Full-Time

Director – Vendor Information Risk Management

Updated on 11/21/2024

Manulife

Manulife

Compensation Overview

CA$98.4k - CA$177.1kAnnually

+ Incentive Programs + Incentive Compensation

Senior

Kitchener, ON, Canada

Hybrid work arrangement requiring 3 days in office.

Category
Cybersecurity
IT & Security
Requirements
  • Bachelor's degree in related field.
  • 5 to 7 years of IT work experience, including 2 to 3 years IT auditing or equivalent experience.
  • CISA or CRISC preferred.
  • Working knowledge of financial services and technology operation.
  • Proven experience in technology audit, risk and/or compliance.
  • Effective communication, presentation, negotiation and influencing skills.
  • Identifies problems, proposes then executes solutions.
  • Communicates in a manner that is easily understood and actionable.
  • Assertiveness in a team environment.
  • Collaborates with key vendors, partners, and other teams.
  • Assumes ownership for deliverables and goals.
  • Improves current processes adding value and efficiencies.
  • Provides and exhibits an expert understanding of specific technical concepts and solutions.
  • Researches and investigates independently new issues and innovations to maintain currency of technical expertise.
  • Excellent organization and planning abilities.
  • Solid communication skills both written and oral.
  • Experience managing audit/compliance.
  • Understanding of controls, audit, and risk management.
Responsibilities
  • Responsible for the North America IS risk assessments of new and existing vendors working with Category Managers in Procurement, BU contacts and contract owners, BU security officers and business continuity analysts.
  • Perform on site visits of vendors as required.
  • Subject matter expert who assists business partners and IT colleagues to identify, quantify then manage their information security risks.
  • Assist in the development, maintenance, and implementation of information risk policies and procedures as well as the monitoring processes and measures to enforce those policies.
  • Contribute to the development of IS risk processes that support Global Information Risk Management objectives.
  • Perform contract reviews with Legal as appropriate.
  • Be part of an active team who remains current on emerging risks and technologies, key developments, and strategies for the businesses you support. Keep abreast of new thoughts, tools, and approaches.
  • Participate in key projects and initiatives ensuring information risk is always considered and managed.
  • Recommends risk management approaches to business that balance business needs with known risk tolerances.

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A