About the Role
This role focuses on developing actionable risk and security insights through structured risk profiling. Reporting to the Director, this first line (1B) role acts as a trusted advisor, translating complex risk data into clear, actionable insights that inform senior leadership decisions, support business objectives, and strengthen the organization’s Information Security & Technology Risk (ISTR) posture.
Responsibilities
- Own and deliver portfolio-level risk profiles by consolidating risk and security insights across assets, initiatives, and key domains, including Cyber/Information Security, Technology Operations, and Technology Delivery.
- Develop and maintain standardized, executive-ready risk reporting, including KRIs/KPIs, thematic risk views, issue trends, policy exceptions, and control health indicators.
- Drive end-to-end governance of portfolio risk reporting, ensuring data quality, integrity, and consistency across inputs from multiple stakeholders and process owners.
- Partner with technology process owners, data owners, and delivery teams to ensure timely, accurate, and complete inputs into risk reporting.
- Act as a central coordination point across Technology, ISTR, Audit, and second line of defense (2LOD) functions, ensuring alignment and a consistent risk narrative.
- Engage with 2LOD oversight functions to incorporate independent challenge and regulatory expectations into reporting outputs.
- Collaborate with SMEs across CIO and CISO organizations to align risk reporting with enterprise priorities and emerging risk themes.
- Present portfolio risk posture, key themes, and emerging risks to senior leadership, demonstrating strong executive presence and influencing decision-making.
- Provide effective review and challenge of risk inputs (e.g., issues, audit findings, control statements) to ensure accuracy and completeness in executive reporting.
- Continuously enhance reporting capabilities through automation, visualization, and improved storytelling.
- Promote a transparent, risk-aware culture by improving visibility and understanding of technology and information security risks.
- Assist with internal policy risk assessments to ensure compliance with standards and regulations.
- Assist with internal, external and regulatory audit responses, including stakeholder engagement and evidence collection.
Requirements
- 8–10 years of experience in financial services or another regulated industry.
- 8–10 years of progressive experience in technology risk, information security, regulatory compliance, or IT governance.
- 3–5+ years of leadership experience (preferred).
- Bachelor's degree in computer science, Information Systems, Engineering, or related field, or equivalent experience.
- Strong understanding of technology risk, information security, Enterprise Risk Management framework, and regulatory requirements (e.g., OSFI, CIRO), as well as industry standards (COBIT, NIST, ISO, SOC 2).
- Proven ability to analyze and translate risks in a business context.
- Demonstrated continuous improvement mindset.
- Excellent written and verbal communication skills.
- Strong stakeholder management skills, with the ability to influence and build consensus.
- Intellectual curiosity and commitment to ongoing learning in technology and risk governance.
- Understanding of large enterprise operating models in regulated environments.
- Understanding PowerBI and automation tools or platforms would be an asset.
- Preferred certifications: CISA, CRISC, CISM, or CISSP.
- Experience with GRC tools (e.g., ServiceNow IRM, MetricStream).
Skills
- Technology Risk
- Information Security
- Regulatory Compliance
- IT Governance
- Enterprise Risk Management
- COBIT
- NIST
- ISO
- SOC 2
- PowerBI
- GRC tools
- ServiceNow IRM
- MetricStream
Location
- Hybrid
Work Type
- Permanent
- Full Time
Experience Level
- 8-10 years
- 3-5+ years leadership
Education Level
- Bachelor's degree in computer science, Information Systems, Engineering, or related field, or equivalent experience.
Salary/Compensations
- $124,300 - $145,300
Benefits
- Career Development opportunities
- Access to industry-leading learning programs
- Up to $2,000 annually towards education reimbursement
- Flexible health and dental benefits
- $5,000 mental health benefit
- In addition to regular vacation and personal days
- Volunteer day
- Company-matching pension plan
- Share ownership program
- Additional investment options
- Employee recognition programs
- Service milestone celebrations
- Employee discounts
- Employee Resource Groups (ERGs)
- Mentorship programs
- Social clubs and events
About the Company
- We are united by a shared purpose: to improve the financial, physical and mental well-being of Canadians.
- Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.
- We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other.
- Learn more about Canada Life.
Equal Opportunity
- We’re committed to removing barriers and ensuring equal access to employment.
- Applicants requiring reasonable accommodation during the application process may contact talentacquisitioncanada@canadalife.com.
- All information provided will be handled in accordance with applicable laws and Canada Life policies.
