Director, Technology & Cyber Control Testing
Core
Lead the execution and continuous evolution of the first-line Technology & Cyber Control Testing Program to provide independent assurance over technology and cyber controls.
Role type
Director, Technology & Cyber Control Testing
Builds
Scalable, risk-based control testing function and operating models for the Digital Business & Technology Solutions organization.
Domain
Financial Services / Technology Risk & Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Technology risk management, Cybersecurity controls, IT general controls, Cloud security, Identity and access management, Change management, Vulnerability management, Incident management, Operational resilience, Third-party technology risk, Data protection, Regulatory frameworks (OSFI, NIST, COBIT, ISO 27001, CIS, DORA), Team leadership, Executive communication, Risk-based testing strategy, Quality assurance frameworks, Remediation validation
Preferred skills
Data analytics, Visualization tools, Workflow automation, GRC platforms
Technologies
OSFI B-13, OSFI E-21, NIST Cybersecurity Framework, COBIT, ISO 27001, CIS Controls, DORA, SOC reporting frameworks
Responsibilities
Develop multi-year testing strategies aligned to business and regulatory risks, Oversee end-to-end control testing lifecycle including planning and remediation validation, Build scalable testing operations and automation opportunities, Establish quality assurance frameworks and calibration programs, Translate testing results into executive-level risk intelligence, Manage issues and partner with leaders to drive remediation, Recruit and mentor a high-performing testing team
Seniority
Director, strategic leadership & team management
