The IAM Policy, Controls, and Compliance Metrics Manager role sits within the Identity and Access Management (IAM) department Cybersecurity, Risk, and Resilience organization. IAM reduces operational risks - such as data leakage, fraud, and service disruptions - by implementing robust security controls across the firm's Technology Division.In this role, the manager directly supports the Vice President, Head of Policy, Controls, and Metrics. Key responsibilities include leading the development, governance, and tracking of IAM policies, risk controls, and compliance metrics, as well as driving strategic IAM initiatives to uphold regulatory standards and safeguard organizational assets.
Location: Montreal (Day 1 onboarding onsite/in office presence 3x/week)
Key Responsibilities:
- Develop and enhance IAM policies and controls, including emerging controls related to AI governance and risk
- management.
- Respond to ad hoc policy, controls, and metrics inquiries from IAM, Technology, business stakeholders, regulators,
- and auditors.
- Design, maintain, and improve control compliance metrics, ensuring alignment between controls, measurements,
- and reporting.
- Communicate policy, control, and metric changes to impacted IAM, Technology, and business stakeholders.
- Maintain control documentation, terminology standards, process documentation, exclusions, reference materials,
- and related intranet content.
- Manage and prioritize the pipeline of policy, control, and metrics initiatives.
- Track and report progress against key policy and control initiatives and milestones for IAM and Cybersecurity
- leadership.
- Lead annual IAM tool certifications and control attestations, and support enhancements to IAM security blueprints.
- Oversee compliance metric reporting, including monthly reporting, escalation, remediation tracking, and non-
- compliance management.
- Support the development and enhancement of IAM's centralized metrics platform, serving as the authoritative
- source for controls, compliance, escalations, and remediation data.
- Conduct data analysis and prepare materials for governance forums and working groups responsible for reviewing
- and approving IAM policies, controls, and metrics.
- Document decisions, track action items, and ensure follow-up activities are completed.
- Prepare materials for Technology Division governance committees in partnership with the Technology Policy Office.
- Drive continuous improvement and automation of policy, controls, metrics, and governance processes to increase
- operational efficiency.
Qualifications:
- Bachelor's degree in Business, Management, Technology, Liberal Arts, or a related field.
- 5+ years of experience in strategy, operations, management consulting, governance, risk management, or a related
- discipline.
- Strong project management and organizational skills, with the ability to manage multiple priorities and deliver results.
- Excellent communication and interpersonal skills, with the ability to build relationships, influence stakeholders, and
- drive consensus across organizations.
- Strong analytical and problem-solving skills, with attention to detail and a focus on quality.
- Demonstrated ownership, accountability, and a proactive, results-oriented mindset.
- Ability to work independently, exercise sound judgment, and effectively manage stakeholder expectations.
- Strong written communication skills and experience creating documentation, policies, procedures, and governance
- materials.
- Intellectual curiosity and willingness to learn new technologies, processes, and business domains.
Preferred Qualifications:
- Experience with IAM, cybersecurity, governance, risk, compliance, or control management programs.
- Experience with Jira, Jive, or similar collaboration and workflow management tools.
- Experience developing metrics, dashboards, reporting frameworks, or governance processes.
- Familiarity with AI governance, technology risk, or policy development is a plus.