-
Audit delivery: Lead SOC 2 Type II readiness and the annual audit cycle end to end, including the evidence plan, control owner coordination, sampling, auditor requests and report issuance.
-
Certification: Drive ISO/IEC 27001:2022 readiness and certification, covering ISMS scope, Statement of Applicability, risk treatment plan, internal audit programme, management review and nonconformity closure.
-
Framework assessment: Manage NIST CSF 2.0 current and target profile assessments, including externally performed assessments, and produce the gap driven remediation roadmap that follows.
-
Control framework: Build and maintain a single unified control set mapped across NIST CSF 2.0, ISO 27001 Annex A, SOC 2 Trust Services Criteria, OSFI B-13 and B-10, and CIRO expectations, so a control is tested once and reported many times.
-
Entity segregation: Maintain entity level control mapping across CIRO regulated and OSFI regulated entities, ensuring every control answer and finding is labelled to the correct regime.
-
Policy management: Own the cybersecurity policy and standards library, including drafting, annual review cycle, approval routing, version control and publication.
-
Risk management: Own the cybersecurity risk register end to end, including risk identification, likelihood and impact scoring, treatment decisions, residual risk and named owners with committed dates.
-
Exception handling: Run the risk acceptance and exception process, including expiry dates, re-review triggers and escalation of expired or repeatedly extended exceptions.
-
Audit delivery: Lead SOC 2 Type II readiness and the annual audit cycle end to end, including the evidence plan, control owner coordination, sampling, auditor requests and report issuance.
-
Certification: Drive ISO/IEC 27001:2022 readiness and certification, covering ISMS scope, Statement of Applicability, risk treatment plan, internal audit programme, management review and nonconformity closure.
-
Framework assessment: Manage NIST CSF 2.0 current and target profile assessments, including externally performed assessments, and produce the gap driven remediation roadmap that follows.
-
Control framework: Build and maintain a single unified control set mapped across NIST CSF 2.0, ISO 27001 Annex A, SOC 2 Trust Services Criteria, OSFI B-13 and B-10, and CIRO expectations, so a control is tested once and reported many times.
-
Entity segregation: Maintain entity level control mapping across CIRO regulated and OSFI regulated entities, ensuring every control answer and finding is labelled to the correct regime.
-
Policy management: Own the cybersecurity policy and standards library, including drafting, annual review cycle, approval routing, version control and publication.
-
Risk management: Own the cybersecurity risk register end to end, including risk identification, likelihood and impact scoring, treatment decisions, residual risk and named owners with committed dates.
-
Exception handling: Run the risk acceptance and exception process, including expiry dates, re-review triggers and escalation of expired or repeatedly extended exceptions.
-
Third party risk: Support vendor and third party security assessments under OSFI B-10, including critical service provider designation, concentration risk and contractual security obligations.
-
Operational resilience: Contribute to OSFI E-21 activities including critical operations mapping, tolerance for disruption, scenario testing and supporting evidence.
-
Issue governance: Track findings from internal audit, external audit, penetration tests, red team assessments and regulatory reviews through to verified closure, each with a named owner and a committed date.
-
Escalation: Escalate slipped remediation commitments through the Director and the Global Security Office rather than allowing findings to age without visibility.
-
Evidence management: Establish and maintain a single evidence repository and an annual evidence calendar, so control owners are asked for each artefact once per cycle.
-
Metrics and reporting: Define, collect and report control effectiveness metrics and key risk indicators, and prepare quarterly executive and Board committee reporting content.
-
Assurance interface: Act as the primary coordination point for external auditors, assessors and regulator information requests, including right of access and audit clause obligations.
-
Team leadership: Hire, coach, develop and manage one to two GRC specialists, setting the quality standard for evidence, documentation and audit responses.
-
Collaboration: Partner with JSOC, Offensive Security, Identity and Access Management, Fraud, Enterprise Risk, Internal Audit, Legal and Privacy, Procurement and entity compliance officers.
-
Continuous improvement: Leverage GRC tooling and automation to reduce manual evidence collection and move the programme toward continuous control monitoring.
-
Currency: Maintain an up-to-date understanding of regulatory developments, framework revisions, cloud control practices and security frameworks relevant to a Canadian regulated financial group.
-
7+ years of relevant experience in cybersecurity governance, risk and compliance, IT audit or technology risk, including at least 2 years leading people or leading a workstream with junior staff assigned.
-
Demonstrated ownership of at least one full SOC 2 Type II audit cycle as the internal lead, from readiness through to report issuance.
-
Hands-on ISO/IEC 27001 implementation or audit experience, ideally through a full certification or recertification cycle.
-
Working fluency in NIST CSF 2.0, including organisational profiles, implementation tiers and cross framework mapping.
-
Experience in a regulated financial services environment such as banking, brokerage, wealth management, payments or fintech.
-
Practical risk management experience covering risk registers, risk treatment plans, risk acceptance and residual risk reporting to senior stakeholders.
-
Experience assessing cloud control environments, particularly GCP or AWS, including identity and access management, logging and configuration controls, rather than reviewing policy documentation alone.
-
Strong written and verbal communication, presentation and technical writing skills, at a standard suitable for auditors, regulators and Board level readers.
-
Ability to operate independently across time zones within a geographically distributed team and with limited day to day supervision.
-
Comfortable challenging control owners constructively and holding remediation commitments to agreed dates.
-
Strong organisational agility, able to run multiple concurrent audit and assessment cycles without losing evidence integrity.