber & IT Risk Management, Global Risk Management (GRM) globally ensuring specific individual goals, plans, and initiatives are executed/delivered in support of the team's business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations, internal policies and procedures.

Collaborates with Technology and Operations teams, Enterprise Technology Risk Management, Regulatory Relations, Internal Audit, Compliance, and business-aligned risk stakeholders to support the effective management of technology and cyber risk issues, regulatory commitments, audit activities, remediation efforts, and governance processes. As part of the Second Line of Defense, the Cybersecurity and IT Risk Management team provides independent oversight and challenge and assists in the development and maintenance of methodologies, policies, standards, processes, and tools supporting the Enterprise Cyber and Technology Risk Management Framework.

The role focuses on audit and regulatory support, issue remediation governance, closure package quality assurance, policy and standards governance processes, management response development, and executive communications. The role also provides independent challenge and risk perspectives on technology and cyber risk matters where warranted by risk exposure, audit observations, regulatory expectations, or control weaknesses.

Is this role right for you? In this role, you will:
  • Champions a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  • Audit and Stakeholder Engagement: Manage constructive working relationships with Internal Audit, external assurance providers, Regulatory Relations, Technology, Operations, Compliance, and risk stakeholders. Support audit and regulatory activities through preparation of risk perspectives, briefing materials, evidence coordination, management responses, and issue updates.
  • Independent Challenge of Audit and Risk Issues: Review audit observations, issue statements, management responses, remediation plans, closure criteria, and supporting evidence. Provide independent challenge and recommendations to ensure risk positions are balanced, accurate, supportable, and aligned with the underlying risk exposure.
  • Management Response Development and Issue Negotiation: Support the development and review of management responses, action plans, remediation strategies, and closure narratives. Challenge issue wording, remediation approaches, and closure assumptions, as appropriate, to ensure clarity, accuracy, and defensibility.
  • Remediation Governance and Coordination: Coordinate remediation activities, issue management efforts, and closure submissions primarily across the Cyber & IT Risk Management organization. Monitor progress against committed actions, facilitate alignment across risk teams, identify dependencies, and escalate delivery risks as appropriate.
  • Cross-Functional Issue Coordination: Support engagement with First Line (1A), Technology Risk Officer (1B), and other stakeholders on an exception basis where issue remediation requires broader coordination, governance alignment, evidence aggregation, or cross-functional execution.
  • Closure Package Preparation and Quality Assurance: Perform quality assurance reviews of remediation closure packages to ensure evidence is complete, relevant, current, and appropriately mapped to regulatory or audit recommendations, management action plans, regulatory commitments, and closure narratives.
  • Evidence Traceability and Audit Readiness: Validate that closure submissions clearly demonstrate remediation activities, control improvements, evidence traceability, and issue resolution outcomes. Challenge unsupported assertions and identify documentation or evidence gaps prior to submission.
  • Process Design and Continuous Improvement: Design, implement, and continuously improve remediation governance processes, quality assurance procedures, issue management routines, evidence standards, stakeholder engagement processes, and reporting mechanisms supporting Cyber & IT Risk Management activities.
  • Policy, Standard Governance: Coordinate governance processes for the challenge of supporting technology policies and standards. Facilitate stakeholder engagement, review cycles, governance approvals, and tracking of required updates and QA of challenge deliverables. Provide independent challenge and recommendations on policies, standards when required.
  • Reporting and Executive Communications: Prepare clear, concise, and evidence-based reporting for senior management, risk committees, audit meetings, governance forums, and remediation oversight activities. Develop independent risk opinions, challenge memoranda, management presentations, briefing notes, and issue status reporting.
  • Technology Resilience and Operational Process Oversight: Assess the design and operating effectiveness of key technology management processes including resiliency management, availability management, change management, configuration management, release management, incident management, problem management, monitoring, observability, and recovery management.
  • Risk Monitoring and Thematic Analysis: Monitor issue portfolios, remediation progress, overdue actions, recurring control weaknesses, and emerging risk themes. Identify trends and systemic concerns requiring escalation, enhanced challenge, or management attention.
  • Emerging Risk Awareness: Maintain awareness of evolving technology and cyber risks, emerging regulatory expectations, audit focus areas, industry developments, and operational resilience requirements that may impact the Bank's risk profile.
  • Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champions a high-performance environment and contributes to an inclusive work environment.


