About the Role
The AVP, Technology Risk is a Second Line of Defense role responsible for executing proactive and effective Technology risk management practices. This role will provide a holistic view of the organization’s technology risk posture, ensure technology risks are understood and mitigated, and foster a risk management culture within the Technology organization.
Responsibilities
- Provide oversight and challenge for the company to advance Technology Risk Governance policies, practices and operating model.
- Provide oversight for the design, implementation, maturity, and continuous monitoring of technology risk controls.
- Participate in governance structure with appropriate committees and stakeholder groups.
- Ensure the development and adoption of policies and operating standards; enforce compliance and run ongoing monitoring of compliance with policies and standards.
- Review the development and evolution of Canada Life’s technology issues and audit management processes.
- Partner with Technology to maintain or expand risk capabilities and services governance.
- Assess the Technology Risk & Control identification process across Canada, supporting the 1 LOD in implementation of controls and conducting Risk and Control Assessment across Canada.
- Advance innovation strategy including automated control testing and the use of AI.
- Contribute to the development and implementation of key risk indicators (KRIs), control indicators, and reporting to measure risk posture and highlight areas of concern.
- Foster, advocate for, and strengthen the organization’s overall technology risk posture.
- Coordinate technology risk activities including supporting audit activities such as Risk reporting and regulatory and related compliance reporting.
Requirements
- 10+ years’ experience in a similar technology risk leadership position.
- 5-10 years of experience in varied senior security related leadership positions would be an asset.
- 5-10 years of experience in the financial services industry or in a large organization.
- 5-10 years of experience within the area of risk, compliance or governance specific to Information Services.
- Understanding of technology risk regulatory, best practices and industry best practices.
- Experience building and working in matrix and complex organizations with demonstrated ability to influence teams where resources do not all report directly into the function.
- Skilled leader with exceptional communication abilities, collaboration and relationship building skills establishing credibility and fostering cross-functional relationships.
- Strong verbal and written communication skills and interpersonal skills needed to effectively build relationships and communicate with Executives, internals stakeholders, and customers.
- Constant learner and passion for technology and risk governance.
- Deep understanding of how large enterprise organizations work, within in a regulated environment.
- Proven ability to identify, analyze and translate risk in the context of what it means to achieving business objectives.
- Familiarity working with a Business Information Security Office (BISO) model.
- Ability to attract, motivate and develop talent to build the right team to meet strategic direction and tomorrow’s needs.
- Extensive knowledge of Cyber and Technology Risk Governance and Control frameworks/standards (i.e., COBIT 2019, ISO 27001, NIST CSF, ITL, etc.).
Skills
- Cyber and Technology Risk Governance
- Control frameworks/standards (COBIT 2019, ISO 27001, NIST CSF, ITL)
- Communication
- Collaboration
- Relationship building
- Risk analysis
- Talent development
Location
- Remote
Work Type
- Permanent
- Full Time
Experience Level
- 10+ years experience in a similar technology risk leadership position
- 5-10 years experience in varied senior security related leadership positions
- 5-10 years experience in the financial services industry or in a large organization
- 5-10 years experience within risk, compliance or governance specific to Information Services
Education Level
- CISSP certification would be an asset
- CISA certification would be an asset
- CISM certification would be an asset
- CRISC certification would be an asset
Salary/Compensations
- $175,000.00 - $225,000.00
Benefits
- Career Development opportunities
- Access to industry-leading learning programs
- $2,000 annually towards education reimbursement
- Flexible health and dental benefits
- $5,000 mental health benefit
- Volunteer day
- Company-matching pension plan
- Share ownership program
- Additional investment options
- Employee recognition programs
- Service milestone celebrations
- Employee discounts
About the Company
- Technology redefines the way we work and deliver to meet business needs and elevates the customer experience.
- We are part of an organization that is embracing modern technology, innovation and agile ways of working.
- Our Technology team is a strategic partner in our business – with an ambition to be a forward-thinking, agile technology organization delivering secure, resilient and leading solutions that support Canada Life and the well-being of millions of Canadians.
- We’re united by a shared purpose: to improve the financial, physical and mental well-being of Canadians.
- Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.
- We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other.
Equal Opportunity
- We’re committed to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact talentacquisitioncanada@canadalife.com. All information provided will be handled in accordance with applicable laws and Canada Life policies.
