OMERS Administration Corporation

Senior Manager, Technology Risk & Controls

OMERS Administration Corporation$122K — $188K *
Enterprise Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in assurance, internal controls or audit practice, including methodology design, sampling and evidence testing.
  • Demonstrated experience designing control frameworks and mapping them to enterprise risk and regulatory obligations, with knowledge of frameworks like COBIT, ISO 27001, and NIST.
  • Experience running the full risk cycle: assessment, control evaluation, remediation validation, and residual risk acceptance.
  • Technical expertise across network, platform, security, and application domains to directly test technology controls.
  • Proven executive-level reporting skills, translating technology and audit findings into business terms.
  • People leadership experience, including coaching and performance management.
  • Demonstrated professional judgement and credibility to maintain independence in assessment roles.

Responsibilities

  • Own the assurance program for property technology, defining methodology, risk-based planning, and annual conclusions.
  • Manage the internal controls framework for property technology, encompassing control design standards and evidence requirements.
  • Oversee the annual evidence and attestation cycle from planning to submission.
  • Lead the risk cycle, including identifying findings and validating remediation efforts.
  • Provide technology assurance on transactions related to portfolio assets, ensuring risk-assessed transitions.
  • Develop and run the incident readiness program, crafting relevant scenarios.
  • Create metrics to identify control weaknesses and trends, aligning with organizational risk appetite.
  • Report to executives and committees, translating findings into actionable business insights.

Benefits

  • Flexible hybrid work guideline requiring 4 days in the office per week.
  • Participation in annual Incentive Awards through Short-term and Long-term Incentive plans.
  • Access to comprehensive group benefits and retirement plans.
Full Job Description
Role Summary:

Oxford owns and operates one of the world's best known real estate portfolios, and the technology inside those buildings is now core operating infrastructure. This role owns the independent assurance program over that technology. It is the objective check that controls are properly designed, working as intended, and evidenced to a standard Oxford can stand behind.

The role reports to the Director, Operational Technology and Cybersecurity, with a direct escalation route to Operational Risk and to the relevant risk or audit committee. This is a second line mandate. The operating teams own and run the controls; this role tests them, forms a conclusion and reports it. Assurance conclusions do not require sign off from the function being assessed.

You will lead a small assurance team and build a program that is still taking shape. Methodology, standards, cadence and reporting are yours to define, with executive and committee visibility from the start.

The role covers a global portfolio of properties across Canada, the United States, the United Kingdom, continental Europe, Singapore and Australia. It carries genuine independence, executive access and committee exposure, and you will build both the program and the team from the ground up.

You will be responsible for:

  • Owning the assurance program over property technology, covering methodology, risk-based planning, scope, sampling, testing, findings and the annual conclusion, and standing behind that conclusion even when it is unfavorable.
  • Owning the internal controls framework as it applies to property technology: control design standards, evidence requirements, testing expectations, and the mapping between the technology control set and Oxford's wider control obligations.
  • Running the annual evidence and attestation cycle end to end, including planning, evidence standards, testing, exceptions and observations, and the position submitted.
  • Leading the risk cycle: identifying findings, evaluating the controls behind them, recommending solutions, validating remediation, performing root cause analysis on control failures, and facilitating residual risk acceptance where remediation is not pursued.
  • Delivering technology assurance on transactions: assessing the technology and control position of assets entering the portfolio, assuring a secure and evidenced exit for those leaving it, and risk assessing significant technology initiatives before they reach the estate.
  • Owning the incident readiness exercise program, including scenario design, delivery, evaluation and carry forward actions, with scenarios drawn from the real incident and near miss record.
  • Building the metrics that surface control weakness, including control environment health, exception trends and remediation ageing, read against risk appetite, alongside recurring second line monitoring such as restricted access review.
  • Reporting to executives and committee, translating control and risk findings into business terms leaders can act on, and acting as the coordination point for internal and external audits.
  • Partnering across the three lines with Compliance, Enterprise Operational Risk and Internal Audit so the approach to technology risk stays consistent, and leading, coaching and developing the assurance team.
  • Decision authority You will set the assurance methodology, scope, sampling approach and testing standard, and decide what counts as sufficient evidence for a control. You also determine control ratings and findings, the attestation position submitted, exercise scope and evaluation criteria, the assurance requirements applied to acquisitions and dispositions, and the priorities of the program.


Required Skills & Experience

  • 8+ years in assurance, internal controls or audit practice, including methodology design, sampling and evidence testing.
  • Demonstrated experience designing control frameworks and mapping them to enterprise risk and regulatory obligations, with working knowledge of recognized frameworks such as COBIT, ISO 27001 and the NIST Cybersecurity Framework.
  • Experience running the full risk cycle: assessment, control evaluation, remediation validation and residual risk acceptance.
  • Enough technical depth across network, platform, security and application domains to test technology controls directly rather than rely on what is asserted.
  • Proven executive and committee-level reporting, with the ability to put technology and audit findings in business terms.
  • People leadership experience, including coaching and performance management.
  • The professional judgement and credibility to hold an independent position within the structure you assess, and to escalate when it is warranted.


Preferred Skills & Experience

  • A professional designation such as CPA, CIA, CISA, CISSP or equivalent.
  • Experience developing control metrics and measurement where none existed before.
  • Exposure to real estate, infrastructure or other multi-site operating environments, or to building technology and operational technology estates.
  • Experience assuring technology in a multi-jurisdictional portfolio.
  • Bachelor's degree or equivalent experience.


We believe that time together in the office is important for OMERS and Oxford, the strength of our employees, and the work we do for our pension members. In delivering on our pension promise, keeping us connected to our work and each other, our flexible hybrid work guideline requires teams to come in to the office 4 days per week.

This posting is for an existing vacancy.

The expected salary range for this position is $122,000.00 - $188,000.00 per year.

You may also be eligible to receive an annual Incentive Award pursuant to our Short-term Incentive plan and our Long-Term Incentive plan (if applicable), and to participate in our group benefits and retirement plans - details on these elements of compensation are included within OMERS & Oxford offer letters.

About OMERS Administration Corporation

OMERS Administration Corporation is a Canadian pension fund that manages investments for the Ontario Municipal Employees Retirement System (OMERS). OMERS is one of Canada's largest pension funds, with over 500,000 members and over CAD 100 billion in net assets. OMERS Administration Corporation manages a diversified portfolio of investments across various asset classes, including public equity, private equity, infrastructure, real estate, and fixed income. The company's mission is to provide secure and sustainable pensions to its members while generating returns that help fund their pensions. OMERS Administration Corporation is headquartered in Toronto, Canada.
Learn more about OMERS Administration Corporation
Size
2,700 employees
Industry

Similar Jobs

More Jobs at OMERS Administration Corporation

More Enterprise Technology Jobs

Find similar Senior Manager, Technology Risk & Controls jobs: