Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Manager, Cyber and Regulatory Audit image - Rise Careers
Job details

Manager, Cyber and Regulatory Audit

Press Tab to Move to Skip to Content LinkSelect how often (in days) to receive an alert:Title: Manager, Cyber and Regulatory AuditRequisition ID: 212522Salary Range:90,000.00-167,200.00Please note that the Salary Range shown is a guideline only. Salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience.Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Global Banking and MarketsGlobal Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank’s strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world.Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group.Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries! We work together to drive ambition for every future!PurposeThe Information Security and Control (IS&C) Manager will participate and manage various aspects of information security, risk assessments, and contribute to the overall success of the U.S. IS&C’s governance, regulatory compliance, and risk program.This role requires a seasoned professional with a strong background in information security, risk management, cybersecurity technology risk, compliance, policy, and governance. The IS&C Manager will assist with regulatory responses, audit requests and participate in various cybersecurity risk assessments, risk mitigation strategies, and safeguard the Bank from potential informational security threats. The person will also play a role in reviewing and implementing security policies, procedures, and controls to protect the organization's data, systems, and networks.The role will be expected to work closely with cross-functional teams to establish and maintain a robust cybersecurity and technology risk management program to proactively safeguard the organization from security threats by ensuring that vulnerabilities are identified, monitored, and treated, as well as assuring the Bank meets regulatory compliance.What You’ll Do• Regulatory and Compliance Management (specific to cybersecurity):• Participates in engagements with external regulatory and internal/3rd party auditors requests for information security and cybersecurity.• Monitors, analyzes, and reports on cybersecurity requirements against relevant U.S. regulations and cybersecurity standards, such as NYSDFS, FFIEC, and NIST CSF.• Provides support to IT&S auditors and compliance with respect to regulatory and audit information requests.• Continuously monitors and assesses the effectiveness of security controls and processes.• Reviews cybersecurity control library periodically and provides updates as needed.• Cybersecurity and Technology Risk Governance:• Understand how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.• Identifies and assesses cybersecurity and technology risks to ensure compliance with regulations and internal policies.• Performs cybersecurity risk assessments and provide updates to US IS&C senior management team.• Risk and Issues Management:• Reports and tracks all cybersecurity-related issues that pertains to audits, regulatory requirements, control testing, and other issues.• Provides guidance to internal stakeholders on cybersecurity best practices.• Prepares regular reports and presentation decks on risk management, gap assessment, cybersecurity-related issues for senior management and stakeholders .• Monitors and tracks the progress of risk mitigation efforts related to cybersecurity.• Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank’s Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.• Champions a high-performance environment and contributes to an inclusive work environment.What You’ll Bring• Required 5+ years of experience as an Information Security Analyst or related cybersecurity field with technology risk background.• Experience in IT key security controls/mechanisms and risk assessment concepts pertaining to complex data, application, and networking environments.• Prior experience and knowledge with NYDFS, FFIEC, or other US financial regulatory audits.• Have strong verbal and written communication skills in English with excellent individual project management and tracking skills.• Cybersecurity related certification is preferred (CISSP, CCSP, CRISC, CISM).• University degree or college diploma in a cybersecurity related field is preferred.Interested?If your experience is closely related but doesn’t align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank!At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. That’s why we work to grow and diversify talent and engage employees in a performance-oriented culture.What's in it for you?Scotiabank wants you to be able to bring your best self to work – and life, every day. With a focus on holistic well-being, our many flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.Location(s): United States : New York : New York City || United States : Texas : HoustonScotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here . Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.Nearest Major Market: New York CityJob Segment: Audit, Compliance, Information Security, Investment Banking, M&A, Finance, Legal, Technology, Management
Scotiabank Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Scotiabank DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Scotiabank
Scotiabank CEO photo
Scott Thomson
Approve of CEO

Average salary estimate

Estimate provided by employer
$73 / HOURLY (est.)
min
max
$70
$75

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Manager, Cyber and Regulatory Audit, Scotiabank

Are you ready to take your career to the next level as a Manager, Cyber and Regulatory Audit at Scotiabank in Houston, TX? Join our team and become an integral part of our innovative Global Banking and Markets division, where we're committed to creating a high-performing and inclusive culture. In this exciting role, you'll be at the forefront of safeguarding our organization against cybersecurity threats while ensuring compliance with ever-evolving regulations. Your strong background in information security and risk management will be vital as you participate in regulatory responses and audit requests, helping to shape the organization’s technology risk management program. You'll work collaboratively with cross-functional teams to monitor, assess, and implement security controls, ultimately driving our mission to protect our data and support our clients’ success. At Scotiabank, we aim to empower our employees, allowing you to bring your best self to work and promoting a holistic approach to your well-being. If you have the qualifications and a passion for cybersecurity, join us in making a substantial impact in the banking industry today!

Frequently Asked Questions (FAQs) for Manager, Cyber and Regulatory Audit Role at Scotiabank
What are the key responsibilities of the Manager, Cyber and Regulatory Audit at Scotiabank?

As the Manager, Cyber and Regulatory Audit at Scotiabank, you'll oversee various aspects of information security and risk management. Responsibilities include engaging with external regulators, managing audit requests, monitoring compliance with cybersecurity regulations, conducting risk assessments, and reporting cybersecurity issues. You'll also contribute to developing security policies and work with teams to mitigate risks, ensuring the protection of the bank's data and technology infrastructure.

Join Rise to see the full answer
What qualifications do I need to apply for the Manager, Cyber and Regulatory Audit role at Scotiabank?

