דלג לתוכן הראשי

Manager, Cybersecurity Governance, Risk & Compliance

Questrade Financial Groupישראללא צויןFull-timeדרגה: לא צוין

פורסם אתמול · 0 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה. פתיחת חשבון חינם לוקחת כמה שניות.

תיאור המשרה המלא

המשרה המקורית · נשמר לעיון

Questrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure.

At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work.

Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG.

What’s in it for you as an employee of QFG?

• Health & wellbeing resources and programs

• Paid vacation and personal days for work-life balance

• Competitive compensation and benefits packages

• Work-life balance

• Career growth and development opportunities

• Opportunities to contribute to community causes

• Work with diverse team members in an inclusive and collaborative environment

We’re looking for our next Manager, Cybersecurity Governance, Risk & Compliance. Could It Be You?

The Manager, Cybersecurity Governance, Risk & Compliance is a hands-on people manager accountable for cybersecurity compliance, audit delivery and risk management across Questrade Financial Group's regulated entities. She/he will personally lead the SOC 2 Type II and ISO 27001 audit cycles, own the cybersecurity control framework and enterprise cybersecurity risk register, and build, coach and manage a small team of one to two GRC specialists. The role operates in a dual regulatory environment covering CIRO regulated dealer and wealth entities and OSFI regulated federal financial institutions, and is based in Israel working Toronto business hours.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

• Audit delivery: Lead SOC 2 Type II readiness and the annual audit cycle end to end, including the evidence plan, control owner coordination, sampling, auditor requests and report issuance.

• Certification: Drive ISO/IEC 27001:2022 readiness and certification, covering ISMS scope, Statement of Applicability, risk treatment plan, internal audit programme, management review and nonconformity closure.

• Framework assessment: Manage NIST CSF 2.0 current and target profile assessments, including externally performed assessments, and produce the gap driven remediation roadmap that follows.

• Control framework: Build and maintain a single unified control set mapped across NIST CSF 2.0, ISO 27001 Annex A, SOC 2 Trust Services Criteria, OSFI B-13 and B-10, and CIRO expectations, so a control is tested once and reported many times.

• Entity segregation: Maintain entity level control mapping across CIRO regulated and OSFI regulated entities, ensuring every control answer and finding is labelled to the correct regime.

• Policy management: Own the cybersecurity policy and standards library, including drafting, annual review cycle, approval routing, version control and publication.

• Risk management: Own the cybersecurity risk register end to end, including risk identification, likelihood and impact scoring, treatment decisions, residual risk and named owners with committed dates.

• Exception handling: Run the risk acceptance and exception process, including expiry dates, re-review triggers and escalation of expired or repeatedly extended exceptions.

• Audit delivery: Lead SOC 2 Type II readiness and the annual audit cycle end to end, including the evidence plan, control owner coordination, sampling, auditor requests and report issuance.

• Certification: Drive ISO/IEC 27001:2022 readiness and certification, covering ISMS scope, Statement of Applicability, risk treatment plan, internal audit programme, management review and nonconformity closure.

• Framework assessment: Manage NIST CSF 2.0 current and target profile assessments, including externally performed assessments, and produce the gap driven remediation roadmap that follows.

• Control framework: Build and maintain a single unified control set mapped across NIST CSF 2.0, ISO 27001 Annex A, SOC 2 Trust Services Criteria, OSFI B-13 and B-10, and CIRO expectations, so a control is tested once and reported many times.

• Entity segregation: Maintain entity level control mapping across CIRO regulated and OSFI regulated entities, ensuring every control answer and finding is labelled to the correct regime.

• Policy management: Own the cybersecurity policy and standards library, including drafting, annual review cycle, approval routing, version control and publication.

• Risk management: Own the cybersecurity risk register end to end, including risk identification, likelihood and impact scoring, treatment decisions, residual risk and named owners with committed dates.

• Exception handling: Run the risk acceptance and exception process, including expiry dates, re-review triggers and escalation of expired or repeatedly extended exceptions.

