Role: Risk Lead
Location: Toronto, ON (Onsite)
Duration: Contract
We are looking for the Technology Risk Lead (7+ years) with expertise in Cybersecurity, IT Governance, Audit, NIST/COBIT/ISO 27001, Agile/DevOps, and Financial Services Risk Management.
Required Qualifications
- Bachelor’s degree in computer science, Information Technology, Risk Management, Engineering, or related discipline.
- 7+ years of experience in technology risk, operational risk, cybersecurity, technology governance, audit, or software engineering.
- Strong understanding of software development methodologies, including Agile and DevOps.
- Knowledge of technology risk frameworks and control standards.
- Experience supporting regulatory, audit, or compliance activities.
Preferred Qualifications
- Experience within a regulated financial services environment.
- Knowledge of NIST, COBIT, ITIL, ISO 27001, FFIEC, or comparable frameworks.
- Professional certifications such as: CRISC, CISM, CISSP, CISA, PMP, CGEIT
Key Responsibilities
Risk Advisory and Partnership
- Serve as the primary risk advisor for assigned technology development teams.
- Build strong relationships with engineering leaders, product owners, architects, and delivery teams.
- Provide guidance on technology, operational, cybersecurity, data, and regulatory risks associated with initiatives and platforms.
- Support informed risk-taking by helping teams understand risks and mitigation options.
Risk Identification and Assessment
- Facilitate ongoing identification and assessment of risks across applications, platforms, processes, and technology programs.
- Evaluate inherent and residual risks associated with new solutions, major changes, cloud migrations, and transformation initiatives.
- Perform risk analysis and challenge assessments to ensure risks are appropriately understood and documented.
- Identify emerging risks, trends, and control weaknesses.
Control Environment and Governance
- Promote effective controls throughout the software development lifecycle.
- Partner with development teams to strengthen preventive, detective, and corrective controls.
- Support compliance with enterprise policies, standards, and regulatory requirements.
- Participate in governance forums, risk reviews, architecture reviews, and change approval processes.
Risk Issue Management
- Oversee the lifecycle management of findings, issues, audit observations, regulatory actions, and control deficiencies.
- Challenge remediation plans to ensure root causes are addressed effectively.
- Track progress against commitments and escalate concerns when milestones are at risk.
- Support evidence collection and validation activities.
Metrics and Reporting
- Develop and maintain risk dashboards and management reporting.
- Provide meaningful insights into risk exposure, control effectiveness, issue trends, and remediation status.
- Prepare materials for senior management, risk committees, and governance forums.
- Communicate risk themes and emerging concerns in a clear and actionable manner.
Regulatory, Audit, and Compliance Support
- Coordinate responses to internal audit, external audit, and regulatory examinations.
- Ensure development teams understand and address regulatory obligations and control expectations.
- Support preparation of management responses, remediation plans, and status updates.
- Assist in demonstrating effective risk management practices to auditors and regulators.
Risk Culture and Education
- Promote a strong risk culture across the development organization.
- Educate teams on risk management principles, policies, standards, and control expectations.
- Coach leaders on integrating risk considerations into planning and decision-making.
- Foster accountability for risk ownership and control effectiveness.
Thank you
Praveen
praveen.s@themesoft.com