Senior Manager Regulatory Compliance - Tangerine
Toronto, ON, CA, M2H0A1
Scotiabank
Requisition ID: 228750
Tangerine is Canada’s leading direct bank. We offer flexible and accessible banking options, innovative products, and award-winning Client service. The reason why Tangerine employees come to work each day is to help Canadians live better lives. We focus on making a difference in our communities, and that includes our own internal community. It’s important to us that our employees feel empowered and enthusiastic about belonging to our Orange culture.
As Canada’s leading digital bank, Tangerine technology is at the heart of everything we do. We have redefined what digital banking is, and we continue to evolve to tackle any opportunity and face every challenge through progressive technology and the power of collaboration.
Do you like new challenges? Are you ready to reach new heights in your career and become part of an established disruptor? If so, come join us and help redefine the Canadian banking landscape!
The Team
The Tangerine Technology and Cyber Risk team plays a vital role in the bank’s technology and security compliance risk management by implementing the Regulatory Compliance Management (RCM) Framework in accordance with the regulatory requirements of OSFI’s Guideline E13 and in conjunction with the Bank’s overall Regulatory Compliance Program. The Tangerine Technology and Cyber Risk team works closely with Global Compliance, front-line technology and security teams providing First Line of Defense for all technology compliance risk domains including IT Governance, IT Risk, Cyber Security, Information Security, Infrastructure, Network and IT Operations, and Software Development and Change Management to ensure overall technology regulatory compliance.
The Role:
The Senior Manager of Regulatory Compliance is responsible for overall Technology Regulatory Compliance by following Regulatory Compliance Management (RCM) framework and managing detailed plans to prioritize and execute multiple workstreams to achieve full technology regulatory compliance in a timely manner. Ensuring key controls are operating effectively and activities conducted are compliant with the governing regulations, internal policies, and procedures.
Is this role right for you? In this role you will:
- Identify OSFI regulatory obligations and controls according to the technology compliance risk domain(s) assigned to you. This will require working with technology and security Risk owners across Technology teams.
- Collaborate and work closely with Business Lines (BLs)/Corporate Function (CFs) partners and technology teams to document controls and map to the technology obligations embedded in technology and cyber specific regulations.
- Proactively maintain the regulatory library on an ongoing basis by updating the obligations as well as related control documentation and accurate mapping of the correct controls to the obligations.
- Regularly assess inherent risk, control strength, operating and design effectiveness and evaluate residual risk.
- Work actively with the global team of risk professionals to conduct technology and security control testing. Manage remediations and compliance gaps.
- Create and maintain effective reporting and analytics on the compliance measures to monitor and drive compliance gap remediation.
- Proactively identify opportunities to improve effectiveness and enhancements of risk identification and management policies and processes.
- Partner with other risk groups and contribute to the ongoing update and enhancement of controls, frameworks, policies, risk indicators and metrics.
- As needed, collaborate and appropriately challenge the technology and security teams in the assessment of the effectiveness of controls to mitigate regulatory obligations as well as the remediation of control gaps.
- As needed, coordinate with technology and security teams and the testing team to develop and execute testing activities.
- Establish monthly reporting of KPI dashboard.
- Maintain Tangerine’s IT KPIs and KRIs within risk appetite for the IT domains assigned.
- Facilitate and contribute to the preparation of management reporting relating to the responsibilities within the role.
- Lead engagement with Tangerine’s 2nd and 3rd Line of Defense function to influence the focus, scope, and criteria for the testing of the Bank’s IT risk capabilities.
- On-going monitor and track issues raised by Internal Audit, assist risk owners to ensure remediation is completed within pre-defined timelines and risk is addressed appropriately.
Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have:
- Graduate or Postgraduate degree with a minimum of 10 years of relevant combined experience in Regulatory Compliance, Risk, or other Control Functions (Audit, Risk, etc.).
- You have a strong knowledge of regulatory and industry frameworks, guidelines, and standards, governing the management of technology systems and information security (OSFI, COBIT, NIST, ITIL etc.)
- Experience in interpreting Information technology and security regulatory rules is an asset.
- Great relationship manager and collaborator with solid communication (verbal/written) skills.
- Possess at least 5 years of demonstrated hands-on experience with risk management, governance, control, or audit function.
- Keen on keeping current with emerging trends, best practices, directions and issues in information technology and security and global regulatory developments.
- Relevant certifications Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) are desirable.
- Proficiency in creating engaging presentations, utilizing visual storytelling, and formatting slides effectively, along with experience in delivering presentations to various audiences.
- Understands how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
- Sound business and technical acumen, with demonstrated agility in learning and ability to quickly become comfortable with unfamiliar businesses areas of technologies.
- Ability to connect programs/projects to broader organizational goals and grasp the key performance drivers of business partners.
- Supports an environment in which the team pursues effective and efficient operations of respective areas in accordance with Scotiabank’s Values, its Code of Conduct and the Global Sales Principles, while ensuring adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance and conduct risk.
- Build and maintain strong relationships with key contacts within Technology, Operations, and the Business Units to support effective management and delivery of goals for the role.
- Excellent communication (presentation skills, verbal and written). The ability to communicate confidently and clearly at all levels of the organization.
- Proven ability to work both independently and within a team environment.
- Must also be proactive and creative, with strong, proven ability to plan and manage competing priorities, as well as ability to recognize and appropriately handle sensitive and confidential information.
- Excellent stakeholder management and influencing / negotiation skills, capable of balancing multiple perspectives, effective at all levels.
What's in it for you?
- You will be part of a diverse and inclusive team of Client-focused go-getters looking to learn from each other in an environment that celebrates and recognizes success!
- You will have access to thousands of online and in person courses so you can shape your career growth with the support from diverse industry leaders.
- You will get our help to save for your future and to invest in your total wellbeing through our Tangerine benefits*.
- You belong here, we are equal and un-complicated. Bring your true self to work, dress codes don’t apply here.
- You will enjoy workspace flexibility and all the excitement that comes from working at the official Bank of the Toronto Raptors.
*Tangerine employees participate in Scotiabank’s pension & benefits programs (available to permanent employees)
Location(s): Canada : Ontario : Toronto
At Tangerine we value the unique skills and experiences each individual brings to the team, and are committed to creating and maintaining an inclusive and accessible environment. If you require accommodation during the recruitment and selection process, please let our Recruitment team know.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Banking CISA CISSP COBIT Compliance Governance ITIL KPIs NIST Risk management
Perks/benefits: Career development Flex hours
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.