Overview

Third Party Security Risk Manager Jobs in Toronto, Ontario, Canada at EQ Bank | Equitable Bank

Title: Third Party Security Risk Manager

Company: EQ Bank | Equitable Bank

Location: Toronto, Ontario, Canada

Join a ChallengerBeing a traditional bank just isn’t our thing. We are big believers in innovating the banking experience because we believe Canadians deserve better options, and we challenge ourselves and our teams to creatively transform what’s possible in banking. Our team is made up of inquisitive and agile minds that find smarter ways of doing things. If you’re not afraid of taking on big challenges and redefining the future, you belong with us. You’ll get to work with people who will encourage you to reach new heights. We like to keep things fun, ask questions and learn together.

We are a big (and growing!) family. Overall we serve more than 670,000 people across Canada through Equitable Bank, Canada’s Challenger Bank™, and have been around for more than 50 years. Equitable Bank’s wholly-owned subsidiary, Concentra Bank, supports credit unions across Canada that serve more than six million members. Together we have over $125 billion in combined assets under management and administration, with a clear mandate to drive change in Canadian banking to enrich people’s lives. Our customers have named our EQ Bank digital platform (eqbank.ca) one of the top banks in Canada on the Forbes World’s Best Banks list since 2021.

Purpose of JobThe Third-Party Security Risk manager will work closely with the technology teams and line of business teams to mitigate the risk of security attacks emanating from partners, vendors and other related third-parties while enabling the business to grow the bank and serve our customers efficiently and securely.

Main Activities:

Perform Third-Party security risk assessments

Monitor and report on third-party security risk action plans, engaging with third-party contacts as well as business stakeholders

Maintain third-party security risk management framework ensuring alignment with Risk management framework (2nd Line of defense) and Privacy requirements

Provide security input to third-party contracts by ensuring alignment with cyber security regulatory requirements and Company cyber security policies

Identify supplier related cyber risk threat scenarios and evaluate risk rating based on a thorough review of the third party’s security program and technical architecture

Monitor third-party compliance program, ensuring continuous compliance and evidence collection, validation, and recording

Knowledge/Skill Requirements:

A college diploma or university degree is required. Higher accreditation (e.g. Bachelor of Computer Science) is preferred

At least five (5) years of information security and information risk experience

At least three (3) years of third-party risk management experience (including hands-on experience conducting third party risk assessments)

Understanding of Cloud Shared responsibility models and risk mitigation approach/techniques

Experience in performing organization-wide/entity security risk assessments or audits is required

Understanding and experience with security compliance frameworks such as PCI DSS, BSIMM, Cloud Security Alliance, NIST, ISO 27K series is required

Understanding of Canadian Financial industry regulations relevant to third-party security and privacy expectations E.g. OSFI, OPC

The following certifications are preferred: CCSP, CCSK, CISM, CISSP, CISA, or CRISC

Experience working in a banking or financial services environment is an asset

Accountability

The incumbent works under direct management of the Senior Manager, Informati…

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.

About EQ Bank | Equitable Bank