Manager, Cyber Security & IT Risk

ScotiabankToronto, ON
Onsite

About The Position

Manager, Cyber Security and IT Risk will contribute to the overall success of Cyber Security and IT Risk Management within Global Risk Management by supporting independent Second Line of Defense oversight, review, and challenge of cybersecurity risk management activities across the Bank. The role is focused on conducting cybersecurity risk assessments and thematic reviews, challenging First Line of Defense risk identification and remediation activities, monitoring key cyber risk indicators, supporting issue management oversight, and preparing concise risk reporting for senior management and governance committees. As part of the Second Line of Defense, the role provides objective challenge and advice to First Line teams while maintaining independence from control ownership and execution. The role helps assess whether IT and cyber risks are appropriately identified, measured, monitored, reported, and remediated in alignment with the Bank’s risk appetite, internal standards, regulatory expectations, and the Cyber and IT Risk Management Framework.

Requirements

  • Minimum 5 years of experience in cybersecurity, technology risk, information security, internal audit, risk advisory, or related disciplines, preferably within a financial services or highly regulated environment.
  • Experience conducting cybersecurity assessments, thematic reviews, control evaluations, or independent challenge activities across key cybersecurity domains.
  • Strong understanding of cybersecurity risk management practices and control frameworks, including areas such as identity and access management, vulnerability management, data protection, security monitoring, incident response, third-party risk, cloud security, and technology resilience.
  • Experience reviewing evidence, assessing control effectiveness, identifying control gaps, and communicating risk implications to business and technology stakeholders.
  • Experience supporting issue management and Risk acceptance processes, including issue identification, root cause analysis, remediation plan review, evidence assessment, and closure validation. Including Risk Acceptance adjudication and oversight.
  • Experience analyzing risk indicators, assessment results, issue trends, and emerging threats to generate meaningful risk insights and management reporting.
  • Ability to prepare concise, executive-level reporting and present cybersecurity risks, control weaknesses, and remediation concerns to senior stakeholders.
  • Experience reviewing cybersecurity standards, methodologies, procedures, or governance frameworks and assessing alignment with regulatory requirements and industry expectations.
  • Experience contributing to the enhancement of risk management methodologies, assessment frameworks, governance processes, reporting capabilities, or oversight practices.
  • Strong written and verbal communication skills with the ability to influence stakeholders and provide effective challenge while maintaining professional relationships.

Responsibilities

  • Conduct risk-based cybersecurity assessments, thematic reviews, and targeted challenge activities across key cybersecurity domains.
  • Independently assess whether cyber risks are appropriately identified, measured, monitored, reported, and remediated by the First Line of Defense.
  • Evaluate the effectiveness of risk management processes, control environments, remediation activities, and governance practices, and provide objective challenge, recommendations, and escalation where material risks or control weaknesses exist.
  • Support monthly and quarterly cyber and IT risk reporting for senior management and risk governance committees.
  • Analyze and challenge KRIs, control metrics, issue trends, assessment results, emerging threats, and remediation progress to develop clear, concise, and decision-useful risk insights.
  • Escalate material risks, deteriorating trends, and persistent control gaps through appropriate governance channels.
  • Support Second Line oversight of cyber and IT risk issues throughout the issue lifecycle, including issue identification, severity assessment, root cause review, management action plan challenge, remediation progress monitoring, evidence review, and closure readiness assessment.
  • Provide challenge where remediation actions do not appear sufficient, timely, sustainable, or aligned to the underlying risk. This also includes IT and Cyber Risk Acceptance oversight.
  • Review and challenge the appropriateness, completeness, and effectiveness of cybersecurity standards, procedures, methodologies, and governance frameworks developed by the First Line of Defense.
  • Assess alignment with regulatory requirements, industry frameworks, emerging risks, and the Bank's cyber and IT risk management framework, and provide recommendations to address gaps or strengthen control expectations.
  • Contribute to the ongoing development and maturation of the Cyber Security and IT Risk Management function by enhancing challenge methodologies, assessment approaches, reporting capabilities, issue management processes, governance practices, and supporting tools.
  • Support the development of frameworks, procedures, templates, and guidance that strengthen the effectiveness, consistency, and scalability of Second Line oversight activities.

Benefits

  • A competitive compensation and benefits package.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service