Cyber Risk Manager

3 weeks ago


New York, New York, United States Scotiabank Full time
Job Summary:
Senior Cyber and IT Risk Management position available at Scotiabank. Estimated Salary: $163,550 - $292,150 per year.

About the Role:
This is a high-profile role in the Global Banking and Markets division, where you will contribute to the overall success of Cyber & IT Risk Management globally. Your expertise will ensure specific individual goals, plans, initiatives are executed/delivered in support of the team's business strategies and objectives. You will lead expert technical risk assurance and control oversight to ensure the bank achieves its objectives while effectively managing risk. Collaborate with cross-functional teams across the first line of defense to identify, assess, and mitigate emerging risks and vulnerabilities. This role is crucial in fostering a robust risk culture and driving continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls. As part of the second line of defense, the Cybersecurity and IT Risk team provides independent oversight and challenge, and assists in developing methodologies, policies, processes, and tools to support the Cyber and IT Risk Management Framework.

Main Responsibilities:
  • Champion a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems, and knowledge.
  • Lead 2nd Line Challenge: Conduct comprehensive challenge to identify potential threats and vulnerabilities in the Bank's processes, systems, and operations. Partner with 1st line of defense to develop risk mitigation strategies across key cyber and IT domains. Challenge IT and cybersecurity risks within scenario analysis and thematic reviews. Conduct cyber risk assessments, metrics, and controls within globally complex, dispersed, and diverse organizations.
  • Control Evaluation: Evaluate the design of controls and communicate the impact of control weaknesses to first line teams and control implementers.
  • Alignment Evaluation: Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
  • Framework Expertise: Be a subject matter expert in one or more industry-standard risk management frameworks (including ISO27001, COBIT, NIST) and have an in-depth understanding of cyber risk mitigation strategies.
  • Stakeholder Advisory: Advise stakeholders on risk management, controls development, and adherence to mitigate risks.
  • Risk Monitoring: Proactively monitor key risk indicators, analyze control metrics, and provide insights on risk management effectiveness to senior management, driving continuous improvement initiatives.
  • Reporting: Support monthly and quarterly IT and Cyber Risk report development for various risk committees and senior management.
  • Risk Monitoring: Monitor cybersecurity risks and the controls in place within the bank, as well as external cybersecurity reporting that may impact the bank.
  • Security Operations: Manage, assess, or audit security operations processes and technologies, including SOC, SIEM, Fusion Center, and Incident Response.
  • Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champion a high performance environment and contributes to an inclusive work environment.
Requirements:
  • Strong expertise in IT Risk Management (e.g. Logical Access, Data Leakage, Disaster Recovery).
  • Experience with Cybersecurity Risk Management is preferred.
  • A minimum of 7 years of experience in technology departments and/or risk management, preferably in a financial institution.
  • Industry certifications desirable (e.g. CISSP).
    •Advanced knowledge of relevant regulatory rules (OSFI, FFIEC, NYDFS 500) and frameworks (NIST, COBIT) is preferred.
  • 5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation.
  • Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR).
  • Proficiency in data security, risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies.
  • Advanced knowledge of data analytics and data literacy.


  • New York, New York, United States News Corp. Full time

    News Corp. is seeking an experienced Senior GRC Analyst to join our team! As a key member of our cyber security team, you will play a critical role in ensuring the company's global cyber GRC program remains robust and effective. Your responsibilities will include managing and monitoring cyber risks and issues, performing due diligence against our third-party...


  • New York, New York, United States Capital One Full time

    About UsCapital One is a leading financial institution providing innovative banking solutions to customers across the globe.Job DescriptionWe are seeking an experienced Cyber Risk Management Leader to join our Enterprise Services Business Risk Office. This role will provide risk management support to various lines of business, including Brand, Enterprise...


  • New York, New York, United States Sumitomo Mitsui Banking Corporation Full time

    Global Cyber Risk Management DirectorWe are a top-tier global financial group with a strong commitment to innovation and excellence. Our company overview provides a glimpse into our diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. With a presence in nearly 40 countries and over 130 offices, we...


  • New York, New York, United States Teneo Full time

    ResponsibilitiesThe Cyber Risk Management Advisor will be responsible for providing expert advice on cyber risk management to clients across various industries. This will involve conducting research and analysis, developing strategic recommendations, and communicating findings to senior stakeholders.The ideal candidate will have a deep understanding of cyber...


  • New York, New York, United States Capital One Full time

    About UsAt Capital One, we're committed to driving innovation and growth in the field of information security. Our team is passionate about staying ahead of emerging threats and delivering cutting-edge solutions that protect our customers' sensitive data.Job SummaryWe're seeking an experienced Cyber Security Manager, Enterprise Risk to join our Information...


  • New York, New York, United States Nearshore Cyber Full time

    Company OverviewNearshore Cyber is a forward-thinking fintech company that prioritizes innovation and security. As a GRC Analyst, you will be an integral part of shaping our governance, risk, and compliance programs.We are committed to ensuring the highest standards of security and compliance in the financial industry. Our team works tirelessly to identify...


  • New York, New York, United States Fidelity Information Services Full time

    About the TeamWe are a team of highly skilled professionals dedicated to delivering innovative and secure solutions to our clients. As a Enterprise Cyber Risk Management Expert, you will play a critical role in shaping our organization's cybersecurity strategy and ensuring the protection of our assets.The ideal candidate will have a strong background in...


  • New York, New York, United States Aon Full time

    About the JobThis role is perfect for individuals with a passion for cyber risk management and insurance brokering. You will work closely with our team to deliver exceptional results for our clients. The salary range for this position is $85,000 to $110,000 annually, based on education, experience, skills, and location.Key ResponsibilitiesAnalyze the...


  • New York, New York, United States News Corp Full time

    About the Role:The Governance, Risk and Compliance Analyst will play a pivotal part in shaping News Corp's cyber security posture. This role demands an exceptional understanding of global regulatory and compliance requirements, as well as a deep grasp of cyber security control principles and privacy principles.Key Responsibilities: Support the maintenance...


  • New York, New York, United States CyberCube Full time

    About CyberCube: We're a digital analytics leader with a mission to deliver cutting-edge cyber risk solutions. Our explosive team growth and exceptional funding have enabled us to surpass 100 clients globally, with a >99% retention rate. We've been recognized with industry awards, including Cyber Risk Solution of the Year and InsurTech Product of the...


  • New York, New York, United States ShiftCode Analytics Full time

    **About the Role:**We are seeking an Onsite Cyber Risk Manager to join our team at ShiftCode Analytics. As a key member of our security team, you will be responsible for identifying and mitigating potential security risks, as well as implementing and maintaining effective cybersecurity measures.Your expertise will be critical in ensuring the security of our...


  • New York, New York, United States Nearshore Cyber Full time

    **Company Overview**Nearshore Cyber, a leading fintech company, is seeking a skilled Governance, Risk, and Compliance (GRC) Analyst to join their team.This full-time, permanent position offers the opportunity to work 100% remotely from anywhere in the Americas.As a GRC Analyst reporting directly to the Head of Security, you will play a pivotal role in...

  • GRC Risk Specialist

    6 days ago


    New York, New York, United States Nearshore Cyber Full time

    Company OverviewNearshore Cyber is an innovative fintech company seeking a skilled Governance, Risk, and Compliance (GRC) Analyst to join their team. This full-time, permanent position offers the opportunity to work 100% remotely from anywhere in the Americas.


  • New York, New York, United States CyberCube Full time

    Job OverviewCyberCube is a leading provider of digital analytics solutions for cyber risk management. We are seeking an experienced professional to join our team as a Director of Strategic Government Partnerships.About the RoleThe successful candidate will be responsible for building and executing a strategy to engage government agencies in multiple...


  • New York, New York, United States AXA XL Ltd Full time

    As a Cyber Risk Management Professional at AXA XL Ltd in New York, NY, you will be part of a team that offers property, casualty, financial lines, and specialty insurance and reinsurance solutions to mid-sized companies through to large multinationals globally.The estimated salary for this role is $85,000 - $110,000 per year, based on industry standards and...

  • Cyber Risk Consultant

    3 weeks ago


    New York, New York, United States Resilience Corp. Full time

    Resilience Corp. is a leading cybersecurity company on a mission to help organizations achieve cyber resilience.The company was founded in 2016 by experts from the US military and intelligence communities, and has since become a trusted partner for middle to large market enterprises. Resilience offers insurance coverage through its licensed agency and...


  • New York, New York, United States Metropolitan Transportation Authority Full time

    About the PositionThe Metropolitan Transportation Authority is seeking a Chief Cyber Risk Officer to lead our efforts in identifying and mitigating cyber risks. As a senior leader in our IT department, you will play a critical role in developing and implementing effective cybersecurity strategies to protect our organization's assets.Job DescriptionManage and...


  • New York, New York, United States Yoh, A Day & Zimmermann Company Full time

    Job DescriptionWe are seeking a Cyber Risk Professional to join our team in New York City or Stamford, CT. This role involves providing operational support, metrics, reporting, and assisting with the preparation of presentations. You will work closely with the Chief Information Risk Officer (CIRO) and Chief Information Security Officer (CISO).


  • New York, New York, United States CyberCube Full time

    Company OverviewCyberCube is a leading provider of digital analytics solutions, dedicated to delivering innovative cyber risk analytics to the insurance industry. Our mission is to empower clients with cutting-edge insights and tools to mitigate complex cyber threats.Salary & BenefitsWe offer a competitive salary range of $80K - $90K, plus unlimited PTO,...


  • New York, New York, United States Capital One Full time

    Capital One OverviewCapital One is a financial services company that offers a wide range of products and services to its customers. We are committed to helping our customers achieve their financial goals and live better lives.In order to achieve this mission, we need talented individuals who can help us deliver high-quality products and services. That's...