About this role
About the Role
Senior Manager, IT Risk leads the 2nd line of defense for Cyber & IT Risk Management within Global Risk Management at Scotiabank. The role collaborates with cross-functional teams across the first line of defense to identify, assess, and mitigate cyber and IT risks, ensuring compliance with governing regulations and internal policies. It contributes to the development and implementation of risk management policies, standards, and controls to foster a robust risk culture and continuous improvement. As part of the second line of defense, the Cybersecurity and IT Risk team provides independent oversight and challenge, and assists in developing methodologies, policies, processes, and tools to support the Cyber and IT Risk Management Framework. What You'll Do
- Lead 2nd Line Challenge: Conduct comprehensive challenge to identify potential threats and vulnerabilities in the Bank’s processes, systems, and operations.
- Partner with 1st line of defense to develop risk mitigation strategies across key cyber and IT domains.
- Challenge IT and cybersecurity risks within scenario analysis and thematic reviews.
- Conduct cyber risk assessments, metrics, and controls within globally complex, dispersed, and diverse organizations.
- RCSA Program Management: Define the annual plan, in collaboration with GOR, the business and IT Risk. Assign resources as needed on selected RCSAs. Review and challenge the scope for IT, participants, and IT Profile for RCSAs.
- Risk Assessment and Identification: Objectively review & challenge the inherent risk, control effectiveness, and residual risk assessments & rationales, as well as related issues/APs, for technology specific risk/controls.