Senior Manager, Cyber Security and IT Risk
Select how often (in days) to receive an alert:
Select how often (in days) to receive an alert:
Please be advised that our Careers site will be unavailable from November 28 at 12am ET to November 29 12am ET for scheduled system maintenance.Title:
Senior Manager, Cyber Security and IT Risk
Requisition
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
Contributes to the overall success of Cyber & IT Risk Management, Global Risk Management (GRM) globally ensuring specific individual goals, plans, and initiatives are executed/delivered in support of the team's business strategies and objectives. Ensures all activities are conducted in compliance with governing regulations, internal policies and procedures.
Collaborates with Technology and Operations teams, Enterprise Technology Risk Management, Regulatory Relations, Internal Audit, Compliance, and business-aligned risk stakeholders to support the effective management of technology and cyber risk issues, regulatory commitments, audit activities, remediation efforts, and governance processes. As part of the Second Line of Defense, the Cybersecurity and IT Risk Management team provides independent oversight and challenge and assists in the development and maintenance of methodologies, policies, standards, processes, and tools supporting the Enterprise Cyber and Technology Risk Management Framework.
The role focuses on audit and regulatory support, issue remediation governance, closure package quality assurance, policy and standards governance processes, management response development, and executive communications. The role also provides independent challenge and risk perspectives on technology and cyber risk matters where warranted by risk exposure, audit observations, regulatory expectations, or control weaknesses.
Is this role right for you? In this role, you will:
- Champions a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
- Audit and Stakeholder Engagement:
Manage constructive working relationships with Internal Audit, external assurance providers, Regulatory Relations, Technology, Operations, Compliance, and risk stakeholders. Support audit and regulatory activities through preparation of risk perspectives, briefing materials, evidence coordination, management responses, and issue updates. - Independent Challenge of Audit and Risk Issues:
Review audit observations, issue statements, management responses, remediation plans, closure criteria, and supporting evidence. Provide independent challenge and recommendations to ensure risk positions are balanced, accurate, supportable, and aligned with the underlying risk exposure. - Management Response Development and Issue Negotiation:
Support the development and review of management responses, action plans, remediation strategies, and closure narratives. Challenge issue wording, remediation approaches, and closure assumptions, as appropriate, to ensure clarity, accuracy, and defensibility. - Remediation Governance and Coordination:
Coordinate remediation activities, issue management efforts, and closure submissions primarily across the Cyber & IT Risk Management organization. Monitor progress against committed actions, facilitate alignment across risk teams, identify dependencies, and elevate delivery risks as appropriate. - Cross-Functional Issue Coordination:
Support engagement with First Line (1A), Technology Risk Officer (1B), and other stakeholders on an exception basis where issue remediation requires broader coordination, governance alignment, evidence aggregation, or cross-functional execution. - Closure Package Preparation and Quality Assurance:
Perform quality assurance reviews of remediation closure packages to ensure evidence is complete, relevant, current, and appropriately mapped to regulatory or audit recommendations, management action plans, regulatory commitments, and closure narratives. - Evidence Traceability and Audit Readiness:
Validate that closure submissions clearly demonstrate remediation activities, control improvements, evidence traceability, and issue resolution outcomes. Challenge unsupported assertions and identify documentation or evidence gaps prior to submission. - Process Design and Continuous Improvement:
Design, implement, and continuously improve remediation governance processes, quality assurance procedures, issue management routines, evidence standards, stakeholder engagement processes, and reporting mechanisms supporting Cyber & IT Risk Management activities. - Policy, Standard Governance:
Coordinate governance processes for the challenge of supporting technology policies and standards. Facilitate stakeholder engagement, review cycles, governance approvals, and tracking of required updates and QA of challenge deliverables. Provide independent challenge and recommendations on policies, standards when required. - Reporting and Executive Communications:
Prepare clear, concise, and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: