Talent.com
Fairstone Bank
Director, Internal Audit - Technology, Information Security, and AIFairstone Bank • Montreal (administrative region), QC, Canada
Director, Internal Audit - Technology, Information Security, and AI

Director, Internal Audit - Technology, Information Security, and AI

Fairstone Bank • Montreal (administrative region), QC, Canada
4 days ago
Salary
CA$125,000.00 yearly
Job type
  • Full-time
Job description

Who we are:

Fairstone Bank and its family of brands are united in delivering innovative, accessible and reliable financial solutions that enable Canadians to reach their goals. Over the years, our brand family has grown. In 2024, Home Trust Company, Home Bank and Oaken Financial became part of the Fairstone Bank family of brands, alongside Fairstone, Eden and Fig.

Together, we are the leading alternative lending bank in Canada. We have the collective experience and expertise to better serve our customers and foster our partners’ growth. With a diverse suite of products—residential and commercial mortgages, consumer deposits and GICs, credit cards, retail and automobile financing, personal loans and digital lending—we offer financial solutions tailored to all Canadians, including newcomers, small‑business owners, smart investors and savvy consumers.

Backed by nearly a century of lending experience through its legacy companies, Fairstone Bank and its brand family are proud to be Canada’s leading alternative lending bank.

About the role:

The Director, Internal Audit – Technology, Information Security, and AI leads the planning and delivery of risk‑based audits and advisory work across the Bank’s technology and digital risk domains. This role provides independence assurance over technology risks across ITGCs, cybersecurity governance, cloud governance, data management, AI, and technology operations. The Director is expected to exercise independent authority and credible challenge with senior technology leaders including the Chief Technology Officer (CTO) and their leadership team ensuring that technology risks, control gaps, and remediation commitments are appropriately identified, debated, and addressed.

The role requires sufficient technical knowledge and professional competence to engage in difficult, sometimes adversarial conversations with technology leadership, while maintaining a constructive, respected, and independent relationship. Co‑sourced SMEs may support deep technical assessments; however, the Director must independently interpret results, synthesize risk implications, and challenge management where standards or practices are insufficient.

Responsibilities:

Risk Assessment & Strategy Planning (20%)

  • Own and maintain the technology audit universe for core domains: Technology Strategy, Data, and AI, Technology Integration, Software Engineering, Digital Services, Technical Services & Performance, Technology Operations, and Information & Cyber Security.
  • Maintain awareness of technological changes in both external and internal environments including trends in risk management practices and regulatory expectations, and changes in business activities to perform quarterly risk assessments for the technology audit entities within the Internal Audit Universe.
  • Lead the annual technology risk assessment, identify appropriate audits to be included in the annual audit plan and help develop the Plan for the Audit Committee approval.
  • Identify emerging risks within the Technology audit portfolio (e.g., cyber threats, cloud adoption, data privacy), monitor these risks to determine their impact, and assess changes needed for the annual audit plan or planned audits. Incorporate changes as appropriate.

Audit Plan Execution and Delivery (50%)

  • Oversee execution and end‑to‑end delivery of all audit projects within the Technology audit universe, ensuring all documentation and audit reports are complete, and projects are appropriately and effectively staffed. Coordinate use of co‑sourced technical experts for deep cyber/cloud/AI testing where needed.
  • Lead opening and closing meetings, ensuring audit project planning is appropriately completed, reviewing audit working papers, and preparing/reviewing draft internal audit report for each project. Review control design and effectiveness using industry frameworks (NIST CSF, ISO 27001, COBIT).
  • Deliver balanced and insightful reporting to the Chief Internal Auditor and Audit Committee on technology risk posture, themes, and systemic gaps.
  • Oversee remediation/closure of IT audit findings, OSFI findings including tracking closure to due dates, the validation of findings with management, ensuring appropriate responses are received, and appropriate quality assurance practices are followed.
  • Provide independent advice during major technology initiatives (policy& standards enhancements, modernization, cloud migration, data platform enhancements) from governance and risk lens and collaborate with stakeholders to embed controls early.

Leadership & Stakeholder Management (20%)

  • Develop and maintain independent and influential relationships with senior technology stakeholders, including the CTO, CISO, Data & Privacy leadership, and enterprise risk partners (i.e., ERM, ORM, Compliance).
  • Develop and maintain working relationships with the Bank’s external auditors to support their direct assistance and or audit reliance model.
  • Demonstrate the authority, credibility, and technical understanding necessary to challenge technology decisions, risk acceptances, and control deficiencies especially in areas where management believes risks are mitigated.
  • Facilitate difficult discussions with technology leadership by articulating risk impacts, regulatory expectations, and control considerations in a clear and authoritative manner.
  • Lead a team of IT audit professionals with a mix of internal capabilities and co‑sourced specialists.
  • Mentor team members to deepen expertise in ITGCs, cyber governance, and foundational cloud/data risks.

