Senior Manager, Third Party Risk, Cybersecurity
BMO Financial Group
Winnipeg, MB-
Nombre de poste(s) à combler : 1
- Salaire À discuter
- Publié le 9 avril 2025
-
Date d'entrée en fonction : 1 poste à combler dès que possible
Description
Date limite pour présenter sa candidature :
06/26/2025Adresse :
VIRTUAL59 - REMOTE/TELETRAVAIL - ON - BMOGroupe de famille d'emploi :
TechnologieAs a Senior Manager of Third-Party Risk Assessment at BMO, you won’t just manage assessments - you’ll shape how we secure hundreds of critical third-party relationships that power one of North America’s leading financial institutions. This is more than a people management role - it’s a chance to build, coach, and elevate a team of experts while leading frontline efforts in cyber defense.
What Makes This Role Stand Out:
- 100% Remote Flexibility: Work remotely while leading a leading team of experienced Third Party Cyber Assessors - most of whom are tenured, and highly skilled in Third Party Risk Assessments
- Strong Peer Collaboration: You’ll partner closely with another senior manager and report directly to a Director who leads a dynamic 20-person assessment team. You’ll never lead in isolation - you’ll be part of a collaborative leadership structure.
- High Impact & Visibility: Lead quality assurance across hundreds of assessments annually, coach Third Party Risk Assessors, engage with executive stakeholders, and help drive resolution of complex risk findings. You’ll be seen as a go-to expert and decision-maker.
- Mission-Driven Culture: Our team thrives in a fast-moving, high-stakes environment where we balance business agility with security, regulatory expectations, and internal audit. This is cyber with real-world impact - where negotiation, leadership, and strategy matter just as much as technical acumen.
- Growth & Thought Leadership: You’ll be expected to challenge the status quo, bring fresh ideas to evolve our assessment model, and stay ahead of emerging threats - while mentoring others to do the same.
What You Bring to the Table:
- 5-10+ years of Cyber Third-Party Risk assessment experience,
- 5+ years in people-leadership (Managerial) role(s)
- CISSP certified
- Deep knowledge of NIST, ISO, or CIS frameworks
- Hands-on experience with major Cloud platforms such as AWS, Azure, or Google Cloud with a strong understanding of cloud security principles, architectures, and best practices.
- Expert-level capability in interviewing, auditing, documentation, and risk reporting
- Strong coaching instincts and the ability to raise the bar on technical quality
- A calm, assertive presence with proven skills in conflict resolution, negotiation, and influence
- Bonus points for ethical hacking certifications (OSCP, GPEN, CEPT)
You’ll Excel Here If You…
- Love being the calm in the chaos - stepping into crisis calls, leading tough conversations, and helping teams find clarity
- Get energy from teaching others and raising the standard of the whole team
- Aren’t afraid to push back when needed, while still keeping people on your side
- Are a fast learner with the curiosity and technical aptitude to pick up new concepts quickly
Key Responsibilities:
- You are a Quality Assurance Czar. You will be responsible for ensuring all assessments have consistent strong quality and meet the expectations of our stakeholders.
- Train and coach: Work closely with your team of Assessors and provide them feedback on their assessments - this can include both technical and soft skills, like negotiation and communication. Being comfortable challenging others and critiquing the work of others is a must-have.
- Enjoy sharing knowledge. This could include coaching people outside of your team, e.g. explaining to the business a technical security control so that they can better understand the risk.
- Findings management. Review evidence and negotiate the closure of findings with internal teams and third parties.
- Be a thought leader. Bring new ideas to the team and challenge the status quo. The security landscape is always changing - we need to ensure that our assessments are aligned with the latest threats.
Join us if you’re ready to lead with purpose, grow a best-in-class cyber risk team, and help secure the future of banking -
Additional Information:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
- Fosters a culture aligned to BMO purpose, values and strategy and role models BMO values and behaviours in all that they do.
- Ensures alignment between values and behaviour that fosters diversity and inclusion.
- Regularly connects work to BMO’s purpose, sets inspirational goals, defines clear expected outcomes, and ensures clear accountability for follow through.
- Builds interdependent teams that collaborate across functional and operating groups to create the highest value for all stakeholders.
- Attracts, retains, and enables the career development of top talent.
- Improves team performance, recognizes and rewards performance, coaches employees, supports their development, and manages poor performance.
- Provides strategic input into business decisions as a trusted advisor.
- Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
- Acts as a subject matter expert on relevant regulations and policies.
- Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Acts as the prime subject matter expert for internal/external stakeholders.
- Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
- Presents data and information to all levels within IT and to business units.
