Location: southwestern ontario
Position Overview
As an Information Risk Management Senior Consultant, you will be part of the Group Functions (GF) Information Technology First Line of Defense and is responsible for performing risk-based information security assessments for new technologies and maintaining governance frameworks including generative AI technologies, ensuring compliance with information security standards, and managing risks associated with cloud-based, on premise and AI-driven platform and services.
Based in Toronto or Waterloo, ON, this individual contributor position supports a designated business unit and follows a hybrid work arrangement (3 days in office Tuesday, Wednesday & Thursday).
Key Responsibilities- Acts as a liaison and trusted partner for all information security activities in the business unit, ensuring balance between business/IT needs and leading security practices.
- Supports security and risk initiatives to instill cybersecurity policies and practices throughout business units.
- Collaborate with cross‑functional teams to embed cybersecurity and IT controls in all new initiatives and communicate the impact to relevant stakeholders.
- Participates in key initiatives and projects to ensure that cybersecurity and IT controls are accounted for early within the project and software development life cycles.
- Performs comprehensive information risk assessments of on‑prem, IAAS, PAAS, SAAS and generative AI projects, identifying and mitigating risks associated with the solutions.
- Ensures compliance with the global Information Risk Assessment methodology, policies, and standards.
- Maintains up‑to‑date knowledge related to cybersecurity threats, vulnerabilities and mitigations to reduce the attack surface and circulates this knowledge through the business units.
- Develops and implements risk management strategies across the business unit.
- Provides security consulting services to the business and IT partners.
- Tracks and manages identified information risk issues and associated corrective action plans (CAPs), ensuring timely resolution and closure in alignment with governance requirements.
- Supports operational security activities including segment‑specific security processes (e.g., incident response, vulnerability management, firewall reviews).
- Responds to audits, regulatory reviews, risk and controls self‑assessments.
- Provides training and advises key stakeholders on requirements, processes, standards, and best practices around information security and risk management.
- Minimum 5 years of experience in Information
Risk Management:
vendor risk management, project risk management, IT audit or IT controls assessment. - Bachelor’s degree or equivalent. Relevant professional designations (e.g., CISSP, CRISC, CISM, CISA) are a plus.
- Proven ability to quickly and easily adapt to changes within the business and organization.
- Ability to build and maintain robust relationships across teams and stakeholders.
- Ability to work in a fast‑paced workplace.
- Ability to balance competing demands with minimal management direction or support.
- Effective communication, presentation, negotiation and influencing skills.
- Strong presentation and facilitation skills for diverse audiences.
- Excellent time‑management and organizational skills to handle multiple tasks and changing priorities.
- Familiarity with laws and standards frameworks (e.g., NIST, ISO
27001, GDPR, Sarbanes‑Oxley, EU AI Act).
Toronto or Waterloo, ON office with a hybrid work arrangement (3 days in office Tuesday, Wednesday & Thursday).
SalarySalary range is expected to be between $ CAD – $ CAD. Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance.
Benefits- Health, dental, mental health, vision, short‑ and long‑term disability, life and AD&D insurance coverage.
- Adoption/surrogacy and wellness benefits.
- Employee/family assistance plans.
- Retirement savings plans including pension and global share ownership plan with employer matching contributions.
- Financial education and counseling resources.
- Paid time off program including holidays, vacation, personal and sick days, and full…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: