Full Job Description
The Senior Manager, GRC Regulatory Assurance is responsible for providing tactical and operational leadership to ensure TMX Group’s assets are protected and that the organization maintains robust regulatory compliance. This role will drive the maturation of the regulatory assurance program, serving as a critical bridge between TMX Group of subsidiaries and the Information Security Office. You will manage a high-performing team tasked with maturing the information security program, ensuring alignment with global regulatory frameworks, and fostering a culture of risk-aware compliance across the enterprise.
Key Accountabilities
- Regulatory Oversight and Audit Management:
- Oversee activities to maintain regulatory compliance across TMX Group’s regulated entities (e.g., BOC, OSFI, AMF, and SWIFT).
- Perform mapping and control testing of regulatory expectations and principles to control requirements to validate compliance coverage.
- Collaborate with internal stakeholders and Legal to manage regulatory inquiries, audit examinations, and the development of formal responses.
- Track and report on remediation of findings from internal and external audits to ensure timely closure.
- GRC Program Strategy and Maturing:
- Define and maintain the overarching cybersecurity strategy and policy framework lifecycle.
- Manage the continuous improvement of the GRC program, ensuring alignment with industry standards such as NIST, ISO 27001, and ITIL.
- Oversee the refresh of technical security standards and policies to address emerging threats and cloud-native requirements.
- Develop, manage, and enhance GRC risk management tooling capabilities.
- Governance and Reporting:
- Establish and track metrics (KPIs/KRIs) to monitor the effectiveness of the Information Security GRC program.
- Provide monthly and quarterly reporting on the status of regulatory compliance, risk registers, and remediation efforts for executive leadership, CISO, RMC, and Board.
- TPRM Supply Chain Cybersecurity:
- Perform vendor products and services security assessments. Provide purchase and merger and acquisitions advice to CISO, ERM, Procurement, and Legal.
- Team Leadership and Development:
- Lead, mentor, and manage a team of security advisors and analysts.
- Ensure that team members have established SMART objectives aligned with ITSS and overall TMX goals.
- Foster a culture of "Client-Centricity," courage, and trust, promoting proactive engagement with business units.
- Stakeholder Engagement:
- Develop strong working relationships within the Information Security Office, Enterprise Risk Management (ERM), ITSS Architecture, to ensure seamless execution of risk management initiatives.
- Collaborate with the business units to integrate security into business continuity and operational processes.
Skills and Experience
- Education: University undergraduate degree in Computer Science, Engineering, or a related field.
- Experience: 10+ years of information technology experience, with a minimum of 7 years specifically in information security, risk, or regulatory compliance.
- Leadership: 5+ years of people management/leadership experience with a proven track record of developing high-performing teams.
- Regulatory Knowledge: Proficiency in interpreting and applying regulatory frameworks (e.g., BOC, OSFI, AMF, and SWIFT) within a financial market infrastructure context.
- Technical Proficiency: Strong understanding of cybersecurity governance, policy frameworks, and risk assessment methodologies (e.g., TRAs).
- Certifications: CISSP is required. CISA, CISM, or ISO 27001 Lead Auditor certifications are considered significant assets.
- Soft Skills: Proven track record as a business partner who can translate complex technical risk into actionable business language for non-technical stakeholders.
Salary Range: $125,000 - $145,000/year CAD. Please note that the salary range included is a guideline only. The salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience.
The recruiting efforts for this role are intended to fill a vacant position.