About the Role
This role provides specialized technology and cyber risk expertise to assess risks at Federally Regulated Financial Institutions (FRFIs), contributing to OSFI's mandate of ensuring the stability and integrity of Canada's financial system.
Responsibilities
- Provide specialty technology and cyber risk expertise in assessing risks at Federally Regulated Financial Institutions (FRFIs).
- Identify FRFI-specific risks, industry-wide risks, and sector-specific trends related to technology and cyber risks impacting operational resilience.
- Apply expertise in technology and cyber risk management practices, penetration testing, red and blue teamwork, and threat assessments for systems, data, infrastructure, networks, cybersecurity, and digital technology in the financial services industry.
Requirements
- Official Language Proficiency: Bilingual - Imperative (CBC/CBC).
- Experience analyzing data.
- Experience generating reports.
- Experience liaising with Senior Management.
- Experience making presentations to Senior Management.
- Security – Reliability Status.
- Ability to work remotely from home within Canada with internet access.
- Ability and willingness to travel within Canada when required.
Skills
- Knowledge of cybersecurity penetration testing process, methods, and frameworks.
- Knowledge of current and emerging technology or cyber risks and trends in the financial services industry.
- Knowledge of current and emerging cyber threats in the financial services industry.
- Collaboration.
- Results Orientation.
- Critical Thinking.
- Ability to communicate effectively in writing.
- Ability to communicate effectively verbally.
- Knowledge of current and emerging business and environmental trends/issues in the financial services industry (Asset).
- Knowledge of banking or insurance sectors, including key products, functions, and measurement/management techniques (Asset).
- Innovation (Asset).
- Growth and development (Asset).
Location
- Toronto.
- Ottawa (may be approved).
- Vancouver (may be approved).
- Montreal (may be approved).
Work Type
- Indeterminate.
- Telework.
- Mandatory onsite presence.
- Remote (within Canada).
Experience Level
- Significant experience (3+ years) in the financial services industry related to technology and cyber risk management and response in Business or Technology Operations, system/data analysis, or a related control function (e.g., cybersecurity, business continuity management, operational risk).
- Significant experience (3+ years) performing regulatory supervision of technology and cyber risk.
- Recent (within 5 years) and significant (3+ years) experience in technology and cyber risk management and response in two of the following: Business or Technology Operations, system/data analysis, or a related control function (e.g., cybersecurity, business continuity management, operational risk) (Asset).
- Significant experience (3+ years) in technology risk management and cyber risk management in the financial services industry (Asset).
Education Level
- Degree or diploma from a recognized post-secondary institution with specialization in information technology, information/cyber security, computer science, engineering, business, commerce, economics, finance, mathematics, or other relevant field.
- Acceptable combination of relevant experience and education or training.
- Relevant graduate degree from a recognized post-secondary institution (Asset).
- Certified Information Security Manager (CISM) certification (Asset).
- Certified Information Systems Security Professional (CISSP) certification (Asset).
- Certified Information Systems Auditor (CISA) certification (Asset).
Salary/Compensations
- $105,200.00 - $135,300.00
About the Company
- The Office of the Superintendent of Financial Institutions (OSFI) is an independent agency of the Government of Canada.
- Dedicated to fostering public trust and confidence in Canada's financial system.
- Rigorously regulates and supervises over 400 federally regulated financial institutions (FRFIs) and 1200 federally regulated pension plans (FRPPs).
- Ensures FRFIs and FRPPs operate soundly and securely through diligent regulation and supervision.
- Proactive approach to risk management and early intervention safeguards interests of depositors, policyholders, pension plan members, and beneficiaries.
- Mandate is to ensure the stability and integrity of Canada's financial system.
- Maintains financial soundness of FRFIs and FRPPs.
- Safeguards FRFIs against threats to integrity and security, including foreign interference.
- Acts swiftly with proactive intervention when issues arise, requiring corrective measures.
- Continuously monitors and evaluates risks, promoting sound risk management practices.
- Adopts a balanced approach: protecting rights and interests of depositors, policyholders, and creditors while recognizing FRFIs' need to compete and take reasonable risks.
- Safeguards rights and interests of pension plan members, former members, and entitled beneficiaries.
Equal Opportunity
- Committed to providing an inclusive and barrier-free work environment, starting with the hiring process.
- Accommodation available during any phase of the evaluation process.
- Committed to having a skilled and diverse workforce representative of the Canadian population.
- Selection may be made from qualified candidates who self-declare as belonging to Employment Equity groups: Persons with a disability, Indigenous Peoples, Members of a Visible Minority, or Women.
- Committed to diversity and inclusion; strongly encourage candidates to self-declare.
- The Public Service of Canada is committed to building a skilled and diverse workforce that reflects the Canadians we serve.
- Promote employment equity and encourage self-declaration of designated groups.
- Preference will be given to veterans first and then to Canadian citizens and permanent residents.
- Assessment accommodations are designed to remove barriers and ensure candidates with limitations can fully demonstrate their abilities.