• Third party risk: Support vendor and third party security assessments under OSFI B-10, including critical service provider designation, concentration risk and contractual security obligations.

• Operational resilience: Contribute to OSFI E-21 activities including critical operations mapping, tolerance for disruption, scenario testing and supporting evidence.

• Issue governance: Track findings from internal audit, external audit, penetration tests, red team assessments and regulatory reviews through to verified closure, each with a named owner and a committed date.

• Escalation: Escalate slipped remediation commitments through the Director and the Global Security Office rather than allowing findings to age without visibility.

• Evidence management: Establish and maintain a single evidence repository and an annual evidence calendar, so control owners are asked for each artefact once per cycle.

• Metrics and reporting: Define, collect and report control effectiveness metrics and key risk indicators, and prepare quarterly executive and Board committee reporting content.

• Assurance interface: Act as the primary coordination point for external auditors, assessors and regulator information requests, including right of access and audit clause obligations.

• Team leadership: Hire, coach, develop and manage one to two GRC specialists, setting the quality standard for evidence, documentation and audit responses.

• Collaboration: Partner with JSOC, Offensive Security, Identity and Access Management, Fraud, Enterprise Risk, Internal Audit, Legal and Privacy, Procurement and entity compliance officers.

• Continuous improvement: Leverage GRC tooling and automation to reduce manual evidence collection and move the programme toward continuous control monitoring.

• Currency: Maintain an up-to-date understanding of regulatory developments, framework revisions, cloud control practices and security frameworks relevant to a Canadian regulated financial group.

So are YOU our next Manager, Cybersecurity Governance, Risk & Compliance? You are if you…

• 7+ years of relevant experience in cybersecurity governance, risk and compliance, IT audit or technology risk, including at least 2 years leading people or leading a workstream with junior staff assigned.

• Demonstrated ownership of at least one full SOC 2 Type II audit cycle as the internal lead, from readiness through to report issuance.

• Hands-on ISO/IEC 27001 implementation or audit experience, ideally through a full certification or recertification cycle.

• Working fluency in NIST CSF 2.0, including organisational profiles, implementation tiers and cross framework mapping.

• Experience in a regulated financial services environment such as banking, brokerage, wealth management, payments or fintech.

• Practical risk management experience covering risk registers, risk treatment plans, risk acceptance and residual risk reporting to senior stakeholders.

• Experience assessing cloud control environments, particularly GCP or AWS, including identity and access management, logging and configuration controls, rather than reviewing policy documentation alone.

• Strong written and verbal communication, presentation and technical writing skills, at a standard suitable for auditors, regulators and Board level readers.

• Ability to operate independently across time zones within a geographically distributed team and with limited day to day supervision.

• Comfortable challenging control owners constructively and holding remediation commitments to agreed dates.

• Strong organisational agility, able to run multiple concurrent audit and assessment cycles without losing evidence integrity.

Additional Kudos If You…

• CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or an equivalent relevant work experience.

• Knowledge of SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 and Annex A controls, NIST Cybersecurity Framework 2.0 and NIST SP 800-53.

• Familiarity with OSFI B-13, B-10 and E-21, and CIRO cybersecurity expectations, or demonstrated ability to learn a new prudential regime quickly.

• Familiarity with Canadian privacy obligations including PIPEDA and Quebec Law 25.

• Familiarity with GRC and cloud security platforms such as ServiceNow IRM, Salt, ZScaler, Cloudflare, F5, FortiGate, Palo-Alto, Drata or Wiz.

• Familiarity with PCI DSS and MITRE ATT&CK is considered an asset.

Sounds like you? Click below to apply!

At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us.

Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review.

Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.

אודות Questrade Financial Group
פרופיל החברה · בקרוב

ביקורות עובדים · בקרובעוד משרות ב-Questrade Financial Group

שאלות על המשרה

  • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
דומות וקשורות
Questrade Financial Group
פורסם אתמול · 0 מועמדים
בדקו את ההתאמה