Talent.com
Community Trust Company
Principal, IT & Cyber Governance, Risk and ControlCommunity Trust Company • Winnipeg, Canada
No longer accepting applications
Principal, IT & Cyber Governance, Risk and Control

Principal, IT & Cyber Governance, Risk and Control

Community Trust Company • Winnipeg, Canada
7 days ago
Salary
CA$115,000.00 yearly
Job type
  • Permanent
Job description
Principal, IT & Cyber Governance, Risk and Control

5700 Yonge St, North York, ON M2M 4K2, Canada Job Description

Questrade Financial Group (QFG) , through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure. At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work. Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG. What’s in it for you as an employee of QFG? Health & wellbeing resources and programs Paid vacation, personal, and sick days for work-life balance Competitive compensation and benefits packages Work-life balance in a hybrid environment with at least 3 days in office Career growth and development opportunities Opportunities to contribute to community causes Work with diverse team members in an inclusive and collaborative environment This job posting is for an existing vacancy. We’re looking for our next Principal, IT & Cyber Governance, Risk and Control. Could It Be You? The Principal, IT & Cyber Governance, Risk and Control is a senior, expert-like role in the IT & Cyber GRC team. The Principal has the primary responsibility for managing Audit & Regulatory as well as Control Assurance activities, ensuring technology and cyber operations meet rigorous internal policies and external compliance standards, notably SOC 2, SOC 1, and other key frameworks in addition to regulatory requirements (OSFI, CIRO, etc). The role involves driving strategic framework implementation, and spearheading complex risk and control assessments. A critical component is serving as the primary liaison for all audit and attestation engagements, and providing IT & Cyber GRC counsel to high-priority technology projects to ensure security controls are effective and compliance is maintained by design. This position requires in-depth knowledge of technology, cybersecurity, emerging threats and evolving regulatory requirements to proactively manage technology and cyber risk. In this role, responsibilities include but are not limited to: Lead the continuous monitoring and coordination of control-evidence collection and assurance, leveraging automation and innovative GRC solutions to streamline these processes, while also spearheading complex, high-impact control risk assessments and assurance reviews for critical existing IT & Cyber processes and all new strategic initiatives. Drive the strategic design, implementation, and rigorous testing of technology & cybersecurity controls in deep partnership with cross-functional teams to achieve and maintain compliance with target frameworks (e.g., SOC 2, SOC 1, OSFI B-13). Lead all regulatory compliance-related initiatives, including conducting formal gap assessments against control frameworks (e.g., SOC 1 & SOC 2 readiness, OSFI B-13, etc) for new and existing policies and technologies. Manage and serve as the primary point of contact for all internal, external, and regulatory audit and attestation engagements ensuring successful evidence submission and positive assurance outcomes. Take ownership of and execute complex, ad‑hoc, high‑priority activities that require immediate control implementation or assurance validation due to emerging threats or critical business needs. Maintain and actively apply a thorough, expert-level understanding of core GRC Frameworks (SOC 2, ISO 27001, etc.) to strategically and effectively drive control implementation and assurance activities. Maintain expert subject matter knowledge and awareness of new and pending legislative, legal, and statutory changes as they translate into new or updated control requirements across GRC frameworks. Act as a trusted advisor in technology and cyber projects as well as working groups, providing expert GRC counsel on best practices and mandatory requirements during the entire product development and deployment lifecycle. So are YOU our next Principal, IT & Cyber Governance, Risk and Control? You are if you… 5 to 7 years of experience in Information Technology, Cyber Security, Internal Audit, Risk Management and/or Compliance in a financial institution. 3 to 5 years of hands‑on information technology or security operations experience. Holds one or a combination of CISA, CRISC, CISM, CGEIT or equivalent. Knowledge and experience working with data, security, compliance and privacy laws in the Canadian investment and banking industry. Experience writing or updating IT and Security procedures. Experience building key performance and risk indicator dashboards for different management levels. Experience with assessment and review of SOC 1 and 2 reports. Knowledge of a broad set of industry best practices (COBIT, ITIL, NIST CSF, Cloud CSC, Agile SAFE, PCI-DSS, etc.) Exposure to financial industry business processes. Exposure to enterprise and operational risk principles and practices. Exposure to risk scenario analysis, risk quantification and loss event modeling. Experiences with using compliance automation tools. Attributes Strong written, oral communication and interpersonal skills. Ability to communicate with individuals at all levels of the organization. Highly curious, self‑motivated and directed. Proven Governance, Risk and Control knowledge. Strong attention to detail and proven analytical and problem‑solving abilities. Ability to effectively prioritize and execute tasks in a high‑pressure environment. Experience working independently and a team‑oriented, collaborative environment. Ability to conduct research and present insights succinctly. Compensation Information Base salary range: $115,000 - $135,000 The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full‑Time Permanent roles. Sounds like you? Click below to apply! At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us. Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs. 5700 Yonge St, North York, ON M2M 4K2, Canada

#J-18808-Ljbffr
Create a job alert for this search

Principal, IT & Cyber Governance, Risk and Control • Winnipeg, Canada

Similar jobs

IT Governance Analyst Focused on Improvement and Stakeholder Engagement

Price Industries LimitedWinnipeg, MB, CA
Full-time

Transform IT governance as a hands-on Analyst.Emphasize collaborative practices, process improvement, and stakeholder partnerships while thriving in an on-site role in a progressive environment.As ... Show more

