Director, U.S. Deputy CISO
Listed on 2025-12-31
-
IT/Tech
Cybersecurity, Information Security, Data Security
Select how often (in days) to receive an alert:
Please note that the Salary Range shown is a guideline only. Salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience.
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
Global Banking and MarketsGlobal Banking & Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank’s strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world.
Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group.
Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries! We work together to drive ambition for every future!
PurposeThe US Deputy Chief Information Security Officer (Deputy CISO) will support the MD & US CISO in building robust United States technology risk (includes all non-financial risks such as Cyber Risk, Availability, Resiliency Risks and Operational Risk) related controls and processes and ensure they are maintained and adhered to in the assigned portfolio. Along with the MD & US CISO the Deputy CISO will collaboratively assess, evaluate and remediate increasingly complex technology risk, design controls and assist in their implementation in the USA, a key growth market.
Acts in the line of defense as Internal Control (1B) to ensure implementation of initiatives in accordance with regulatory expectations, risk appetite, organizational risk practices and evolving business practices. Ensures all activities conducted are in compliance with governing regulations, internal policies and procedures.
- Champion a customer focused culture to deepen relationships with Sr. leadership, peers, and functional groups by leveraging IT and risk expertise.
- Partners across senior executives US CIO, Global CISO, Risk, Operations, compliance and legal teams to deliver improved US regulatory outcomes and strategies.
- Supports in the US 1st line Technology Risk, Cyber Security and Internal Controls teams.
- Alongside with the MD & CISO, the Deputy CISO will collaborate with US CIO and Global CISO, in leading frequent interaction and reporting to US Federal Regulators.
- Support in overseeing critical 1st Line of Defense (1B) function in highly regulated US Technology realm with ongoing guidance to support the implementation of, and compliance to, established IT Standard, Policies, Procedures, regulatory, operational risk and cyber risk requirements through active engagement, guidance and counselling.
- Support in leading US 1st Line of Defense (1A) teams and Risk owners, to build their capability to identify, assess, mitigate and monitor risks associated with their use of information and IT systems.
- Is primary interface and conduit between the 1A risk owners and other risk groups or advisors in various business areas (Internal Controls, Audit, Cyber Security, Privacy, Fraud, Resilience, Availability) to spearhead the facilitation and execution of risk management activities.
- Support in Managing Technology Risk identification, assessment, prioritization for relevant business areas. Ensures observations, issues and outputs are tracked and actioned.
- Support in leading US Technology risk control testing and monitoring and guides all US based Technology Risk Owners with remediation plans.
- Partner with and face other risk groups to assess, implement and communicate…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).