This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Are you a strategic leader who prefers building and implementing over just theorizing? Do you possess the technical gravitas to challenge a sharp IT team, paired with the diplomatic skill to be viewed as a business enabler rather than a roadblock? As the Director of ERM Cyber Risk, you will report directly to the VP and take the reins of a maturing cyber risk practice. This is a highly autonomous, entrepreneurial role where you will build upon the existing risk registers and control libraries to drive true program automation. Leading a specialized function within the risk department, you will have a massive impact on the organization while gaining exposure to broader enterprise risk domains. Success Milestones (Your First Year) By Month 3: Fully map out and develop our technology environment controls. By Month 6: Successfully identify and stabilize any existing control gaps. By Month 12: Fully roll out the matured program, achieve meaningful automation, and run the function autonomously with strong, trusted IT relationships.
Job Responsibility
Drive Implementation: Take ownership of technology key risk indicators (KRIs), business continuity, disaster recovery, and operational resilience programs from inception to completion
Bridge the Gap: Act as a critical 2nd-line partner to our 1st-line technology and architecture teams
Framework & Policy Leadership: Manage and mature our tech and policy frameworks, build robust risk metrics, and provide proactive thought leadership on emerging threat vectors and AI risk management
Enable the Business: Shift the perception of risk from a compliance roadblock to a collaborative business enabler
Requirements
Financial Services Expertise
Deep, practical experience navigating regulatory requirements within banking, lending, or insurance environments—specifically the OSFI framework
Dual-Perspective Experience
A proven track record working across both 1st-line (technology/infrastructure) and 2nd-line (risk/compliance) functions is highly desirable
Execution over Certifications
While certifications (like CISA, CRISC, or CISM) are great, we highly prioritize a tangible track record of hands-on framework implementation and program rollouts over theoretical knowledge
Influencing Power
A strong, collaborative personality capable of building relationships and guiding an opinionated, highly skilled technology department