 • Promoted

Director of Enterprise Architecture at WCLC

Western Canada Lottery Corporation (WCLC)Winnipeg, MB, Canada
Full-time

Lead the technology strategy at WCLC as the Director of Enterprise Architecture.Drive innovation and ensure long-term sustainability through a strategic collaboration with business leaders.In this ... Show more

 • Promoted

Remote Principal Architect — Cybersecurity Strategy

Palo Alto NetworksWinnipeg, MB, CA
Remote
Full-time

A cybersecurity technology leader in Toronto is looking for a Principal Architect to influence client cybersecurity strategies.This role involves establishing relationships with executives, deliver... Show more

 • Promoted

Lead Cyber Risk Advisor at Malleum

MalleumWinnipeg, MB, CA
Full-time

Take on the role of Lead Cyber Risk Advisor at Malleum to shape outstanding governance and compliance strategies.This remote position involves strategic engagements across national security sectors... Show more

 • Promoted

Senior IT Asset Governance & Optimization Lead

Marqeta, Inc.Winnipeg, MB, CA
Full-time

A leading fintech company based in Canada is seeking an experienced Manager of Asset Management to oversee technology asset governance and lifecycle management programs.This role includes establish... Show more

 • Promoted

Project Manager for IT Governance at Stantec

StantecWinnipeg, MB, CA
Full-time

Manage impactful IT projects with Stantec in Edmonton, Alberta.This role focuses on governance adherence, project management, and stakeholder communication in a full-time capacity.At Stantec, the S... Show more

 • Promoted

Senior Risk & Controls Consultant at FCC

FCC / FACWinnipeg, MB, CA
Permanent

Step into the role of Senior Risk & Controls Consultant at FCC, where you will focus on risk assessments and control improvements in a hybrid environment.Enjoy a competitive salary and comprehensiv... Show more

 • Promoted

Head of IT and Information Security

HRBWinnipeg, MB, CA
Full-time

Our client is a well-funded, seed-stage AI startup that builds agents for the factory floor.They develop and distribute a software-first agent layer that plugs into the cameras and machines factori... Show more

 • Promoted

Head of Risk - Remote

BitfinexWinnipeg, MB, CA
Remote
Full-time

Be among the first 25 applicants.Inspired by Bitcoin's vision of financial freedom, we are committed to empowering individuals to transact and connect seamlessly across the globe.From the early day... Show more

 • Promoted

Remote Security Strategy Lead - Applications and IT

Targeted TalentWinnipeg, MB, CA
Remote
Full-time

A leading security consultancy in Ontario seeks an Information & Application Security Manager to lead their cybersecurity strategy and oversee IT, applications, and infrastructure security.This han... Show more

 • Promoted

Dynamic Partnership Opportunity for IT Systems and ISO Standards

ATIA LtdWinnipeg, MB, CA
Full-time

Explore a lucrative partnership to connect clients with IT systems and ISO solutions.Bring your client database or networking skills to earn commissions on every project! This role invites partner... Show more

 • Promoted

Director, Enterprise Risk Management

ML6 Search + Talent Advisorywinnipeg, mb, ca
Full-time

Our client, a rapidly growing insurance organization, is seeking a strategic and collaborative Director of Enterprise Risk Management (ERM) to lead and evolve the organization’s enterprise-wide ris... Show more

 • Promoted

Director, Enterprise Risk Management - ML6 Search + Talent Advisory

ML6 Search + Talent Advisorywinnipeg, mb, ca
Full-time

Our client, a rapidly growing insurance organization, is seeking a strategic and collaborative Director of Enterprise Risk Management (ERM) to lead and evolve the organization’s enterprise-wide ris... Show more

 • Promoted

IT Security Risk Analyst

Onico SolutionsWinnipeg, MB, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

IT Security Operations Lead at ROBINSON

ROBINSONWinnipeg, MB, CA
Full-time

Advance your career as an IT Security Operations Lead at ROBINSON, emphasizing hands-on security operations and compliance management.Focus on incident investigation and tool optimization.This role... Show more

 • Promoted

Partnership Opportunities in IT Systems and ISO Standards Services

ATIA LtdWinnipeg, MB, CA
Full-time

Unlock potential as a partner specializing in IT systems and ISO standards.Connect clients with the services they need while enjoying lucrative commission structures! This opportunity is designed ... Show more

 • Promoted

Cyber Practice Broker at Purves Redmond Limited

TryApplyNowWinnipeg, MB, Canada
Full-time

Drive impactful results as a Broker in the Cyber Practice at Purves Redmond Limited.Manage client portfolios with a focus on renewals and strategic advisory services.This full-time position require... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2PWinnipeg, MB, CA
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumWinnipeg, MB, CA
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Director of ITGC Reporting at Canada Life

TechAlliance of Southwestern Ontario, London Economic Development CorporationWinnipeg, MB, CA
Full-time +1

Join Canada Life as the Director of ITGC Reporting, focusing on corporate financial oversight in a permanent, full-time role.Enhance internal controls and ensure compliance with key regulations.Rep... Show more