About The Position

Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank’s strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world. Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group. Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries! We work together to drive ambition for every future! The Senior Manager of Technology Risk & Control Assessments will play a critical role in the hands-on execution of the Risk and Control Self-Assessment program across Technology. Reporting to the Director of Technology RCSAs, this role will lead the operational delivery of RCSAs, working closely with team members and First Line partners to ensure timely, accurate, and high-quality assessments. This role partners with technology leadership, risk management teams, and control owners to identify, assess, and mitigate technology risks while ensuring alignment with the bank’s enterprise risk management framework, regulatory expectations, and industry standards. The Senior Manager will lead deep-dive technology risk assessments, evaluate the effectiveness of controls, challenge risk assessments from the first line of defense, and deliver risk insights to senior management and risk governance committees. The ideal candidate is detail-oriented, collaborative, and skilled at managing multiple priorities in a fast-paced environment.

Requirements

  • Hands-on experience executing risk assessments or similar governance processes.
  • A minimum of 8+ years of experience in technology departments and/or risk management, preferably in a financial institution
  • 8+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation
  • Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
  • Proficiency in data security, risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
  • Bachelor’s degree in Information Systems, Computer Science, Risk Management, or related field.
  • Advanced knowledge of data analytics and data literacy

Nice To Haves

  • Industry certifications desirable (e.g. CISSP)
  • Advanced knowledge of relevant regulatory rules (OSFI, FFIEC, NYDFS 500) and frameworks (NIST, COBIT) is preferred

Responsibilities

  • Lead end to end execution of Technology RCSA activities across critical systems, platforms, and critical business services.
  • Own facilitation of risk identification, inherent risk assessment, control mapping, and residual risk determination for technology processes and services.
  • Perform deep dive assessments to evaluate control design and operating effectiveness across key technology domains (e.g., access management, change management, resiliency, third party risk).
  • Identify control gaps, emerging risks, and systemic issues, and drive clear remediation actions to reduce operational and cyber risk exposure.
  • Partner closely with First Line Technology teams to gather risk and control data, validate assessment outcomes, and reinforce ownership of risks and controls.
  • Provide oversight, coaching, and quality assurance to junior team members during RCSA execution.
  • Contribute to the continuous improvement of RCSA methodologies, tools, and procedures to enhance consistency, efficiency, and risk insight.
  • Participate in technology risk governance forums and working groups, supporting effective escalation and decision making.
  • Coordinate with Second and Third Line teams to support review, challenge, and alignment of RCSA outcomes.
  • Track issues, action plans, and remediation activities resulting from RCSAs, incidents, and regulatory findings, and support sustainable closure.
  • Deliver clear reporting on RCSA progress, key findings, and emerging risk themes, including concise summaries for senior management and governance committees.

Benefits

  • flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service