Bank of Montreal

Senior Manager, Information Security Risk

Bank of Montreal • $85K — $185K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in cybersecurity, technology risk, or related fields.
  • Postsecondary degree in relevant fields like Computer Science or Cybersecurity.
  • In-depth knowledge of cybersecurity governance and risk management.
  • Demonstrated technical expertise in areas such as security operations or cloud security.
  • Strong understanding of regulatory requirements relevant to cybersecurity.

Responsibilities

  • Serve as a senior risk advisor on cybersecurity and technology risks.
  • Develop independent views on cybersecurity risk across portfolios.
  • Provide strategic risk advice to senior leaders on technology initiatives.
  • Evaluate and recommend enhancements to cybersecurity governance frameworks.
  • Lead risk-based assessments and thematic reviews of cybersecurity risks.
  • Challenge significant cybersecurity issues and advise on management responses.
  • Monitor risk appetite measures and external threats to identify adverse trends.

Benefits

  • Health insurance coverage.
  • Tuition reimbursement for further education.
  • Accident and life insurance policies.
  • Retirement savings plans with company contributions.
  • Performance-based incentives and discretionary bonuses.
Full Job Description

Application Deadline:

10/11/2026

Address:

100 King Street West

Job Family Group:

Audit, Risk & Compliance

This role sits within the Technology and Operations risk area as part of Operational and Non-Financial Risk (ONFR). As BMO’s independent second line of defense (2LoD), ONFR oversees and challenges how operational and non-financial risks are managed across the Bank.

ONFR works with the first line of defense (1LoD) and other risk and control functions, applying risk expertise, informed judgment, and data-driven insight to support sound decisions. It maintains independent oversight and effective challenge to promote alignment with the Bank’s risk appetite and help protect the organization.


Role Overview

The Senior Manager, Cyber Risk Oversight and Governance provides independent oversight and effective challenge of cybersecurity and related technology risks. The role advises senior leaders on material exposures and complex matters, offering an objective perspective to support decisions consistent with BMO’s risk appetite.

Working across Cybersecurity, Technology, business lines, and risk and control functions, the Senior Manager assesses the Bank’s cybersecurity risk profile and provides strategic input on material initiatives, emerging technologies, significant issues, and evolving threats. The role leads risk-based oversight, translates complex technical matters into clear risk implications, and delivers practical recommendations to senior management and governance forums.

The ideal candidate is an experienced risk or technology professional who combines cybersecurity or broader technical expertise with strong judgment, clear communication, and the ability to provide constructive challenge collaboratively.


Key Accountabilities

  • Serve as a senior risk advisor, providing independent oversight, credible challenge, and actionable advice regarding cybersecurity and related technology risks, controls, strategies, and risk management practices.
  • Develop and communicate an independent view of the cybersecurity risk profile across assigned portfolios, including material initiatives, emerging risks, control weaknesses, risk concentrations, and areas of heightened exposure.
  • Provide strategic risk input and recommendations to senior leaders on business decisions, technology transformation, emerging technologies, third-party dependencies, and new capabilities with significant cybersecurity implications.
  • Evaluate the design and effectiveness of cybersecurity governance frameworks, policies, standards, methodologies, controls, and risk management practices, and recommend proportionate enhancements where appropriate.
  • Lead risk-based oversight activities, including independent risk assessments, thematic reviews, capability assessments, governance activities, and targeted evaluations of material or emerging risks.
  • Challenge significant cybersecurity issues, incidents, risk acceptances, control deficiencies, and remediation plans, and advise on appropriate escalation where the level of risk or management response is not aligned with established expectations.
  • Monitor and analyze risk appetite measures, risk indicators, control performance, issues, incidents, external threats, industry developments, and regulatory expectations to identify adverse trends and changes in risk exposure.
  • Translate complex cybersecurity and technical matters into concise, decision-useful reporting, analysis, and recommendations for senior management, governance committees, Board-level forums, auditors, regulators, and other stakeholders.
  • Act as a subject-matter expert and primary risk partner for assigned cybersecurity areas, using technical credibility, sound judgment, and constructive challenge to influence risk decisions.
  • Represent the second line during regulatory examinations, ongoing supervisory engagements, internal and external audits, governance forums, and other senior stakeholder discussions.
  • Build trusted relationships across Cybersecurity, Technology, business lines, and other risk and control functions while maintaining the independence and objectivity required of the second line.
  • Lead or contribute to cross-functional initiatives that strengthen cybersecurity risk governance, assessment, monitoring, reporting, and organizational risk awareness.
  • Promote consistent, transparent, and data-informed risk practices and contribute to the continued evolution of the risk management framework and oversight capabilities.

Qualifications

  • 7+ years of relevant experience in cybersecurity, technology, technology risk, operational risk, information security, audit, or a related discipline.
  • Postsecondary degree in Computer Science, Information Technology, Engineering, Cybersecurity, Business Administration, or a related field, or an equivalent combination of education and experience.
  • In-depth knowledge of cybersecurity and technology risk management practices, governance frameworks, risk appetite, control environments, issue management, and remediation governance.
  • Demonstrated technical expertise in one or more cybersecurity disciplines, such as security operations, vulnerability management, cloud security, identity and access management, or security architecture, is strongly preferred. Candidates with broader technical experience in areas such as enterprise architecture, engineering, infrastructure, cloud platforms, or software development will also be considered.
  • Ability to evaluate cybersecurity strategy, technical architectures, threats, vulnerabilities, control designs, and operational practices and translate them into clear risk and business implications.
  • In-depth knowledge of applicable cybersecurity regulatory requirements and supervisory expectations, including those established by the Office of the Superintendent of Financial Institutions (OSFI), the Office of the Comptroller of the Currency (OCC), and the Federal Reserve.
  • Experience supporting regulatory examinations, ongoing supervisory engagements, internal or external audits, or responses to regulatory findings is preferred.
  • Strong working knowledge of recognized cybersecurity and technology risk frameworks and guidance, including NIST, ISO, FFIEC, and other applicable industry standards.
  • Strong understanding of independent risk oversight, risk and control assessment, effective challenge, control testing or validation, risk acceptance, issue management, and remediation governance.
  • Experience leading or contributing to thematic reviews, independent assessments, capability assessments, or other significant risk-based oversight activities.
  • Demonstrated ability to provide constructive and credible challenge to senior technical and non-technical stakeholders while maintaining effective working relationships.
  • Strong analytical and problem-solving skills, including the ability to assess complex or ambiguous matters, evaluate incomplete or conflicting information, identify material risk implications, and develop practical recommendations.
  • Strong written and verbal communication skills, including the ability to prepare concise materials and communicate complex technical risk matters to executive, Board-level, governance, audit, and regulatory audiences.
  • Strong influencing, negotiation, advisory, and relationship-management skills, with demonstrated effectiveness across organizational, functional, and jurisdictional boundaries.
  • Ability to identify emerging technologies, threats, regulatory developments, and industry trends and assess their potential implications for the organization.
  • Ability to manage ambiguity, balance competing considerations, and exercise sound independent judgment in a rapidly evolving technology, threat, and regulatory environment.
  • Strong collaboration and leadership skills, with the ability to lead significant oversight initiatives and deliver results through cross-functional engagement.
  • Strong capability in data-informed analysis, risk aggregation, trend identification, risk reporting, and decision support.
  • Relevant cybersecurity or risk certifications, such as CISSP, CISM, CISA, GIAC, and CRISC, are preferred.

Salary:

$85,500.00 - $185,000.00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: 

About Bank of Montreal

The Bank of Montreal is a Canadian multinational investment bank and financial services company. It provides a wide range of personal and commercial banking, wealth management, and investment banking products and services. The bank had revenues of CAD 23.6 billion in 2020.
Learn more about Bank of Montreal
Size
45,454 employees
Market Cap
$60.9 billion
Industry
Founded
1817
5 Year Trend
+9.1%
NASDAQ

Similar Jobs

More Jobs at Bank of Montreal

More Information Technology Jobs

Find similar Senior Manager, Information Security Risk jobs: