Were looking for our next Manager, Cybersecurity Governance, Risk & Compliance. Could It Be You?
The Manager, Cybersecurity Governance, Risk & Compliance is a hands-on people manager accountable for cybersecurity compliance, audit delivery and risk management across our regulated entities. She/he will personally lead the SOC 2 Type II and ISO 27001 audit cycles, own the cybersecurity control framework and enterprise cybersecurity risk register, and build, coach and manage a small team of one to two GRC specialists. The role operates in a dual regulatory environment covering CIRO regulated dealer and wealth entities and OSFI regulated federal financial institutions, and is based in Israel working Toronto business hours.
Audit delivery: Lead SOC 2 Type II readiness and the annual audit cycle end to end, including the evidence plan, control owner coordination, sampling, auditor requests and report issuance.
Certification: Drive ISO/IEC 27001:2022 readiness and certification, covering ISMS scope, Statement of Applicability, risk treatment plan, internal audit programme, management review and nonconformity closure.
Framework assessment: Manage NIST CSF 2.0 current and target profile assessments, including externally performed assessments, and produce the gap driven remediation roadmap that follows.
Requirements: So are YOU our next Manager, Cybersecurity Governance, Risk & Compliance? You are if you
7+ years of relevant experience in cybersecurity governance, risk and compliance, IT audit or technology risk, including at least 2 years leading people or leading a workstream with junior staff assigned.
Demonstrated ownership of at least one full SOC 2 Type II audit cycle as the internal lead, from readiness through to report issuance.
Hands-on ISO/IEC 27001 implementation or audit experience, ideally through a full certification or recertification cycle.
Working fluency in NIST CSF 2.0, including organisational profiles, implementation tiers and cross framework mapping.
Experience in a regulated financial services environment such as banking, brokerage, wealth management, payments or fintech.
Practical risk management experience covering risk registers, risk treatment plans, risk acceptance and residual risk reporting to senior stakeholders.
Experience assessing cloud control environments, particularly GCP or AWS, including identity and access management, logging and configuration controls, rather than reviewing policy documentation alone.
Strong written and verbal communication, presentation and technical writing skills, at a standard suitable for auditors, regulators and Board level readers.
Ability to operate independently across time zones within a geographically distributed team and with limited day to day supervision.
Comfortable challenging control owners constructively and holding remediation commitments to agreed dates.
Strong organisational agility, able to run multiple concurrent audit and assessment cycles without losing evidence integrity.
Additional kudos if you
CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or an equivalent relevant work experience.
Knowledge of SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 and Annex A controls, NIST Cybersecurity Framework 2.0 and NIST SP 800-53.
Familiarity with OSFI B-13, B-10 and E-21, and CIRO cybersecurity expectations, or demonstrated ability to learn a new prudential regime quickly.
Familiarity with Canadian privacy obligations including PIPEDA and Quebec Law 25.
Familiarity with GRC and cloud security platforms such as ServiceNow IRM, Salt, ZScaler, Cloudflare, F5, FortiGate, Palo-Alto, Drata or Wiz.
Familiarity with PCI DSS and MITRE ATT&CK is considered an asset.
This position is open to all candidates.