Senior Audit Manager, Emerging Risk & Cyber Security

Scotiabank
Toronto, ON
$89.5K-$112.7K a year (estimated)
Full-time

Requisition ID : 203180

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Purpose

Contributes to the overall success of the Emerging Risk & Cyber Security Audit in ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team's business strategies and objectives.

Ensures all activities conducted are in compliance with governing regulations, internal policies and procedures.

The Senior Audit Management will be required to work as part of a team or lead a team to conduct risk-based audit assessments of medium to high complexity following the Bank's Audit Methodology.

As a Senior Audit Manager, you will support the Director, Emerging Risk & Cyber Security Audit by planning and executing risk-based technical audits, across Cyber Security, Technology Infrastructure, Cloud and Digital Banking (web and mobile applications), to provide opinions on the effectiveness of controls to meet business objectives.

In addition, the subject matter expert is expected to be knowledgeable in risks associated with systems development methodologies (Waterfall and Agile), project management, automation and orchestration, data protection and outsourced IT services.

Accountabilities

Audit Execution :

Plan and lead collaborative risk-based Information and Cyber Security audits of moderate to high complexity in a local and global context and conclude whether risks are appropriately managed through the existence of effective control or other techniques.

When assuming a supervisory role, the auditor is expected to develop a comprehensive audit plan clearly outlining the objective, scope, deliverables, approach, resourcing and schedule.

Ensure quality of assignments through effective application of the Audit Standard Methodology of the Bank and appropriate use of specific applications and tools.

Strive for efficient use of audit resources by monitoring execution of audits assigned, timely escalation, and management of conflicts.

The incumbent is expected to seek and obtain direction, perspective and resources as required in order to complete the assigned audit on time and within budget.

Prepare and deliver effective presentations to clients at audit opening and closing meetings as a means of communicating and gaining their agreement and understanding of audit plans and audit results.

Provide value-adding and effective audit recommendations to client senior management identifying significant issues in a business context, working with audit clients to identify and recommend feasible solutions.

Present audits conclusions and reports in a relevant context and applicable to the Bank by ensuring they are supported by an orderly accumulation and analysis of documented audit evidence and that the content is clear and concise.

Perform accountabilities with minimal supervision and provide audit management and audit client with regular status updates of assignments.

Actively seek to be informed of industry and corporate initiatives and trends in order to support effective audit continuous monitoring of the Banks proper management of information and cyber security risks.

Leadership :

Maintain information security competency through ongoing professional development and staying abreast of emerging technologies, risks and controls in information and cyber security.

Provide direction, guidance and expert advice to audit teams globally to allow definition of effective assessments on information and cyber security risk management.

When required, prepare and deliver effective presentations on various audit and information security related matters to Audit senior management and relevant stakeholder across the Bank as a means to demonstrate expertise.

Identify and advise Audit teams on the use of data analytics and other advanced techniques and tools in order to improve efficiency and effectiveness of audit assessments.

Establish and maintain solid relationship with audit clients to serve as a catalyst of positive change and improvement of information and cyber security risk management.

Education and Other Requirements

Bachelor's degree in Information Technology, Computer Science or equivalent required.

One or more of the following certifications : CISA, CISM, CISSP, CCSP, GCIA, CEH is required.

Excellent analytics skills and proficiency with Microsoft Word, excel, and Powerpoint

Cloud engineering or architecture designation would be an asset.

Skills, Experience & Functional Competencies

7 years of information and cyber security experience.

Excellent written and verbal communication skills.

Experience in the assessment of threats and risks over IT processes and assets.

Knowledge and experience with security assessment tools (exploit tools, vulnerability assessment) and Security Operations Centre software (IDS, IPS, SIEM, etc.).

Knowledgeable in cyber security processes areas such as web application security, secure network security architecture, penetration testing, Red Team testing, vulnerability assessments, encryption, data loss prevention, coding assessment, cloud security, DDoS protection, and malware protection.

Ability to work independently and as part of a team of professionals

Location(s) : Canada : Ontario : Toronto

Scotiabank is a leading bank in the Americas. Guided by our purpose : "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone.

If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know.

If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role.

We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

30+ days ago
Related jobs
KPMG-Canada
Toronto, Ontario

Our Technology Risk Services services team is growing and we are looking for Senior Managers to join our team in Toronto. Working closely with our Audit teams to scope processes, conducting assessments of IT risks and controls, including general IT controls and automated controls embedded within inf...

CIBC
Toronto, Ontario

Nous bâtissons une banque axée sur les relations pour un monde moderne.Nous recrutons des professionnels talentueux et passionnés qui ont à cœur de faire ce qu’il faut pour nos clients.Banque CIBC, nous misons sur vos forces et vos ambitions pour vous donner le pouvoir d’agir.Les membres de notre éq...

Coinbase
Canada
Remote

At least 5 years of experience in security domains such as Application Security, Product Security, Infrastructure Security, Cloud Security, Security Engineering, etc. Build and manage a focused onchain security services/team and guide the development and operation of onchain security tools, audit fr...

Aviva
Markham, Ontario

Do you enjoy identifying, assessing and managing risk as part of running your day to day operations? Does the opportunity to design and perform controls to mitigate risk exposures, including control testing, and highlighting inadequate processes and unexpected events/incidents motivate you? We will ...

KPMG
Canada, Canada

We are currently looking for a Manager or Senior Manager specialized in Operational Risk Management to join our Financial Risk Management team in Montreal. Manage a variety of mandates involving non-financial risks (operational risks, business continuity, third-party risks, etc. In-depth knowledge o...

Ernst & Young
Toronto, Ontario

Financial Audit IT Integration - Execution of IT related audit procedures (including IT related procedures beyond ITGCs) in support of financial statement audits and reporting on internal controls over financial reporting (integrated and non-integrated audits). EY is seeking a Senior Manager, to joi...

PwC
Vaughan, Ontario

SummaryA career within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against threats, propels transformation, and drives growth. We play an integral role in helping our clients ensure they ar...

Community Trust
Mississauga, Ontario

Reporting to the Chief Risk Officer, the Senior Manager - IT Risk & Governance Oversight will play a key role in monitoring the management of IT and Cyber related risks. Monitor and review IT and cyber risk indicators, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), to id...

0000050007 Royal Bank of Canada
Toronto, Ontario

As a Senior Cyber Security Analyst in the Identity Access Management (IAM) Team, you will work with the IAM Application Onboarding Team to integrate RBC applications onto IAM solutions ( Entra ID (Azure), Sailpoint IIQ, CyberArk, etc). Confidentiality, Cyber Security Management, Decision Making, Det...

BMO
Canada, Canada

Through policy development and implementation, the incumbent will define in the methodology how the non-financial risk framework is executed and the associated risks are managed, monitored, and reported across the enterprise. Prior policy writing, as well as policy publication lifecycle experience, ...