To be considered for the Manager, Cyber and Regulatory Audit position at Scotiabank, you should have at least 5 years of experience in information security or a related field with a focus on technology risk. Familiarity with U.S. financial regulations, such as NYDFS and FFIEC, is essential. Candidates with cybersecurity certifications like CISSP, CISM, or CRISC are preferred. A university degree in a cybersecurity-related discipline can also enhance your application.

Join Rise to see the full answer
How does Scotiabank support career development for the Manager, Cyber and Regulatory Audit?

Scotiabank is committed to employee empowerment and career development. As a Manager, Cyber and Regulatory Audit, you will have access to continual learning opportunities, including training in the latest cybersecurity practices and technologies. The bank also encourages professional certifications and provides resources to help you grow your skills. You'll work in a dynamic environment that fosters innovation and collaboration, allowing you to reach your full potential.

Join Rise to see the full answer
What skills are essential for success as a Manager, Cyber and Regulatory Audit at Scotiabank?

Success in the Manager, Cyber and Regulatory Audit role at Scotiabank hinges on excellent communication skills, both verbal and written. You'll need strong analytical abilities to identify and mitigate cybersecurity risks effectively. Familiarity with regulatory frameworks and a solid understanding of technology security controls are crucial. Project management skills will help you track and report on compliance efforts. An inclusive mindset to foster a collaborative workspace is also essential.

Join Rise to see the full answer
What kind of work environment can I expect as a Manager, Cyber and Regulatory Audit at Scotiabank?

At Scotiabank, you'll experience a comprehensive and inclusive work environment that values diverse backgrounds and perspectives. As the Manager, Cyber and Regulatory Audit, you will work in a supportive team that emphasizes collaboration and continuous improvement. The culture encourages open communication and celebrates achievements, ensuring you feel valued and empowered to contribute effectively to our shared goals.

Join Rise to see the full answer
Common Interview Questions for Manager, Cyber and Regulatory Audit
Can you explain your experience with cybersecurity compliance regulations entities like NYDFS or FFIEC?

When answering this question, provide specific examples from your previous roles where you monitored or implemented compliance with cybersecurity regulations. Discuss the frameworks you are familiar with, detailing how you ensured adherence and any challenges you overcame in maintaining compliance for your organization.

Join Rise to see the full answer
How do you approach conducting a risk assessment for cyber threats?

Explain your methodology for risk assessment, including identifying assets, evaluating potential threats, and assessing vulnerabilities. Discuss any tools or frameworks you use and provide an example of a risk assessment you led, focusing on the outcomes and risk mitigation strategies you recommended.

Join Rise to see the full answer
What strategies do you use to stay current on emerging cybersecurity threats?

Detail your commitment to continuous learning by discussing the resources you utilize, such as cybersecurity publications, online courses, or industry conferences. Mention any professional networks or groups you are a part of that keep you informed about trends and threats in the cybersecurity landscape.

Join Rise to see the full answer
Describe a time when you had to handle a cybersecurity incident. What was your role?

Use a specific example of a past incident where you played a key role. Outline the steps you took to respond, how you collaborated with your team, and the lessons learned from the experience. Highlight your problem-solving skills and ability to work under pressure.

Join Rise to see the full answer
How would you evaluate the effectiveness of current security controls in place?

Discuss the metrics or key performance indicators you would use to measure the effectiveness of security controls. Highlight any tools or assessments you have employed in the past to evaluate security measures, and explain how you ensure they align with regulatory requirements and organizational goals.

Join Rise to see the full answer
What leadership qualities do you believe are important for a Manager in Cyber and Regulatory Audit?

Discuss attributes like strong communication, decision-making skills, and the ability to inspire others in your response. Provide examples of how you have applied these qualities in previous roles to lead teams effectively and adapt to challenges.

Join Rise to see the full answer
How do you manage competing priorities within your role?

Outline your approach to time management and prioritization. Discuss strategies you implement to handle multiple tasks simultaneously, including tools or methods you use to stay organized while ensuring quality and compliance are upheld in your work.

Join Rise to see the full answer
Can you provide an example of how you've improved a cybersecurity compliance process in the past?

Share a specific scenario where you identified an area for improvement in a compliance process. Describe the changes you implemented, the steps you took for stakeholder buy-in, and how these changes benefited the organization in terms of compliance and risk management.

Join Rise to see the full answer
In your opinion, what is the biggest cybersecurity threat facing financial institutions today?

Articulate your perspective on current threats - perhaps focusing on data breaches, phishing attacks, or insider threats. Support your opinion with recent examples or statistics from the industry to demonstrate your understanding of the current cybersecurity landscape.

Join Rise to see the full answer
How do you ensure effective communication of cybersecurity policies across the organization?

Explain how you tailor your communication style to diverse audiences. Discuss methods such as training sessions, workshops, or accessible policy documentation that you have used to enhance awareness and understanding of cybersecurity policies within an organization.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
ServiceNow Remote 6 Temasek Boulevard Suite 40-01, Singapore, Singapore
Posted 11 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
Visa Remote Frankfurt, Germany
Posted 6 days ago
Photo of the Rise User
Iodine Software Remote No location specified
Posted 20 hours ago
Alphabe Insight Inc Hybrid Philadelphia, PA, USA
Posted 22 hours ago

Scotiabank is one of the leading foreign banks serving large national and multinational corporations in the U.S. through its Global Banking and Markets, Global Transaction Banking and Wealth Management business lines.

31 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 17, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!