We are recruiting a Senior IT Risk & System Governance Lead on behalf of a leading financial services regulatory body in downtown Toronto.
As digital systems expand, internal technology teams face increasing audit engagements and operational reporting demands. To maintain high execution velocity while satisfying regulatory mandates, the Information Services & Digital Solutions team is creating a dedicated 1st-Line IT Governance function.
This role acts as the primary strategic interface and "audit shield" between technology engineering teams, enterprise risk groups, and external auditors. The goal is to streamline compliance, eliminate redundant evidence gathering, and build proactive controls directly into system architectures.
Directly reporting into The Chief Technology Officer, who is seeking an authoritative, highly articulate, and practical "doer"-someone who can independently command respect from software engineering leads and external auditors alike.
The ideal candidate brings a strong computer science foundation, hands-on control testing experience, and an assertive communication style capable of resolving scope creep, driving remediation to root-cause closure, and translating complex technical risks into clear executive insights.
First-Line Audit Defense & Interface: Serve as the single point of contact for all IT audit and risk inquiries; triage requests and shield engineering teams from audit fatigue.
Evidence Registry Management: Build, standardize, and maintain a centralized Evidence Registry to eliminate duplicate evidence asks for change management, access controls, and ITGCs.
Proactive "Risk-by-Design": Partner with system architects and platform engineers early in project lifecycles to embed control requirements into systems before production deployment.
Remediation & Finding Closure: Write realistic, risk-calibrated management responses, establish clear remediation roadmaps with control owners, and track findings through to completion.
Executive & Regulatory Reporting: Maintain the IT Risk Register and deliver concise, metrics-driven dashboards (KRIs/KPIs) for CTO and executive leadership decision-making.
Education: Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline.
Experience: 7+ years of progressive experience in 1st-line IT risk, IT governance, or IT audit within regulated Canadian enterprise environments (banking, financial services, insurance, or public sector).
Certifications: CRISC or CISA strongly preferred; CISM, CISSP, or PMP highly regarded.
Technical Depth: Deep fluency in ITGCs, ITACs, SDLC security, cloud control frameworks (NIST SP 800-53, ISO 27001, SOC 2), and OSFI regulatory guidelines.
Stakeholder Leadership: Proven ability to influence cross-functional technology teams without direct management authority and maintain firm, respectful boundaries with external audit bodies.
