Application Deadline:
Address:
100 King Street WestJob Family Group:
Audit, Risk & ComplianceOversees, monitors, and reports on information and technology risks for a designated portfolio. Develops and monitors the risk management and governance framework and practices leveraged across BMO to manage information and technology risks. Develops and monitors adherence to policies, standards, methodologies, and controls that increase transparency, accuracy, and consistency across groups. Works with stakeholders to implement the methodology, metrics, and program standards for the assigned portfolio to ensure compliance, effective monitoring, timely reporting, and identify action plans.
Key Accountabilities:
· Administers and maintains technology and information security and management risk program activities, adhering to applicable policies, procedures, and established processes.
· Reviews new business initiatives and monitors existing initiatives to identify potential risk situations and impacts; makes recommendations or escalates in accordance with established guidelines.
· Identifies potential risk situations and impacts and makes recommendations or escalates, as appropriate.
· Provides advice and guidance to assigned business or groups on implementation of the risk framework, including effective challenge.
· Coordinates and participates in the execution of oversight and governance activities, including reporting; assessment of education and training needs; development and delivery of training; and development and execution of regulatory administration processes and procedures.
· Consults with stakeholders to improve the consistency and transparency of risk measurement, metrics, and reporting.
· Supports the development and maintenance of the governance system and framework, including policy, standard, and operating procedure lifecycle management, as well as education and training assessments.
· Builds effective relationships with internal and external stakeholders, including business stakeholders and corporate support areas, to provide second line of defense information and technology risk management support.
· Manages databases and supports analysis, forecasting, and data visualization, ensuring adherence to data governance standards.
· Analyzes data and information to provide insights and recommendations, including identifying risk impacts associated with new processes and workflows related to initiatives.
· Maintains tools and templates for information and technology risk programs and standards, including Risk Control Self Assessment (RCSA), Sarbanes-Oxley (SOX), business continuity planning standards, and policies for internal and third-party solution development.
· Develops and maintains in-depth knowledge of business and related risk management requirements and legislative and regulatory directives and guidance.
· Builds effective relationships with internal and external stakeholders.
· Analyzes data and information to provide insights and recommendations.
Cloud Technology Governance:
· Assesses and monitors risks associated with cloud technologies, including concentration risk, third-party dependencies, cloud-native services, container platforms, and emerging cloud architectures.
· Reviews cloud governance controls and risk management practices to ensure alignment with enterprise standards, regulatory expectations, and risk appetite.
· Supports the development and enhancement of cloud-related risk metrics, key risk indicators (KRIs), reporting, and governance processes.
· Engages with technology stakeholders to evaluate cloud adoption initiatives and identify potential risk impacts related to security, availability, recoverability, data management, and operational resilience.
Artificial Intelligence Risk and Governance:
· Reviews AI governance frameworks, risk assessments, controls, and monitoring processes to ensure alignment with enterprise policies, standards, and regulatory expectations.
· Evaluates AI use cases, development practices, and deployment activities to identify potential risk exposures and ensure appropriate governance throughout the AI lifecycle.
· Monitors emerging industry, regulatory, and technology developments related to AI and advises stakeholders on potential impacts to the organization's risk profile.
Qualifications:
· Typically 7+ years of relevant experience and a post-secondary degree in a related field of study, or an equivalent combination of education and experience.
· Degree in Information Technology, Computer Science, Business Administration, or a related field of study preferred.
· Completion of a security-related certification preferred, such as CISSP, CISA, CISM, or GIAC
· In-depth or expert knowledge of information and technology risk management practices.
· In-depth or expert knowledge of the designated business or product portfolio.
· In-depth or expert knowledge of regulatory requirements.
· In-depth or expert knowledge and experience with risk policy frameworks and quality control or testing frameworks.
· In-depth or expert knowledge of AI governance and risk management
· In-depth or expert knowledge of cloud technologies and governance practices
· Seasoned professional with a combination of education, experience, and industry knowledge.
· Verbal and written communication skills: In-depth / Expert.
· Analytical and problem-solving skills: In-depth / Expert.
· Influence skills: In-depth / Expert.
· Collaboration and team skills, with a focus on cross-group collaboration: In-depth / Expert.
· Ability to manage ambiguity.
· Data-driven decision-making: In-depth / Expert
Salary:
$85,500.00 - $185,000.00Pay Type:
SalariedThe above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://jobs.bmo.com/ca/en.
BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.