Standards, Methodology & Tools (10%)

  • Ensure all technology audit work adheres to the Global Internal Audit Standards (GIAS) and Internal Audit methodology. Contribute to annual review of audit practices and methodology against relevant benchmarks.
  • Map controls to recognized frameworks as appropriate: NIST CSF/800‑53, ISO 27001/27701, COBIT, CIS Controls, CSA CCM, PCI DSS (if applicable), and applicable privacy regulations. Recommend changes to audit processes, methodology and reporting to improve effectiveness.
  • Champion continuous improvement, agile auditing methods, and data‑driven audit techniques (CAATs, automation, scripts, and continuous monitoring).
  • Promote tooling: GRC, ticketing/ITSM (e.g., ServiceNow), CI/CD, CSP native security tooling, CSPM/CWPP, SIEM/SOAR, data lineage/governance tools, and model monitoring platforms.

What we’re looking for:

Formal Education:

  • University degree in information systems, Computer Science, Engineering, Accounting, or related field.
  • Certified Information Security Audit designation.
  • Certifications in the following are preferred:
  • Audit: CIA, Risk: CRISC, CGEIT, Security: CISSP, CISM, CCSP, ISO 27001
  • Cloud: AWS/Azure/GCP security or architecture certifications
  • Data/Privacy: CDMP, CIPT/CIPM/CIPP, ISO 27701

Related Experience:

  • 10+ years of progressive experience within the Financial Services Industry.
  • Solid Information Technology (IT)/Information Security (IS) audit and/or similar management experience in a regulated financial institution.
  • Strong experience leading audits of information technology, information security, data management, and project management, in conformance with IIA Standards.
  • Excellent understanding of risk management and related governance concepts, tools, techniques and best practices gained from practical financial services experience.
  • Strong command of at least three of the following: ITGCs, cybersecurity operations, cloud security/ governance, data governance/quality/privacy, SDLC/DevSecOps, AI/ML governance/model risk.

Skills:

  • Strong understanding of the Bank’s risk tolerance, risk management, & risk assessment activities.
  • Technical auditing proficiency in a regulated financial services environment, including strong analytical risk assessment and problem‑solving skills.
  • Ability to counsel and advise on complex risk situations affecting the organization, within the context of audit assignments, including recommendations on related risk management.
  • Excellent communication, decision making, time management, negotiation, and influencing skills.
  • Leads and demonstrates knowledge, teamwork, cross‑unit cooperation and information and consistently demonstrates and reinforces organizational values.
  • Solution‑focused and takes initiative ensuring self and team work effectively and efficiently within established guidelines.
  • Ability to lead a strategic and progressive approach to provide value‑added recommendations to leaders across the Bank.

What you’ll love about working here:

  • Award‑Winning Culture: We’re proud to be recognized as one of Canada’s Top 100 Employers.
  • Work‑Life Balance: Enjoy flexibility with our hybrid work model designed to support your lifestyle.
  • Time to Recharge: Generous vacation based on your role, statutory holidays, plus 6 wellness days to prioritize your well‑being.
  • Compensation Package: Competitive base salary plus an annual incentive bonus tied to performance.
  • Comprehensive Benefits: Robust health and dental coverage through Manulife, as well as virtual healthcare through Dialogue.
  • Future‑Ready Savings: Group Retirement Savings Plan with up to 7% employer match.
  • Exclusive Perks: Discounts from top retailers via WorkPerks, plus location‑based perks like gym memberships and Toronto Bike Share.
  • On‑Site Fitness: Gym access at our London and Montreal offices.
  • Continuous Growth: Education Assistance Program and Fairstone Academy for training and skill development.
  • Family Support: Parental leave top‑up program to help you during life’s big moments.
  • Community Impact: One paid volunteer day to give back to causes that matter to you.

What you can expect - pay & process:

  • Expected base salary range is $125,000 - $150,000, plus the opportunity to earn an annual incentive bonus tied to performance.
  • This posting is for an existing vacancy within our organization.
  • Artificial intelligence may be used in parts of the recruitment process.
  • All candidates considered for hire must successfully pass a criminal background check, credit check, and validation of their work experience to qualify for hire.
#J-18808-Ljbffr
Create a job alert for this search

Director, Internal Audit - Technology, Information Security, and AI • Montreal (administrative region), QC, Canada

Similar jobs

IT Internal Audit Lead – Integrated Systems

Intact Financial CorporationMontreal
Full-time

A leading financial services company in Montreal is seeking an IT Internal Audit Assistant Manager to join their team.This role focuses on evaluating IT security controls within business systems.Id... Show more

 • Promoted

Manager of Enterprise Risk Services in Internal Audit and Compliance

MNPMontreal (administrative region), QC, CA
Full-time

Spearhead enterprise risk solutions as a Manager of Internal Audit.Your impactful role will shape effective strategies that protect assets and enhance financial reporting reliability for clients.Th... Show more

 • Promoted

Director, Internal Audit

PSP’s Private Debt & Credit Investment (PDCI) groupMontreal (administrative region), QC, CA
Full-time

We’re seeking a Director, Internal audit to partner with key stakeholders and peers to support and engage with our powerful networks of people, opportunities, and investments.At PSP, we embrace peo... Show more

 • Promoted

Director of Product Security Architecture — Lead Secure AI

GitLabMontreal (administrative region), QC, CA
Full-time

A leading tech company is seeking a Director, Product Security Architecture to manage a team and oversee the security architecture strategy, focusing on risk reduction across their products.The ide... Show more

 • Promoted

IT Lead Auditor

Crédit Agricole CIBMontreal, Montreal (administrative region), CA
Full-time

Join to apply for the IT Lead Auditor role at Crédit Agricole CIB.The Lead Auditor / Vice President – Montreal Team Lead conducts IGE (Inspection Generale / Internal Audit) Americas audits supporti... Show more

 • Promoted

Cybersecurity Director – Transformation Initiatives

CoFoMo Inc.Montreal
Full-time

Elevate transformation projects as a Cybersecurity Director.Define and implement essential governance frameworks to mitigate LLM risks while ensuring regulatory compliance in a hybrid environment.A... Show more

 • Promoted

Director Of Internal Controls And Enterprise Risk Management

Groupe Dynamite Inc.Mount Royal, Canada
Full-time

Shape financial governance as the Director of Internal Controls.Lead the compliance with Regulation 52-109 while enhancing our Enterprise Risk Management framework in a critical leadership position... Show more

 • Promoted

Director, IT Infrastructure Innovation

BRPMontreal, QC, Canada
Full-time

We are looking for a Director, IT Infrastructure Innovation who will report to the Senior Director, IT Operations and Infrastructure.The Director plays a leading role in the modernization, automati... Show more

 • Promoted

Director of Internal Control to Enhance Risk Management Framework

Groupe Dynamite, Inc GarageMount Royal, Montreal (administrative region), CA
Full-time

Shape the internal control landscape as the Director of Internal Control.Ensure compliance and risk strategies align with industry standards and business objectives.In this essential role, you will... Show more

 • Promoted

Director, It Audit — Lead Ti Team In Montréal

LaotopMontréal, Canada
Full-time

Une entreprise de services professionnels recherchée un directeur ou directrice pour le poste d'Audit TI à Montréal.Ce rôle nécessite une forte compétence en auditorat TI et un diplôme de compt... Show more

 • Promoted

Lead It Audit & Tech Risk Director

Crowe BGKWestmount, Canada
Full-time

Une entreprise de services professionnels recherche un(e) directeur(rice) principal(e) pour l'audit des systèmes d'information et risques technologiques à Westmount.Le candidat idéal possèd... Show more

 • Promoted

Director, Product Management – Assurance (Global role – in a virtual working environment) -

Grant Thornton International Ltdsaint-esprit, qc, ca
Full-time

Grant Thornton is one of the world’s leading professional services networks with member firms in over 150 countries, 80,000 people and global revenues of $8.Member firms offer audit, tax, and advis... Show more

 • Promoted

Director of Governance and Internal Controls

PwC CanadaMontreal (administrative region), QC, CA
Full-time

Lead governance and regulatory functions as a Director specializing in Internal Audit.Utilize expertise in internal controls to proactively address organizational risk and enhance stakeholder engag... Show more

 • Promoted

Innovation Senior Director

Banque Nationale du CanadaMontreal (administrative region), QC, CA
Full-time

A career as a Senior Innovation Manager in the Information Security (CTO) team at National Bank means acting as a strategic leader who accelerates organisational performance by orchestrating automa... Show more

 • Promoted

Director of AI

People In AIsaint-esprit, qc, ca
Full-time

Director, AI / ML (Applied AI & Agentic Systems).A scaled, product-led technology company operating at the intersection of data, AI, and vertical SaaS—focused on transforming how complex, real-worl... Show more

 • Promoted

Director, Enterprise Risk Management

ML6 Search + Talent Advisorysaint-esprit, qc, ca
Full-time

Our client, a rapidly growing insurance organization, is seeking a strategic and collaborative Director of Enterprise Risk Management (ERM) to lead and evolve the organization’s enterprise-wide ris... Show more

 • Promoted

Director, Internal Audit - Technology, Information Security, and AI

Fairstone BankMontreal (administrative region), QC, CA
Full-time

Fairstone Bank and its family of brands are united in delivering innovative, accessible and reliable financial solutions that enable Canadians to reach their goals.Over the years, our brand family ... Show more

 • Promoted

Senior Internal Audit Director Opportunity

nestoMontreal
Full-time

Establish and lead an impactful Internal Audit function.Drive risk-based assurance initiatives in collaboration with senior stakeholders to foster business success.In this role, you will be respons... Show more

 • Promoted

Director Internal Audit with Technology Focus

PSP Investments | Investissements PSPMontreal
Full-time

Become the Director of Internal Audit, emphasizing technology and digital transformation.Handle audit programs and recommend improvements in a flexible hybrid workspace.In this strategic role, you ... Show more

 • Promoted

Transformational VP, Internal Audit for Operational Excellence

Coastal Community Credit UnionMontreal (administrative region), QC, CA
Full-time

Lead transformational changes in governance and risk management as the VP of Internal Audit.Utilize your vast experience to enhance organizational effectiveness in a cooperative setting.In this lea... Show more