Senior Manager, GRC Regulatory Assurance

TMX GroupToronto, ON
CA$125,000 - CA$145,000Hybrid

About The Position

The Senior Manager, GRC Regulatory Assurance is responsible for providing tactical and operational leadership to ensure TMX Group’s assets are protected and that the organization maintains robust regulatory compliance. This role will drive the maturation of the regulatory assurance program, serving as a critical bridge between TMX Group of subsidiaries and the Information Security Office. You will manage a high-performing team tasked with maturing the information security program, ensuring alignment with global regulatory frameworks, and fostering a culture of risk-aware compliance across the enterprise.

Requirements

  • University undergraduate degree in Computer Science, Engineering, or a related field.
  • 10+ years of information technology experience, with a minimum of 7 years specifically in information security, risk, or regulatory compliance.
  • 5+ years of people management/leadership experience with a proven track record of developing high-performing teams.
  • Proficiency in interpreting and applying regulatory frameworks (e.g., BOC, OSFI, AMF, and SWIFT) within a financial market infrastructure context.
  • Strong understanding of cybersecurity governance, policy frameworks, and risk assessment methodologies (e.g., TRAs).
  • CISSP is required.
  • Proven track record as a business partner who can translate complex technical risk into actionable business language for non-technical stakeholders.

Nice To Haves

  • CISA, CISM, or ISO 27001 Lead Auditor certifications are considered significant assets.

Responsibilities

  • Oversee activities to maintain regulatory compliance across TMX Group’s regulated entities (e.g., BOC, OSFI, AMF, and SWIFT).
  • Perform mapping and control testing of regulatory expectations and principles to control requirements to validate compliance coverage.
  • Collaborate with internal stakeholders and Legal to manage regulatory inquiries, audit examinations, and the development of formal responses.
  • Track and report on remediation of findings from internal and external audits to ensure timely closure.
  • Define and maintain the overarching cybersecurity strategy and policy framework lifecycle.
  • Manage the continuous improvement of the GRC program, ensuring alignment with industry standards such as NIST, ISO 27001, and ITIL.
  • Oversee the refresh of technical security standards and policies to address emerging threats and cloud-native requirements.
  • Develop, manage, and enhance GRC risk management tooling capabilities.
  • Establish and track metrics (KPIs/KRIs) to monitor the effectiveness of the Information Security GRC program.
  • Provide monthly and quarterly reporting on the status of regulatory compliance, risk registers, and remediation efforts for executive leadership, CISO, RMC, and Board.
  • Perform vendor products and services security assessments.
  • Provide purchase and merger and acquisitions advice to CISO, ERM, Procurement, and Legal.
  • Lead, mentor, and manage a team of security advisors and analysts.
  • Ensure that team members have established SMART objectives aligned with ITSS and overall TMX goals.
  • Foster a culture of "Client-Centricity," courage, and trust, promoting proactive engagement with business units.
  • Develop strong working relationships within the Information Security Office, Enterprise Risk Management (ERM), ITSS Architecture, to ensure seamless execution of risk management initiatives.
  • Collaborate with the business units to integrate security into business continuity and operational processes.

Benefits

  • Generous time-off and leaves
  • Cloud-first and hybrid workstyle
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service