Vista previa generada por IA
Lead IT Risk & Cyber Security Specialist – Drive operational risk strategy and cyber resilience for Wealth Management in Toronto.
Deliver advanced threat assessments, manage vulnerability programs, and steer executive risk meetings to safeguard RBC’s technology.
What is the opportunity?
This role participates in and leads some of the execution of the Wealth Management Technology (WMT) Operational Risk Annual Plan and execution of operational risk management (ORM) and IT Risk management within WMT. The role is also responsible for participating in planning and managing Operational Risk Management programs and processes as they flow across WMT.
Technical manager with 1-2 direct reports, expert understanding of IT, Cyber & Operational risk management practices, providing control and advisory services to: application development, support teams and the Wealth Management Business. Services provided cover IT, Cyber & operational risk analysis, risk & compliance exposure reporting, risk awareness & advisory, and regulatory response.
What will you do?
Lead identification, assessment and treatment recommendations for IT, Cyber & Operational risks
Lead vulnerability management program for WMT covering all Application and Infrastructure assets
Lead WMT cyber security operations in response to the current and emerging threat landscape
Responsible for execution and completion of security exemption and acceptance workflow process from start to finish
Lead preparation and participate in execution of executive level meetings (attended by WMT SVP and Senior Leadership Team) on various control and risk topics (e.g. areas of focus and risk acceptances)
Lead execution of risk profile review meetings (attended by Vice Presidents/Senior Directors and their delegates) to ensure SMT risk profiles are adequately managed
Lead execution of risk profile review meetings (attended by Vice Presidents/Senior Directors and their delegates) to ensure SMT risk profiles are adequately managed
Lead/manage direct reports to ensure risk register workflow is executed effectively
Contribute to the delivery of the WMT IT & Operational risk awareness program
What do you need to succeed?
Must-have
Experience conducting threat risk assessments on enterprise applications
Expert knowledge in IT and operational risk management processes, methods and tools
Expert knowledge of Cybersecurity threats, Application and Infrastructure security including
Experience with Penetration testing & DevSecOps with focus on SAST, DAST, SCA, Container and Server security assessments
Experience with emerging AI driven cyber threat landscape
Experience with building Agentic AI driven solutions and automation
Strong knowledge of IT infrastructure & software security architectures
Demonstrable technical knowledge and experience covering the operating systems (e.g. Unix, Windows, zOS) and database systems (e.g. Oracle, SQL Server, Sybase, DB2) in use in Finance IT
CRISC or CISSP Certification
Good communication (verbal and written) skills, including strong appreciation of relationship management
Nice-to-have
CCSP certification
Knowledge of GRC tools (e.g. ServiceNow, Archer)
What’s in it for you?
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable.
Leaders who support your development through coaching and managing opportunities.
Ability to make a difference and lasting impact.
Work in a dynamic, collaborative, progressive, and high-performing team.
A world-class training program in financial services.
Opportunities to do challenging work.
Job Skills
Arquitectura de seguridad informática, Estrategias de gestión de riesgos, Gestión de relaciones interpersonales, Gestión de rendimiento (PM), Gestión de riesgo operativo, Gestión de seguridad cibernética, Gestión de seguridad de la información, Orientado al detalle, Penetrationstests, Pensamiento crítico, Pensamiento estratégico, Perfil de riesgo, Seguridad de tecnología de la información, Seguridad en aplicaciones, Toma de decisiones
Additional Job Details
Address:
RBC CENTRE, 155 WELLINGTON ST W:TORONTO
City:
Toronto
Country:
Canadá
Work hours/week:
37.5
Employment Type:
Full time
Platform:
TECHNOLOGY AND OPERATIONS
Job Type:
Regular
Pay Type:
Salaried
Posted Date:
2026-07-23
Application Deadline:
2026-07-31
Note : Applications will be accepted until 11:59 PM on the day prior to the application deadline date above
Our Employment Opportunities
At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.
Join our Talent Community
Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.
Expand your limits and create a new future together at RBC.
Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well‑being of our clients and communities at jobs.rbc.com .
RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.