IT Risk & Controls Partner (Information Security)
Aviva Canada is committed to an inclusive and supportive workplace where individuals and teams thrive. Our core values—Care, Commitment, Community, and Confidence—guide everything we do.
We are looking for a positive and forward‑thinking IT Risk and Controls Partner who specializes in Cyber and Information Security. The ideal candidate will bring strong collaboration, communication, and analytical skills, and will report directly to the Head of Technology Strategic Initiatives, Risk and Operations. This role is central to IT’s first‑line risk and control team and is critical to maintaining a robust risk culture across the department.
What You’ll Do
Deliver efficient, effective, and timely first‑line oversight of risk management related to cyber and information security. This includes :
- Performing risk and control assessments
- Managing risk events and issues, facilitating root‑cause analysis of incidents, and quantifying loss impacts
- Monitoring the IT risk profile, KRIs, and associated metrics to proactively identify changes and emerging risks
- Conducting in‑depth analysis on inherent and residual risk related to cyber and data loss
- Monitoring and reporting on the status of management’s IT risk response plans
- Ensuring our GRC tool 'iCare' remains reliable and up to date
- Report identified IT and cyber‑security vulnerabilities in a language that senior leaders can understand and act upon.
- Develop and manage relationships with technology and CISO partners, including Aviva Canada, Aviva Group second and third lines of defense, and other first‑line risk and control teams.
- Periodically analyze risk data (internal and external) to identify common themes, patterns, and trends at an aggregate level.
- Serve as an SME on cyber and information security for Aviva Canada’s technology and business transformation projects where needed.
- Support the identification and reporting submissions for regulatory surveys and stay current on new developments and emerging risks.
What You’ll Bring
5+ years of experience within IT Operations, IT System Development Life Cycle, IT and / or Cyber Risk Management, Governance, and / or Audit.Effective communication, listening, presentation, and facilitation skills.Effective interpersonal, leadership, and relationship‑building skills for engaging with managers at all levels.Ability to analyze complex data sets, identify trends, and communicate actionable conclusions.Strong strategic and critical thinking skills.Experience using GRC risk management tools.Professional certifications or membership in associations such as CRISC, CISA, CISSP, CISM is an asset.What You’ll Get
The salary range for this position is $115,000 to $150,000. Individual compensation is determined by experience, knowledge, and internal equity.Compelling rewards package including base compensation, eligibility for an annual bonus, retirement savings, share plan, health benefits, personal wellness, and volunteer opportunities.Outstanding career development opportunities and support for professional education.Competitive vacation package with the option to purchase 5 extra days off per year.Employee‑driven programs focused on gender, LGBTQ+, origins, diversity, and inclusion.Corporate wellness programs for physical and mental health.Hybrid flexible work model.Aviva Canada welcomes applications from all qualified individuals and provides accommodations for persons with disabilities at all stages of the hiring process. If you need an accommodation during the interview or hiring process, please contact your Aviva Talent Acquisition Partner to arrange appropriate accommodation.
Aviva Canada may use AI (Artificial Intelligence) tools to assist in screening, assessing, and selecting applicants for this position.
Seniority level
Mid‑Senior level
Employment type
Full‑time
Job function
Information Technology
Industries
Insurance
#J-18808-Ljbffr