Cyber Security Risk and Controls Manager
Eq Bank
Join a Challenger
Being a traditional bank just isn’t our thing, so we challenge ourselves to get creative in providing innovative banking solutions for Canadians.
How do we get there? With a talented team of inquisitive and agile challengers that break through the status quo. So, if you’re passionate about redefining the future of banking—while having fun—this could be your next big opportunity.
Our company continues to grow, and today we serve more than 670,000 people across Canada through Equitable Bank, Canada's Challenger Bank™, and have been around for more than 50 years. Equitable Bank's wholly-owned subsidiary, Concentra Bank, supports credit unions across Canada that serve more than six million members. Together we have over $125 billion in combined assets under management and administration, with a clear mandate to drive change in Canadian banking to enrich people's lives. Our customers have named our EQ Bank digital platform ( eqbank.ca ) one of the top banks in Canada on the Forbes World's Best Banks list since 2021.
The Purpose of Job
The Cyber Security Risk & Controls Manager is responsible for developing, implementing, and enhancing the bank’s information security risk management framework, with a specific focus on control assurance, cyber risk assessments, with a particular focus on third-party (vendor) risk management.
This role serves as a subject matter expert (SME) for security risk across business units, technologies, and third-party engagements, helping to protect the organization against emerging cyber threats while enabling business resilience and regulatory compliance.
The core parts of your role would be to:
- Manage & lead the identification, assessment, and management of cyber and information security risks across the organization.
- Own and lead the third-party cyber risk assessments, including onboarding assessments, projects, contract reviews, continuous monitoring, and breach response coordination.
- Perform security risk assessments of new or existing services, applications, technologies and vendors. Documents and effectively communicates findings to key stakeholders.
- Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments, and any other relevant areas for existing services and third-party vendors.
- Partner with Procurement, Legal, and Business Units to embed security requirements into onboarding and vendor lifecycle processes.
- Support internal and external audits, regulatory exams, and compliance reviews, ensuring timely evidence collection and response.
- Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology/security threats against the bank.
- Maintain a third-party risk scoring model and threat intelligence integration to proactively identify and mitigate supplier risks.
- Oversee the cyber risk register, KRI metrics ensuring risks are accurately captured, monitored, and reported to senior management.
Let's Talk About You!
- Bachelor’s or Master’s degree in Cybersecurity, Information Technology, Risk Management, or related field.
- At least eight (8) years of information security and information risk experience.
- At least four (5) years of third-party risk management experience (including hands-on experience conducting third party risk assessments)
- Understanding of Cloud Shared responsibility models and risk mitigation approach/techniques.
- Experience in performing organization-wide/entity security risk assessments or audits is required.
- Understanding and experience with security compliance frameworks such as PCI DSS, BSIMM, Cloud Security Alliance, NIST, ISO 27K series is required.
- Understanding of Canadian Financial industry regulations relevant to third-party security and privacy expectations E.g. OSFI, OPC
- The following certifications are preferred: CCSP, CCSK, CISM, CISSP, CISA, or CRISC.
- Experience working in a banking or financial services environment is an asset.
What we offer [For full-time permanent roles]
Competitive discretionary bonus
✨ Market leading RRSP match program
Medical, dental, vision, life, and disability benefits
Employee Share Purchase Plan
Maternity/Parental top-up while you care for your little one
Generous vacation policy and personal days
Virtual events to connect with your fellow colleagues
Annual professional development allowance and a comprehensive Career Development program
A fulfilling opportunity to join one of the top FinTechs and help create a new kind of banking experience
Equitable Bank is deeply committed to inclusion. Our organization is stronger and our employees thrive when we honour and celebrate everyone’s diverse experiences and perspectives. In tandem with that commitment, we support and encourage our staff to grow not just in their career path, but personally as well.
We commit to providing a barrier-free recruitment process and work environment for all applicants. Please let us know of any accommodations needed so that you can bring your best self to the application process and beyond. All candidates considered for hire must successfully pass a criminal background check and credit check to qualify for hire. While we appreciate your interest in applying, an Equitable recruiter will only contact leading candidates whose skills and qualifications closely match the requirements of the position.
We can’t wait to get to know you!