- Leads/oversees the management of vendor relationships and provides guidelines for execution; ensures that all agreements are met as per requirements.
- Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations.
- Analyzes trends and stays current with industry events to proactively prevent information security issues.
- Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
- Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
- Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
- Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
- Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
- Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
- Creates professional presentations and deliver them in a meaningful concise way.
- Assesses information security impact to a project’s benefits and risks when scope changes.
- Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
- Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
- Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
- Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
- Operates at a group/enterprise-wide level and serves as a specialist resource to senior leaders and stakeholders.
- Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to problems that can be complex and non-routine.
- Implements changes in response to shifting trends.
- Broader work or accountabilities may be assigned as needed.
Qualifications:
- Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
- Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).Possesses an expert level of knowledge of information security processes, procedures and controls.
- Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 - In-depth/Expert.
- Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth/Expert.
- Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls.
- Understanding and problem solving ability of information security issues across the bank - In-depth/Expert.
- Understanding of information security risk and regulatory requirements - In-depth/Expert.
- Knowledge of the technical/business environment and the corporate processes and procedures - In-depth/Expert.
- Seasoned professional with a combination of education, experience and industry knowledge.
- Verbal & written communication skills - In-depth / Expert.
- Analytical and problem solving skills - In-depth / Expert.
- Influence skills - In-depth / Expert.
- Collaboration & team skills; with a focus on cross-group collaboration - In-depth / Expert.
- Able to manage ambiguity.
- Data driven decision making - In-depth / Expert.
Salaire :
$100,800.00 - $187,200.00Type de rémunération :
SalaireCe qui précède représente la fourchette et le type de rémunération de BMO Groupe financier.
Les salaires varieront en fonction de facteurs comme l’emplacement, les compétences, l’expérience, les études et les qualifications pour le poste et pourront inclure une structure de commissions. Les salaires pour les postes à temps partiel seront calculés au prorata du nombre d’heures travaillées régulièrement. Pour les rôles à commission, le salaire susmentionné représente la cible de BMO Groupe financier pour la première année au poste.
La rémunération totale offerte par BMO variera selon le type de rémunération associé au poste et peut comprendre des primes de rendement, des primes discrétionnaires ainsi que d’autres avantages et récompenses. BMO offre également une assurance santé, le remboursement des frais de scolarité, une assurance accident et une assurance vie, ainsi que des régimes d’épargne-retraite. Pour en savoir plus sur nos avantages sociaux, consultez le site : https://jobs.bmo.com/ca/fr/R%C3%A9mun%C3%A9ration-globale
À propos de nous
À BMO, nous sommes animés par une raison d’être commune : Avoir le cran de faire une différence dans la vie, comme en affaires. Cette raison d’être nous invite à entraîner des changements positifs et durables pour nos clients, nos collectivités et nos gens. En travaillant ensemble, en innovant et en repoussant les limites, nous transformons des vies et des entreprises et favorisons la croissance économique partout dans le monde.
En tant que membre de l'équipe de BMO, vous êtes valorisé, respecté et entendu, et vous avez plus de moyens pour progresser et obtenir des résultats. Nous nous efforçons de vous aider à obtenir des résultats dès le premier jour, pour vous-même et nos clients. Nous vous offrirons les outils et les ressources dont vous avez besoin pour franchir de nouvelles étapes, car vous aidez nos clients à franchir les leurs. Au moyen de formation et de coaching approfondis ainsi que de soutien de la direction et d'occasions de réseautage, nous vous aiderons à acquérir une expérience enrichissante et à élargir votre groupe de compétences.
Pour en savoir plus, visitez-nous à l'adresse https://jobs.bmo.com/ca/fr.
BMO s'engage à offrir un milieu de travail inclusif, équitable et accessible. Nous apprenons de nos différences et tirons notre force des gens et de leurs différents points de vue. Des mesures d’adaptation sont disponibles sur demande pour les candidats qui participent à tous les aspects du processus de sélection. Pour demander des mesures d’adaptation, veuillez communiquer avec votre recruteur.
Remarque aux recruteurs : BMO n’accepte pas les curriculum vitæ non sollicités provenant de toute source autre que le candidat directement. Tout curriculum vitæ non sollicité envoyé à BMO, directement ou indirectement, sera considéré comme la propriété de BMO. BMO ne paiera aucuns frais pour les placements découlant de la réception d’un curriculum vitæ non sollicité. Une agence de recrutement doit d’abord détenir une entente de service écrite valide et dûment signée avant d’envoyer des curriculum vitæ.
Exigences
non déterminé
non déterminé
non déterminé
non déterminé
D'autres offres de BMO Financial Group qui pourraient t'intéresser