Application Deadline:
10/11/2026
Address:
100 King Street West
Job Family Group:
Audit, Risk & Compliance
This role sits within the Technology and Operations risk area as part of Operational and Non-Financial Risk (ONFR). As BMO’s independent second line of defense (2LoD), ONFR oversees and challenges how operational and non-financial risks are managed across the Bank.
ONFR works with the first line of defense (1LoD) and other risk and control functions, applying risk expertise, informed judgment, and data-driven insight to support sound decisions. It maintains independent oversight and effective challenge to promote alignment with the Bank’s risk appetite and help protect the organization.
Role Overview
The Senior Manager, Cyber Risk Oversight and Governance provides independent oversight and effective challenge of cybersecurity and related technology risks. The role advises senior leaders on material exposures and complex matters, offering an objective perspective to support decisions consistent with BMO’s risk appetite.
Working across Cybersecurity, Technology, business lines, and risk and control functions, the Senior Manager assesses the Bank’s cybersecurity risk profile and provides strategic input on material initiatives, emerging technologies, significant issues, and evolving threats. The role leads risk-based oversight, translates complex technical matters into clear risk implications, and delivers practical recommendations to senior management and governance forums.
The ideal candidate is an experienced risk or technology professional who combines cybersecurity or broader technical expertise with strong judgment, clear communication, and the ability to provide constructive challenge collaboratively.
Key Accountabilities
- Serve as a senior risk advisor, providing independent oversight, credible challenge, and actionable advice regarding cybersecurity and related technology risks, controls, strategies, and risk management practices.
- Develop and communicate an independent view of the cybersecurity risk profile across assigned portfolios, including material initiatives, emerging risks, control weaknesses, risk concentrations, and areas of heightened exposure.
- Provide strategic risk input and recommendations to senior leaders on business decisions, technology transformation, emerging technologies, third-party dependencies, and new capabilities with significant cybersecurity implications.
- Evaluate the design and effectiveness of cybersecurity governance frameworks, policies, standards, methodologies, controls, and risk management practices, and recommend proportionate enhancements where appropriate.
- Lead risk-based oversight activities, including independent risk assessments, thematic reviews, capability assessments, governance activities, and targeted evaluations of material or emerging risks.
- Challenge significant cybersecurity issues, incidents, risk acceptances, control deficiencies, and remediation plans, and advise on appropriate escalation where the level of risk or management response is not aligned with established expectations.
- Monitor and analyze risk appetite measures, risk indicators, control performance, issues, incidents, external threats, industry developments, and regulatory expectations to identify adverse trends and changes in risk exposure.
- Translate complex cybersecurity and technical matters into concise, decision-useful reporting, analysis, and recommendations for senior management, governance committees, Board-level forums, auditors, regulators, and other stakeholders.
- Act as a subject-matter expert and primary risk partner for assigned cybersecurity areas, using technical credibility, sound judgment, and constructive challenge to influence risk decisions.
- Represent the second line during regulatory examinations, ongoing supervisory engagements, internal and external audits, governance forums, and other senior stakeholder discussions.
- Build trusted relationships across Cybersecurity, Technology, business lines, and other risk and control functions while maintaining the independence and objectivity required of the second line.
- Lead or contribute to cross-functional initiatives that strengthen cybersecurity risk governance, assessment, monitoring, reporting, and organizational risk awareness.
- Promote consistent, transparent, and data-informed risk practices and contribute to the continued evolution of the risk management framework and oversight capabilities.
Qualifications
- 7+ years of relevant experience in cybersecurity, technology, technology risk, operational risk, information security, audit, or a related discipline.
- Postsecondary degree in Computer Science, Information Technology, Engineering, Cybersecurity, Business Administration, or a related field, or an equivalent combination of education and experience.
- In-depth knowledge of cybersecurity and technology risk management practices, governance frameworks, risk appetite, control environments, issue management, and remediation governance.
- Demonstrated technical expertise in one or more cybersecurity disciplines, such as security operations, vulnerability management, cloud security, identity and access management, or security architecture, is strongly preferred. Candidates with broader technical experience in areas such as enterprise architecture, engineering, infrastructure, cloud platforms, or software development will also be considered.
- Ability to evaluate cybersecurity strategy, technical architectures, threats, vulnerabilities, control designs, and operational practices and translate them into clear risk and business implications.
- In-depth knowledge of applicable cybersecurity regulatory requirements and supervisory expectations, including those established by the Office of the Superintendent of Financial Institutions (OSFI), the Office of the Comptroller of the Currency (OCC), and the Federal Reserve.
- Experience supporting regulatory examinations, ongoing supervisory engagements, internal or external audits, or responses to regulatory findings is preferred.
- Strong working knowledge of recognized cybersecurity and technology risk frameworks and guidance, including NIST, ISO, FFIEC, and other applicable industry standards.
- Strong understanding of independent risk oversight, risk and control assessment, effective challenge, control testing or validation, risk acceptance, issue management, and remediation governance.
- Experience leading or contributing to thematic reviews, independent assessments, capability assessments, or other significant risk-based oversight activities.
- Demonstrated ability to provide constructive and credible challenge to senior technical and non-technical stakeholders while maintaining effective working relationships.
- Strong analytical and problem-solving skills, including the ability to assess complex or ambiguous matters, evaluate incomplete or conflicting information, identify material risk implications, and develop practical recommendations.
- Strong written and verbal communication skills, including the ability to prepare concise materials and communicate complex technical risk matters to executive, Board-level, governance, audit, and regulatory audiences.
- Strong influencing, negotiation, advisory, and relationship-management skills, with demonstrated effectiveness across organizational, functional, and jurisdictional boundaries.
- Ability to identify emerging technologies, threats, regulatory developments, and industry trends and assess their potential implications for the organization.
- Ability to manage ambiguity, balance competing considerations, and exercise sound independent judgment in a rapidly evolving technology, threat, and regulatory environment.
- Strong collaboration and leadership skills, with the ability to lead significant oversight initiatives and deliver results through cross-functional engagement.
- Strong capability in data-informed analysis, risk aggregation, trend identification, risk reporting, and decision support.
- Relevant cybersecurity or risk certifications, such as CISSP, CISM, CISA, GIAC, and CRISC, are preferred.
Salary:
$85,500.00 - $185,000.00
Pay Type:
Salaried
The above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://jobs.bmo.com/ca/en.
BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.