Hybrid Director, Cyber Security Risk Oversight – Global Risk

Posted last month

Apply now

About the role

  • Lead the independent oversight of cybersecurity risks, ensuring robust alignment with Manulife’s standards and strategic objectives.
  • Provide expert guidance to uphold the integrity of the cybersecurity framework.
  • Collaborate with multidisciplinary teams to gain a comprehensive understanding of Manulife’s technology strategy, operations, and regulatory environment.
  • Proactively identify and assess areas of emerging and heightened risk related to information and cybersecurity.
  • Evolve and enhance Line 2 oversight frameworks to effectively manage and mitigate risks associated with information and cybersecurity, ensuring these frameworks remain agile and responsive to new challenges.
  • Oversee Line 1 risk, compliance, and operational metrics, and actively participate in the development and maintenance of Line 2’s information and cybersecurity risk measurement programs.
  • Ensure these metrics are comprehensive and support strategic risk management initiatives.
  • Conduct comprehensive and in-depth assessments of technology programs, particularly those with third-party dependencies, to ensure the safeguarding of organizational assets.
  • Utilize advanced risk assessment methodologies to identify vulnerabilities and implement effective mitigation strategies.
  • Execute independent and objective challenges to existing cybersecurity measures across critical risk domains, including Identity & Access Management, Cloud Security, Network Security and Data Security.

Requirements

  • 7-10 years in cybersecurity or technology risk management and/or First Line cybersecurity operations
  • Experience with critical security risk domains such as cloud security, network security, identity and access management, and third-party security
  • Commitment to continuous learning of cybersecurity risks, threat landscape, and best practices, with a focus on effective and efficient governance and oversight
  • Experience in developing enterprise policies & standards, conducting risk assessments, and a strong understanding of common risk frameworks, such as NIST Cybersecurity Framework and 800-53, ISO 27001/27002, and PCI DSS 4.0
  • Ability to work cross-functionally, aligning risk management with broader business strategies
  • Excellent verbal and written communication skills, with a focus on technical writing. Must be able to effectively convey complex risk concepts and insights to senior leadership and business collaborators.
  • Skilled in crafting clear and concise reports, presentations, and documentation to facilitate informed decision-making
  • Expertise in engaging with diverse collaborators to integrate their feedback into risk management practices
  • Ability to effectively manage crises related to cybersecurity risks, demonstrating resilience and adaptability
  • Keen interest in emerging technologies and innovations, with the ability to assess potential risks and opportunities.

Benefits

  • health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage
  • adoption/surrogacy and wellness benefits
  • employee/family assistance plans
  • various retirement savings plans (including pension and a global share ownership plan with employer matching contributions)
  • financial education and counseling resources
  • generous paid time off program in Canada (including holidays, vacation, personal, and sick days)
  • full range of statutory leaves of absence

Job title

Director, Cyber Security Risk Oversight – Global Risk

Job type

Experience level

Lead

Salary

CA$110,530 - CA$205,270 per year

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job