×
Register Here to Apply for Jobs or Post Jobs. X

Manager, Information Risk Management

Job in Montreal, Montréal, Province de Québec, Canada
Listing for: Manulife
Full Time position
Listed on 2026-02-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below
Location: Montreal

The Manager, Information Risk Management, plays a key role in providing independent Line 2 oversight across Global Cybersecurity Services (GCS) and broader technology domains. This role leads and executes complex risk assessments, provides credible challenge to control owners and senior technology partners, and ensures that technology, cyber, data, AI, and emerging tech risks are appropriately identified, managed, and governed. The Manager acts as a trusted advisor, contributes to the evolution of IRM oversight practices, and may lead or coach junior analysts to support consistent, high‑quality risk governance across the enterprise.

Position Responsibilities:

Independent Oversight & Support

  • Lead Line 2 oversight activities across technology, cyber, data, AI, cloud, and emerging technology domains.

  • Perform oversight and challenge on complex RCSAs, thematic reviews, technology change assessments, and targeted risk deep dives.

  • Provide expert review and challenge of Line 1 control documentation in areas such as cloud security, IAM, data protection, infrastructure, resilience, and disaster recovery.

  • Oversee and validate the quality of risk assessments, evidence, and remediation commitments provided by Line 1 partners.

  • Monitor and escalate significant issues, risk exceptions, control gaps, and corrective action plans.

  • Review reportable events, including security incidents, operational disruptions, and third‑party risks, ensuring accurate classification and effective remediation.

  • Governance, Reporting & Collaboration

  • Develop and deliver high‑quality risk reporting, dashboards, and insights for senior leadership, risk committees, and governance forums.

  • Maintain and enhance oversight processes, documentation, templates, and guidance materials to support a consistent risk practice.

  • Identify opportunities to uplift risk maturity, streamline processes, and strengthen the effectiveness of IRM oversight.

  • Contribute to the development of policies, standards, and methodologies in collaboration with Standards Governance, Technology Risk, Operational Risk, Privacy, and Compliance.

  • Represent IRM in cross‑functional forums, working groups, and strategic initiatives.

  • Professional Skills

  • Communicate clearly and concisely with stakeholders.

  • Build strong working relationships across Line 1 and Line 2 teams.

  • Demonstrate curiosity, attention to detail, and a commitment to a strong risk culture.

  • Required Qualifications:

  • 5–7+ years of experience in technology risk, cybersecurity, IT audit, or related domains.

  • Bachelor’s degree in computer science, computer engineering, IT Security, or a related field or equivalent experience.

  • Strong knowledge of cloud, IAM, cyber operations, resilience, infrastructure, or data protection concepts.

  • Experience leading oversight reviews of RCSAs, control testing programs, complex risk assessments, or thematic reviews.

  • Strong capability in analyzing technical risks and presenting them in business-relevant terms.

  • Demonstrated ability to engage and influence senior stakeholders across Technology, Cyber, and Risk teams.

  • Strong written and verbal communication skills & detail-oriented with strong organizational skills

  • Proactive, adaptable, and able to operate effectively in a dynamic and maturing risk environment.

  • Strong communication skills, clear, concise risk messaging for senior leaders.

  • Bilingualism (English and French) is an asset. If the successful candidate is in Québec, proficiency in English will be required to support clients from various provinces outside of Quebec.​

  • Preferred Qualifications:

  • Professional certifications or working towards such as CISSP, CISA, CRISC and CISM is an asset

  • Deep familiarity with risk and control frameworks (e.g., NIST CSF, ISO 27001, CIS Controls) is an asset

  • Experience coaching others or providing informal leadership is considered an advantage.

  • When you join our team:

  • We’ll empower you to learn and grow the career you want.

  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.

  • As part of our global team, we’ll support you in shaping the future you want to see.

  • #LI-Hybrid

    About Manulife and John Hancock

    Manulife Financial…

    Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
    To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
     
     
     
    Search for further Jobs Here:
    (Try combinations for better Results! Or enter less keywords for broader Results)
    Location
    Increase/decrease your Search Radius (miles)

    Job Posting Language
    Employment Category
    Education (minimum level)
    Filters
    Education Level
    Experience Level (years)
    Posted in last:
    Salary