Director of Cyber Risk Governance overseeing cybersecurity and regulatory compliance at Manulife. Ensuring adherence to global regulations while enhancing cybersecurity governance practices.
Responsibilities
Lead the independent oversight of cybersecurity risks, ensuring alignment with Manulife’s standards and strategic objectives
Conduct independent assessments against industry frameworks such as NIST and SWIFT
Oversee and challenge adherence to cybersecurity regulatory requirements
Ensure accurate interpretation and compliance by first-line teams with global regulators including OSFI, SEC, HKMA, MAS, and others
Stay current on emerging technologies and regulatory changes to maintain a robust cybersecurity posture
Collaborate across first and second lines of defense to develop and report on Key Risk Indicators (KRIs)
Support leadership in preparing board-level cybersecurity materials, offering actionable insights on cyber and emerging risks, data security and operational resilience
Partner with the Information Risk team to drive oversight roadmaps and strategies
Ensure efficient and effective processes are in place to provide comprehensive coverage across the enterprise
Identify opportunities to enhance governance practices, improve oversight maturity, and strengthen risk management capabilities.
Requirements
7–10 years in cybersecurity risk management
Strong technical acumen across domains such as identity and access management (IAM), cloud security, network security, and data protection
Experience with performing cyber due diligence over mergers and acquisitions
Experience with designing, implementing and running data protection capabilities including DLP and insider threat prevention
Experience in different aspects of cyber operations including incident response, threat intelligence/detection, red/blue/purple teaming and threat hunting
Demonstrated ability to provide strategic oversight, challenge and governance in cybersecurity risk management
Experience interpreting and governing cybersecurity regulations from bodies such as OSFI, SEC, HKMA, MAS, and SWIFT
Strong understanding of industry recognized frameworks including NIST CSF, ISO27001/27002 and PCI DSS
Demonstrated ability to conduct technical cybersecurity assessments against regulatory and industry standards
Ability to analyze cybersecurity trends and emerging risks to identify opportunities for improving the organization’s security posture
Experience building out strategies and roadmaps related to cybersecurity governance
Strong relationship-building skills with the ability to influence and build credibility across diverse stakeholder groups
Excellent verbal and written communication skills, with the ability to produce high-quality deliverables for executive and board-level audiences.
Senior Regulatory Specialist managing regulatory activities for pharmaceutical CMC projects. Collaborating with diverse teams and ensuring timely delivery of regulatory documentation and compliance.
Director of Regulatory Affairs leading drug product regulatory strategy and team management. Ensuring compliance and managing communication with FDA and regulatory bodies in a pharma environment.
Senior Project Engineer focusing on GMP Compliance in the Life Sciences sector. Responsible for project planning, execution, and client communication in Mannheim, Germany.
Senior Consultant managing Compliance projects in the medical devices sector with a focus on Quality & Regulatory. Collaborating with a dynamic team in a leading GMP - expert company.
Regulatory CMC Manager supporting multi - product global regulatory CMC for products at Marketing Authorisation Application Stage. Focused on documentation preparation, submissions, and providing regulatory support.
Manage Vodafone's satellite communications policy and regulations while collaborating with teams. Engage in strategic initiatives and develop regulations to support satellite ambitions.
Compliance Analyst managing fraud prevention strategies and governance in Brazil's iGaming sector. Ensuring compliance with regulations and internal policies in a dynamic environment.
GRC Consultant implementing governance, risk, and compliance projects for cybersecurity at Redbelt Security. Evaluating processes and recommending improvements to enhance cybersecurity effectiveness.
Customs Compliance Engineer focusing on customs classification and supporting import/export activities at Universal Robots. Collaborating with teams in Denmark and maintaining classification codes.