$118k - $152k per year
...The Role We are seeking an experienced Technology Controls & Cyber Security leader to join our Technology & Engineering practice in Toronto.... ...senior stakeholders to strengthen security governance, technology risk management, and cyber resilience across complex technology environments...RiskLong term contractInternshipImmediate start- ...billion in combined assets under management and administration, with a clear mandate... ...planning and executing the bank’s Cyber Resilience Testing and offensive security program, commonly referred to as “... ...presentation of technical cyber control effectiveness to key stakeholders....SuggestedHourly payPermanent employmentFull timeWork at office
$85k - $156k per year
...What will your typical day look like? The Technical Cyber Risk Assessment Manager will be responsible for the following: Perform in‑depth... ...infrastructure, applications, and platforms. Validate actual control effectiveness by reviewing live configurations, security...RiskPermanent employmentFlexible hours$81.13k - $141.24k per year
...organization, apply now. We are currently seeking a Cyber Risk Consultant - Financial Services - Remote to join our team... ...professional with deep expertise in cyber risk management, Business Information Security Office (BISO) operations, and emerging AI governance practices...RiskLong term contractTemporary workWork at officeRemote workFlexible hours- ...AI Cybersecurity Architect | GenAI Security | Cloud Security | Cyber Risk | AI Governance | Banking Job Description Role Summary Cybersecurity... ...• Cyber analytics • Define and enforce security controls for AI/GenAI platforms, including: • Model security...RiskPermanent employment
$120k - $135k per year
...The Role: OpenTable's Finance team is looking for a Manager, IT Risk and Controls! The Manager, IT Risk & Controls is a leadership role responsible... ...is to ensure OpenTable’s systems, processes, and data are secure, compliant with regulatory and corporate requirements, and...RiskFull timeWork at officeLocal areaFlexible hours2 days per week- ...About the Role As a Senior Leader within Capco’s Cyber Risk Management practice, you will be driving the growth, delivery, and innovation... ...access management, vulnerability management, application and data security, and third-party risk. Ensure project delivery aligns with...RiskImmediate start
- ...record of streamlining identity Lifecycle management. Configure and deploy SailPoint... ...applications. Implement and maintain access control policies, role-based access controls (RBAC... ...the functionality, performance, and security of IAM solutions. Troubleshoot and resolve...Full time
$142k - $160k per year
...to celebrate your contributions. The Job: Cyber Security Engineer What You’ll Do Reporting to the Senior Manager, Cyber Operations , the Cyber Security Engineer... ...and continuously improving enterprise security controls and capabilities across multiple security...RiskTemporary workWork at officeRemote work$70 - $90 per hour
...Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. Apply expertise in systems...Full timeContract workSummer workRemote workFlexible hours- ...142 billion in combined assets under management and administration, with a clear mandate... ...The Work The Senior Analyst - Cyber Threat Modeling and Risk supports the Threat Modeling and Risk... ..., assessment, and tracking of cyber security risks across technology. The role...RiskHourly payPermanent employmentFull timeWork at office
- ...You should be searching for a hands-on cyber security expert / systems engineer with an understanding... ...Should be able to deep enough into risk analysis Have strong hands-on operational... ...: Governance focused PM/Team Manager or High-level architecture backgrounds...RiskFull time
$115 per hour
...client on Public Sector. we are looking for contract S enior Cyber Security Specialist Duration : 12 month Experience required: ~... ..., including SOC 2 Type 2. ~ Extensive knowledge in cyber risk management frameworks, conducting threat risk assessments, and recommending...RiskHourly payFull timeContract workFor contractorsFixed term contractRelocationShift work$90 per hour
...Job Responsibility: This role will require contractors to come onsite for occasional meetings.This is a new security modernization project from OPS. They will be reviewing vendor security.They will need to have experience reviewing SOC 2 Type 2 documentation and writing recommendations...Hourly payFull timeFor contractorsFixed term contractRelocationMonday to friday- ...Security Architect (Cybersecurity, Cloud Security, Risk Management, NIST, CISSP) Location: Toronto, ON - Hybrid (4 Days WFO) Role Descriptions: Team Description... ...to advance technology and third-party information/cyber risk management capabilities that enable the Fund...RiskPermanent employment
$80 per hour
...looking to hire Consultant - Technology & Cyber Security Audit for their team with a contract for... ...assessment, testing and validation of controls and will be required to document your effective... ...opinion. You will be responsible for managing completeness of scope, execution...RiskPermanent employmentContract workWork at office$82.22k - $119.5k per year
...were recently confirmed and dates for implementation of the new salary rates are still to be determined. Are you experienced in Risk Management for Capital Markets? The Ontario Financing Authority (OFA) is seeking a motivated professional to provide senior-level, highly specialized...RiskPermanent employment$110k - $160k per year
...world. The Opportunity The Tech Risk-SAP GRC team within EY’s Business Consulting... ...looking for a dynamic person in the SAP Security, Controls, and SAP GRC space. This candidate will... ...transformation Strategic risk management Enterprise Governance, Risk and Control...RiskFlexible hoursWeekend work$120k - $160k per year
...Benefact Group , are looking for a Senior Risk Control Specialist to join our Toronto office... ...to work across multiple areas of risk management. You'll conduct in-person and virtual... ...fire protection programs, construction, security, etc.) A minimum of 7 years of related...RiskRemplacementPermanent employmentWork at officeHome officeMonday to friday$100.71k - $125.92k per year
...Role impact: The Senior Manager Information Security Risk & Governance leads the Information Security Risk Management and Governance programs. Their... ...; document and monitor the implementation of security controls and adjust risk rating accordingly Develop maintain and...RiskFull time$85k - $156k per year
...In this role, you will focus on managing and mitigating risks within the business. Your day will revolve... ...contractual obligations and practical risk management. This is a strategic position aimed... ...we ensure that our operations remain secure and efficient. Join a team that...RiskPermanent employmentContract workFlexible hours- ...design, and implement AI strategies that are secure, scalable, and human-centered. We believe... ...you inherit a legacy infrastructure, manage a large team, and maintain the status quo.... ...names, and develop response frameworks for risks unique to agentic AI — things like prompt...RiskFull timeFor contractorsInternshipRemote workDay shift
$85k - $156k per year
...typical day look like? This role is within the Technology Control Management Team and reports to the Control Management Team Leader. You... ...operate within a dedicated team to deliver technology and cyber security control processes using integrated risk management tools (extensively...RiskPermanent employmentFlexible hours- ...Who we are looking for: Credit Operations is looking for a dynamic, influential, and results-driven leader to be the next Manager, Risk Policy. You will lead the ongoing implementation of the Risk Scorecard and measuring performance of the predictive model. This...RiskFull timeContract workWork at officeFlexible hoursShift work
$85k - $156k per year
...typical day look like? Deloitte Global is seeking a Manager to join the Global Independence team within Global Risk & Brand Protection – a high-impact position... ...areas of risk management, confidentiality & privacy, cyber security oversight, regulatory, independence & conflicts,...RiskPermanent employmentRemote workFlexible hours$140k - $260k per year
...the role for you. What will your typical day look like? As a member of the leadership team you will spend your time helping manage the risk for the service line. This will involve assisting with strategic initiatives for the Risk Team to help drive for better...RiskPermanent employmentFlexible hours- ...This is a remote position. Senior Cyber Security Specialist-Offensive Security Location: Remote (Canada)... ...Work with engineering teams on remediation and secure SDLC Provide clear technical risk analysis and reporting Required Skills ~10+...RiskFull timeContract workRemote work
$207k - $253k per year
...how to be great with money—bringing clarity, confidence, and control to every dollar earned, so they can turn hard work into lasting... ...exciting phase of growth, and we’re hiring an Engineering Manager for the Risk team to help scale what comes next. You’ll be making high-impact...RiskFull timeInternship$126k - $234k per year
...-- What will your typical day look like? As a Senior Manager in People Risk, you will work collaboratively within a high-performing Enterprise... ...of strategy, governance, policies, processes, and controls related to people risk, and tailoring approaches to the client...RiskPermanent employmentFlexible hours$89.34k - $132.88k per year
...Division & Section: Corporate Real Estate Management, Business Management Work Location:... ...Toronto objectives.The Quality Assurance and Risk Management (QARM) Unit supports CREM by assessing... ...of business processes and internal controls, supporting internal and external audits,...RiskLong term contractFull timeContract workTemporary workInternshipWork at officeMonday to fridayShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Risk and Controls Manager. Be the first to apply!
- manager cyber security Toronto, ON
- group risk manager Toronto, ON
- senior manager risk management Toronto, ON
- operational risk manager Toronto, ON
- credit risk Toronto, ON
- risk and insurance manager Toronto, ON
- cybersecurity sales engineer Toronto, ON
- spécialiste en sécurité informatique Toronto, ON
- remote cyber security Toronto, ON
- entry level cyber security Toronto, ON