Do you have the skills that will enable you to succeed? We'd love to work with you if you have:
  • University degree, preferably in Computer Science, Computer Engineering, Information Systems, Business, Risk Management, or a related field
  • Cybersecurity, technology, audit, regulatory, or risk management certification preferred (e.g., CISSP, CISM, CRISC, CISA, CGEIT, CCSP, ITIL, COBIT, ISO 27001, or equivalent experience)
  • Strong understanding of technology and cyber security regulatory frameworks and guidance (e.g., OSFI B-13, DORA, FFIEC, NIST Cybersecurity Framework 2.0, COBIT, ITIL, ISO 27001, ISO 22301, ISO 27031, and related industry practices)
  • A minimum of 7 years' experience in technology risk management, cyber risk, technology audit, regulatory engagement, remediation governance, information security, technology operations, operational resilience, or related disciplines preferably in a financial institution.
  • 5+ years of experience or equivalent expertise in technology risk management, technology audit, regulatory remediation, control assurance, information security oversight, or an equivalent independent risk management function
  • Strong expertise in regulatory and audit engagement, including issue assessment, management response development, scope negotiation, remediation planning, evidence evaluation, and closure package preparation.
  • Experience assessing and challenging findings, issue wording, root cause, severity, management action plans, due dates, closure criteria, and evidence sufficiency.
  • Strong understanding of technology and cyber risk domains including IAM/PAM, data protection, cloud, infrastructure, technology resilience, incident/problem management, change management, asset management, third-party technology risk, and control governance.
  • Experience performing independent reviews of technology controls, remediation plans, policies, standards, procedures, control requirements, and closure submissions.
  • Experience designing or improving governance processes, QA standards, issue management routines, reporting mechanisms, escalation protocols, evidence standards, and remediation oversight practices.
  • Strong knowledge of enterprise technology management processes including incident management, problem management, change management, configuration management, monitoring, service management, access management, and control lifecycle management.
  • Experience developing risk opinions, challenge memoranda, thematic reviews, executive reporting, audit/regulatory briefing materials, governance presentations, and remediation closure narratives.


What's in it for you?
  • An inclusive & collaborative working environment that encourages creativity, curiosity, and celebrates success!
  • We offer a competitive rewards package: Performance bonus, Employee Share Ownership Program, and Pension Plan Matching, Health Benefits from day one!
  • Your career matters! You will have access to career development and progression opportunities.


Location(s): Canada : Ontario : Toronto

About Scotiabank

Scotiabankers are committed to helping individuals, companies, and communities to thrive in a changing world. From personal and business banking, brokerage, and insurance, to private wealth, and the most sophisticated commercial, corporate and institutional services, they serve the diverse needs of some 21 million customers in more than 55 countries. Founded in 1832 in Halifax, Nova Scotia, their growth has always been fuelled by the success of their customers and their longevity secured by an unshakable commitment to carefully and expertly managing risk and capital. That focus on doing what's right for customers—short- andlong-term—has made us a global financial services leader. Headquartered in Canada, they are over 86, 000 Scotiabankers strong. Each of us are committed to being the best at understanding their customers' needs and all of us working together to deliver practical advice and relevant solutions that help their customers become financially better off.

Scotiabank Careers

Join Scotiabank, a premier financial institution, and become part of a diverse and inclusive team that’s leading the way in global banking. At Scotiabank, we offer more than just job opportunities; we provide a platform for professional growth and innovation in the financial services industry.

Work You’ll Do

At Scotiabank, we’re not just filling positions; we’re cultivating leaders. Dive into a workplace where diversity training and leadership development shape the path to your future. Our commitment to professional growth is evident in our robust training programs and continuous learning opportunities that foster innovation and strategic thinking.

Explore a World of Opportunities

Whether you’re looking for a full-time position, an internship, or a leadership role, Scotiabank has a spectrum of opportunities to fit your career ambitions. Our team is composed of individuals who bring a wealth of skills and perspectives to our company, driving us forward with their creativity and strategic insights.

Innovative Work Environment

Scotiabank’s culture is one of collaboration and respect, where each team member’s contribution is valued. Engage in meaningful work that challenges you to leverage your skills and push the boundaries of what’s possible in the banking sector. Our innovative projects not only support the growth of the company but also ensure our position as a leader in the industry.

Benefits and Growth

Choosing a career at Scotiabank means opting for a life of growth and opportunity. Our employees enjoy competitive benefits, including comprehensive health coverage, retirement plans, and flexible working conditions, all designed to support your career and personal life. We believe in nurturing our team’s potential by providing them with the tools they need to succeed both professionally and personally.

Join Our Team

Ready to take the next step in your career? Explore the job opportunities at Scotiabank by searching our open positions that match your skills and interests. We are continuously hiring and looking for passionate, curious, and solution-driven team players.

Networking and Professional Development

Stay connected and advance your career through Scotiabank’s extensive networking opportunities. Participate in events that connect you with other professionals and leaders within the industry. Our career resources will help you prepare your resume, ace your interviews, and land the job that best suits your career goals.

Stay Ahead

Keep up to date with the latest in career tips, industry insights, and company news—all from the people who work here at Scotiabank. Personalize your experience by subscribing to job alert emails tailored to your preferences and be the first to know about new openings and exciting developments. Join Scotiabank and be part of a team that values integrity, respect, and accountability. Discover how your career can flourish in an environment committed to your professional development and personal growth.
Learn more about Scotiabank
Size
90,619 employees
Market Cap
$57.5 billion
Industry
5 Year Trend
+7%
NASDAQ

Similar Jobs

More Jobs at Scotiabank

More Information Technology Jobs

Find similar Senior Manager, Cyber Security and IT Risk jobs: