SCM Insurance Services – Cyber Insurance Claims Examiner – Full Time, Remote (Anywhere in Canada) – Toronto, ON

Company: SCM Insurance Services

Location: Toronto, ON

Expected salary:

Job date: Sat, 29 Mar 2025 23:22:52 GMT

Job description: Company: ClaimsPro LP – International Programs GroupCyber Insurance Claims Examiner – Full Time, Remote (Anywhere in Canada)International Programs Group (IPG) is an independent third-party claims administration team that provides claims services for Lloyd’s of London, self-insured entities, and organizations with high deductibles. We provide our clients with peace of mind knowing that their interests are looked after by a team of professionals who understand the specific language and technicalities of this market and who are committed to providing the highest quality of Third-Party Administrator (TPA) services. IPG also provides clients with the added value of local, on-the-ground knowledge and coast-to-coast coverage across Canada and the UK.Although intended to be a remote work opportunity, this position may require attendance to the office for training, client meetings, or team meetings with ample notification.Key Responsibilities:

  • Act as an examiner for various Lloyds accounts which involves providing prompt, fair, quality claims service to clients.
  • Examine complex liability claims, with primary focus on Cyber claims
  • Direct Field Adjusters on assignment investigations
  • Settle claims directly with claimants or their representatives
  • Administer claims payments/settlements through trust accounts
  • Liaise with all stakeholders to ensure client’s needs are met

Education, Knowledge and Experience Required:

  • College diploma or combination of education and equivalent business
  • CIP designation an asset
  • 5+ years of claims handling experience
  • 2+ years handling cyber claims
  • Experience dealing with Lloyds a clear advantage.

Competencies Required to Succeed:

  • Individual must demonstrate the ability to direct adjusters of all levels and work effectively in a team environment
  • Previously demonstrated ability to communicate effectively with both internal and external associates, written and oral techniques
  • A positive, “can do” attitude and customer service approach ensuring all inquiries are effectively dealt with in a timely manner
  • Strong analytical, problem solving and organizational skills
  • Demonstrated ability to be proactive in identifying and implementing solutions
  • Proven ability to multi-task in a fast paced and demanding environment
  • Exceptional computer skills. Ability to navigate various systems, proficient in MS Office and work in a paperless environment.

What We Offer:

  • Competitive Pay
  • Work-Life Balance
  • Remote Working Opportunities
  • E-flex Benefits Program
  • Wellness Programs
  • Registered Retirement Savings Plan (RRSP), including a 2% match for full-time employees
  • Training and Career Development Opportunities
  • Employee Referral Bonuses
  • Employee Recognition Program
  • Employee Perks (access to vendor discount programs)
  • Reimbursement for Adjusting Licenses and Dues

SCM Insurance Services and affiliates welcome and encourage applications from people with disabilities. Accommodations are available on request for candidates throughout the recruitment and assessment process.SCM Insurance Services (SCM) and its affiliated companies will not accept unsolicited resume submittals from third- party recruiters and hereby request agencies to not contact SCM employees or managers directly to present candidates. Be advised SCM will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume and will consider any unsolicited resumes forwarded public information. SCM welcomes resumes submitted directly from candidates.

Manager – Cyber Compliance (Payment Card Security) – RSM International – Toronto, ON

Company: RSM International

Location: Toronto, ON

Expected salary: $96000 – 163500 per year

Job date: Thu, 27 Mar 2025 05:56:12 GMT

Job description: We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.CyberCompliance Manager (Payment Card Security)At RSM US LLP, we established the Security and Privacy Risk Consulting (SPRC) group to meet the critical cybersecurity needs of our clients. This team of dedicated cybersecurity professionals focuses exclusively on cybersecurity and information protection. Our SPRC group, located throughout the country, helps clients prevent, detect, and respond to security threats impacting their critical systems and ensures regulatory compliance in handling, processing, and protecting sensitive information. We support a diverse client base across various industries, providing expertise in information security risk management, security testing, enterprise architecture, governance, regulatory privacy compliance, and digital forensics.We are seeking a Manager-level Payment Card Industry (PCI) Qualified Security Assessor (QSA) to join our Security and Privacy Risk consulting practice. As a Manager of CyberCompliance, you will drive the growth of cybersecurity service offerings while understanding industry-specific risks and payment card security requirements. You’ll assist organizations in developing robust data protection programs to safeguard critical assets, particularly the cardholder data environments of RSM US LLP clients. Your team will focus on assessing, designing, and implementing cybersecurity risk management practices such as network segmentation, vulnerability management, data classification, encryption, de-identification, and sensitive data monitoring solutions to ensure cyber regulatory alignment for data-rich organizations.Responsibilities

  • Manage the timely delivery of engagement results and high-quality deliverables, adhering to professional and industry standards.
  • Hands-on delivery and execution of project tasks for complex technology environments.
  • Present project status, risk-based observations, and proposed solutions to clients’ senior management.
  • As a first choice advisor, cultivate and maintain relationships with stakeholders, identifying opportunities for technological and operational risk mitigation.
  • Assess payment card compliance maturity and assist clients in building and implementing sustainable PCI compliance programs.
  • Support organizations in developing and implementing information governance frameworks.
  • Aid clients in designing and maintaining payment card industry and cyber compliance programs, including operational processes, technology, and guidelines.
  • Identify opportunities to expand service scope within engagements and contribute to market-facing initiatives to attract new client prospects.
  • Communicate strategic and tactical risks of account data protection, advanced security threats, enterprise security management practices, and innovative security solutions to clients.
  • Translate complex technical issues into executive-style reports and presentations for senior management.
  • Leverage industry and technical expertise to identify improvement opportunities for clients and support remediation services.
  • Supervise, train, and mentor staff, coordinating with client resources as necessary.
  • Assist in building the SPRC practice by expanding the team’s size and skill set.
  • Set performance expectations for staff and provide constructive feedback.
  • Oversee and train junior team members during service delivery, ensuring quality and fostering growth.
  • Support business development efforts to acquire new clients and expand existing relationships.
  • Identify business opportunities and enhance go-to-market strategies.
  • Advise area leadership on SPRC service line growth and market strategies.
  • Participate in professional organizations and develop thought leadership in relevant cybersecurity topics for internal and external branding.
  • Ensure revenue targets are met, and service offerings remain responsive to the evolving business environment.

Required Qualifications

  • Active or former PCI QSA certification with experience preparing Level 1 and Level 2 PCI DSS Reports on Compliance (ROCs) or 3+ years of PCI DSS experience with one or more of the following certifications:
  • (ISC)2 Certified Information System Security Professional (CISSP)
  • ISACA Certified Information Security Manager (CISM)
  • Certified ISO 27001 Lead Implementer 1
  • (METI) Registered Information Security Specialist (RISS)
  • ISACA Certified Information Systems Auditor (CISA)
  • GIAC Systems and Network Auditor (GSNA)
  • Certified ISO 27001 Lead Auditor
  • IRCA ISMS Auditor or higher—e.g., Auditor/Lead Auditor, Principal Auditor
  • IIA Certified Internal Auditor (CIA)
  • Bachelor’s degree in information technology, business, or related discipline from an accredited college/university.
  • 5+ years of related work experience in cyber compliance consulting or equivalent advanced academic experience.
  • Familiarity with cybersecurity program components and supporting workflows, such as:
  • Regulatory monitoring
  • Business requirements definition
  • Data inventory and information flow mapping
  • Cybersecurity risk management
  • Third-party vendor management
  • Interactions with consumers (data subject requests)
  • Incident management and breach notifications
  • Technical knowledge of network and IT infrastructure, application/database design, IT governance, risk management, incident response, and typical network/IT security components.
  • Working knowledge of key cybersecurity compliance standards and regulations, including PCI DSS, NIST CSF, GLBA, etc.
  • Proven people skills with experience operating in a professional services firm, large consultancy, or similar environment.
  • Demonstrated ability to collaborate effectively, especially with cross-functional teams.

Preferred Qualifications

  • Proven experience engaging with diverse organizational stakeholders, including management, business, marketing, HR, IT, and Legal teams.
  • Advanced degree focused on data protection, privacy, or a related field.
  • Strong written, oral, and presentation skills with an innovative mindset.
  • Knowledge of PCI DSS practices in retail and financial services.
  • Proven ability to work seamlessly in a virtual environment with globally dispersed team members.
  • Creative thinking, individual initiative, and flexibility in navigating rapid changes in technology, regulation, and client needs.
  • Commitment to staying updated with advancements, challenges, and discoveries in the Security and Privacy industry.

At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at .RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Canadian uniformed service; Canadian Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at .At RSM, an employee’s pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.Compensation Range: $96,000 – $163,500Individuals selected for this role will be eligible for a discretionary bonus based on firm and individual performance.

RSM US LLP is a leading provider of professional services globally, with a focus on instilling confidence in a world of change and empowering clients and employees to reach their full potential. The CyberCompliance Manager (Payment Card Security) position involves managing cybersecurity and payment card security requirements, developing data protection programs, and ensuring regulatory compliance. The role includes responsibilities such as delivering high-quality results, building client relationships, and supporting business development efforts. Required qualifications include PCI QSA certification or relevant experience, a bachelor’s degree, and expertise in cybersecurity compliance standards and regulations. Preferred qualifications include engaging with diverse stakeholders, a relevant advanced degree, and strong communication skills. RSM offers a competitive benefits and compensation package and is committed to providing equal opportunity and reasonable accommodation for applicants with disabilities. The salary range for this role is $96,000 – $163,500, with potential for a discretionary bonus based on performance.

Royal Bank of Canada – Associate Director, Cyber Risk and Identity Access Management (IAM) – Toronto, ON

Company: Royal Bank of Canada

Location: Toronto, ON

Expected salary:

Job date: Tue, 11 Mar 2025 00:16:14 GMT

Job description: Job Summary As part of the Group Risk Management’s Enterprise Resilience Risk team, the Associate Director, Cyber & Technology Risk will be responsible for providing challenge and oversight on Identity and Access Management (IAM) programs, IAM lifecycle, and cyber operations teams. You will be responsible to provide an opinion on RBC’s IAM risk posture, developing / overseeing IAM Key Risk Indicators to measure and monitor risk and contributing to the development of enterprise policies and standards governing IAM.Job DescriptionWhat is the opportunity?You will support IT/Cyber Risk Management leadership within the Enterprise Resilience Risk team in delivering various oversight and challenge processes including: tracking and reporting on the status and quality of key IAM Risk programs; developing and utilizing effective risk appetite metrics that provide insights into current risk level; identifying issues with policy compliance through analysis and testing of controls; monitoring and assessing cyber/technology incidents related to IAM; and performing thematic reviews to investigate issues and providing value add recommendations.This includes providing an opinion on RBC’s technology risk posture, developing / overseeing IAM key risk indicators to measure and monitor risk and contributing to the development of enterprise policies and standards governing Identity and Access Management Risk.What will you do?

  • Leverage data driven insight and provided opinions and challenge on key risk indicators.
  • Support the completion of thematic reviews, scenario analysis, external event analysis, new change initiative assessments and development of risk profiles that can be leveraged to report to senior management, board, and regulators.
  • As second line of defense, work closely with first line to provide effective and cyber/technology oversight and challenge for Global Security’s IAM Operational and IT risk programs such as Risk and Control Self-Assessments, Operational Risk Event Reviews, IT Risk Assessments, and Integrated Risk Profiles to validate that the business is operating within Risk Appetite.
  • Support cyber/technology related regulatory examinations / requests / assessments / reporting.
  • Champion managing risk rather than risk avoidance, by seeking solutions.
  • Maintain assigned Domain Risk Profiles to provide a strong fact-based opinion on the Technology Risk profile.
  • Develop and maintain key internal and external relationships to provide advice and oversight on standard compliance, support operational risk program adherence and effective incident reporting.
  • Provide oversight and challenge on the management of significant cyber incidents.
  • Recommend changes to Cyber & IT Risk policies/standards to maintain currency in ensuring relevance to emerging technologies and delivery models.
  • Develop and maintain key Technology relationships to provide expertise and oversight on new initiatives.
  • Keep abreast of emerging technology threats.
  • Proactively manage complex and sometimes competing relationships with key local, regional, and global stakeholders on a regular basis
  • Develop strong relationships within GRM and Operational Risk teams in support of common objectives and goals.

What do you need to succeed?Must-have:

  • CRISC / CISSP / CISM / CISA or similar certification
  • years in the financial services or other regulated industries
  • 5 years of information technology and operations experience is required; preferably as part of an IAM team or IAM related role.
  • Expert knowledge of IAM concepts, methodology, processes and procedures and controls.
  • Experience with IAM technologies and protocols such as: Multi-Factor Authentication, Single-Sign On, MS Active Directory, LDAP, Cloud IAM, SAML, Kerberos, OAuth, Remote Access, etc.
  • Strong technical IAM knowledge covering areas the areas of Authentication, Authorization, Privileged Access Management, and Credential Management
  • Working knowledge of solutions such as CyberArk, SailPoint IdentityIQ, Entra ID, Okta, and HashiCorp Vault.
  • 5 years’ experience in in risk identification, aggregation, analysis, and ranking
  • Strong metrics and performance management background including data management and analysis.
  • Strong knowledge in IT and operational risk management processes, methods, and tools
  • Strong knowledge of technology standards, risks, threats, prevention measures, and best practices.

Nice-to-have:

  • Experience in a large financial service company
  • Knowledge of Project Management (PMF) process/disciplines
  • Strong knowledge of various IT risk frameworks, methodologies, leading industry/assurance standards and regulations, as well as attestation reporting frameworks, such as NIST, COBIT, SOC2 reporting framework
  • Working knowledge of GRC tools (e.g., Archer, ServiceNow, etc.)

What is in it for you?We thrive on the challenge to be our best, progressive thinking, to keep growing, and working together to build and deliver trusted reporting to help our stakeholders succeed and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation.
  • Ability to make a difference and lasting impact.
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • Opportunities to take on progressively greater accountabilities.

Job Skills Confidentiality, Cybersecurity, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Identity Access Management (IAM), Information Security Management, Information Technology (IT) Risk, Information Technology Security, Key Risk Indicators, Operational Risks, Risk Appetite, Risk Assessments, Risk Control Assessment, Risk Management, RiskMetrics, Risk Profile, Risk Reporting, Strategic Thinking, Technology RiskAdditional Job DetailsAddress: 20 KING ST W:TORONTOCity: TORONTOCountry: CanadaWork hours/week: 37.5Employment Type: Full timePlatform: GROUP RISK MANAGEMENTJob Type: RegularPay Type: SalariedPosted Date: 2025-01-15Application Deadline: 2025-03-15Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date aboveInclusion and Equal Opportunity EmploymentAt RBC, we embrace diversity and inclusion for innovation and growth. We are committed to building inclusive teams and an equitable workplace for our employees to bring their true selves to work. We are taking actions to tackle issues of inequity and systemic bias to support our diverse talent, clients and communities.We also strive to provide an accessible candidate experience for our prospective employees with different abilities. Please let us know if you need any accommodations during the recruitment process.Join our Talent CommunityStay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at .

KPMG – GTA Office – Opportunities in Risk Services – Cyber Security – Summer Internship/Co-op – Summer 2025 – Toronto, ON

Company: KPMG

Location: Toronto, ON

Expected salary:

Job date: Wed, 12 Mar 2025 01:33:04 GMT

Job description: . Specific responsibilities include but are not limited to: Support the project manager with day-to-day activities, ensuring… smooth project execution and coordination. Oversee and maintain the project planning tool (an Excel-based tool), ensuring…

that all project plans are up-to-date and accurate. Coordinate with team members to gather and input data, track progress, and identify any issues or roadblocks. Communicate regularly with stakeholders to provide updates on project status and potential risks. Assist in the development of project documentation, including reports, presentations, and meeting agendas. Manage project schedules and timelines, ensuring deadlines are met and tasks are completed on time. Support the project manager in identifying opportunities for process improvement and implementing best practices.

Deloitte – Cloud Cyber Defense Engineer, Deloitte Global Technology – Toronto, ON

Company: Deloitte

Location: Toronto, ON

Expected salary: $69000 – 114000 per year

Job date: Thu, 27 Feb 2025 23:53:29 GMT

Job description: Job Type: Permanent
Work Model: Remote
Reference code: 128558
Primary Location: Toronto, ON
All Available Locations: Toronto, ONOur PurposeAt Deloitte, we are driven to inspire and help our people, organization, communities, and country to thrive. Our Purpose is to build a better future by accelerating and expanding access to knowledge. Purpose defines who we are and gives us reason to exist as an organization.By living our Purpose, we will make an impact that matters.

  • Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
  • Experience a firm where wellness matters.
  • Be expected to share your ideas and to make them a reality.

What will your typical day look like?As a Cloud Cyber Defense Engineer, you will:

  • Be responsible for bringing thought leadership, influence, gathering technical requirements, evaluating solutions, and executing on deliverables addressing Deloitte policies around Private and Public Cloud solutions.
  • Lead and coordinate the work of an integrated project team comprised of multiple technical disciplines, including developers, subject matter experts, cyber defense engineers, SIEM/SOC professionals, and system architects to implement and maintain enterprise-level strategy coordination.
  • Work as an advisor and communicate to leadership and across key cloud cyber teams concerning the planning, development, design, procurement, maintenance, and implementation of enterprise-level cloud cyber defense systems and strategies.
  • Leverage your experience and background in Security Operations Centers (SOC) with security orchestration, automation, and response (SOAR) concepts alongside incident response (IR) processes and procedures to mature existing security products and strategies and operationalize new ones.
  • Lead and deliver secure cloud ecosystem services across multiple Cloud Service Providers and work across Cloud teams and Business units to define security requirements and deliver cloud security platform solutions.
  • Serve as a technical leader on all Cyber matters from best practices to Cloud controls covering required compliance requirements based on data classification.

About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in “what is” but rather “what can be” to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.Enough about us, let’s talk about youRequired:

  • A bachelor’s degree in computer science, Management of Information Systems Security, or equivalent professional experience
  • 2 or more years of experience building, deploying and operating security infrastructure and services within AWS, Azure or GCP.
  • 2 or more years of experience in the following areas:
  • Implementing and integrating cloud security defensive and posture management solutions adhering to and supporting cloud security frameworks / controls such as CSA, MITRE, NIST and ISO and other industry standards as available.
  • Operational experience in one of the following (Defender for Cloud, Guard Duty, Security Command Centre).
  • Participating in and interfacing with Security Operations Center (SOC) and/or Incident Response (IR) teams.
  • SIEM, CSPM and/or CNAPP administration and integration.
  • Successfully operating within Agile environment in accordance with Scrum best practices supporting large scale enterprise Cloud projects from ideation to production.
  • A background in general cloud security practices such as identity and access management (IAM), encryption, security information and event management (SIEM), Cloud Native Application Protection Platforms (CNAPP) and supporting technologies.

Total RewardsThe salary range for this position is $69,000 – $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people’s unique strengths and contributions and rewarding the value that they deliver.Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. Some representative examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, 38+ days off (including 10 firm-wide closures known as “Deloitte Days”), flexible work arrangements and a hybrid work structure.Our promise to our people: Deloitte is where potential comes to life.Be yourself, and more.We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance.You shape how we make impact.Diverse perspectives and life experiences make us better. Whoever you are and wherever you’re from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute.Be the leader you want to beSome guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader.Have as many careers as you want.We are uniquely able to offer you new challenges and roles – and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors.The next step is yoursAt Deloitte, we are all about doing business inclusively – that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our , and the .We encourage you to connect with us at if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis).By applying to this job you will be assessed against the Deloitte Global Talent Standards. We’ve designed these standards to provide our clients with a consistent and exceptional Deloitte experience globally.Deloitte Canada has 20 offices with representation across most of the country. We acknowledge that Deloitte offices stand on traditional, treaty, and unceded territories in what is now known as Canada. We recognize that Indigenous Peoples have been the caretakers of this land since time immemorial, nurturing its resources and preserving its natural beauty. We acknowledge this land is still home to many First Nations, Inuit, and Métis Peoples, who continue to maintain their deep connection to the land and its sacred teachings. We humbly acknowledge that we are all Treaty people, and we commit to fostering a relationship of respect, collaboration, and stewardship with Indigenous communities in our shared goal of reconciliation and environmental sustainability.

Deloitte – Cloud Cyber Defense Engineer, Deloitte Global Technology – Toronto, ON

Company: Deloitte

Location: Toronto, ON

Expected salary: $69000 – 114000 per year

Job date: Fri, 28 Feb 2025 02:09:03 GMT

Job description: Job Type: Permanent
Work Model: Remote
Reference code: 128558
Primary Location: Toronto, ON
All Available Locations: Toronto, ONOur PurposeAt Deloitte, we are driven to inspire and help our people, organization, communities, and country to thrive. Our Purpose is to build a better future by accelerating and expanding access to knowledge. Purpose defines who we are and gives us reason to exist as an organization.By living our Purpose, we will make an impact that matters.

  • Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
  • Experience a firm where wellness matters.
  • Be expected to share your ideas and to make them a reality.

What will your typical day look like?As a Cloud Cyber Defense Engineer, you will:

  • Be responsible for bringing thought leadership, influence, gathering technical requirements, evaluating solutions, and executing on deliverables addressing Deloitte policies around Private and Public Cloud solutions.
  • Lead and coordinate the work of an integrated project team comprised of multiple technical disciplines, including developers, subject matter experts, cyber defense engineers, SIEM/SOC professionals, and system architects to implement and maintain enterprise-level strategy coordination.
  • Work as an advisor and communicate to leadership and across key cloud cyber teams concerning the planning, development, design, procurement, maintenance, and implementation of enterprise-level cloud cyber defense systems and strategies.
  • Leverage your experience and background in Security Operations Centers (SOC) with security orchestration, automation, and response (SOAR) concepts alongside incident response (IR) processes and procedures to mature existing security products and strategies and operationalize new ones.
  • Lead and deliver secure cloud ecosystem services across multiple Cloud Service Providers and work across Cloud teams and Business units to define security requirements and deliver cloud security platform solutions.
  • Serve as a technical leader on all Cyber matters from best practices to Cloud controls covering required compliance requirements based on data classification.

About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in “what is” but rather “what can be” to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.Enough about us, let’s talk about youRequired:

  • A bachelor’s degree in computer science, Management of Information Systems Security, or equivalent professional experience
  • 2 or more years of experience building, deploying and operating security infrastructure and services within AWS, Azure or GCP.
  • 2 or more years of experience in the following areas:
  • Implementing and integrating cloud security defensive and posture management solutions adhering to and supporting cloud security frameworks / controls such as CSA, MITRE, NIST and ISO and other industry standards as available.
  • Operational experience in one of the following (Defender for Cloud, Guard Duty, Security Command Centre).
  • Participating in and interfacing with Security Operations Center (SOC) and/or Incident Response (IR) teams.
  • SIEM, CSPM and/or CNAPP administration and integration.
  • Successfully operating within Agile environment in accordance with Scrum best practices supporting large scale enterprise Cloud projects from ideation to production.
  • A background in general cloud security practices such as identity and access management (IAM), encryption, security information and event management (SIEM), Cloud Native Application Protection Platforms (CNAPP) and supporting technologies.

Total RewardsThe salary range for this position is $69,000 – $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people’s unique strengths and contributions and rewarding the value that they deliver.Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. Some representative examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, 38+ days off (including 10 firm-wide closures known as “Deloitte Days”), flexible work arrangements and a hybrid work structure.Our promise to our people: Deloitte is where potential comes to life.Be yourself, and more.We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance.You shape how we make impact.Diverse perspectives and life experiences make us better. Whoever you are and wherever you’re from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute.Be the leader you want to beSome guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader.Have as many careers as you want.We are uniquely able to offer you new challenges and roles – and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors.The next step is yoursAt Deloitte, we are all about doing business inclusively – that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our , and the .We encourage you to connect with us at if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis).By applying to this job you will be assessed against the Deloitte Global Talent Standards. We’ve designed these standards to provide our clients with a consistent and exceptional Deloitte experience globally.Deloitte Canada has 20 offices with representation across most of the country. We acknowledge that Deloitte offices stand on traditional, treaty, and unceded territories in what is now known as Canada. We recognize that Indigenous Peoples have been the caretakers of this land since time immemorial, nurturing its resources and preserving its natural beauty. We acknowledge this land is still home to many First Nations, Inuit, and Métis Peoples, who continue to maintain their deep connection to the land and its sacred teachings. We humbly acknowledge that we are all Treaty people, and we commit to fostering a relationship of respect, collaboration, and stewardship with Indigenous communities in our shared goal of reconciliation and environmental sustainability.

RSM International – Cyber Testing Consulting Associate – Summer 2025 – Toronto, ON

Company: RSM International

Location: Toronto, ON

Expected salary: $60720 – 72450 per year

Job date: Wed, 19 Feb 2025 07:52:25 GMT

Job description: Time management and project delivery Communication skills Examples of candidate’s responsibilities include: Assess… Professionals® (CISSP®); Certified Information Systems Auditor® (CISA®), Certified Information Security Manager® (CISM®), Certified…

This content discusses the importance of time management and communication skills in project delivery. It also lists examples of responsibilities of candidates in roles such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) and Certified Information Systems Security Professional (CISSP).

Scotiabank – Senior Manager, Cyber & IT Risk, Global Risk Management – Toronto, ON

Company: Scotiabank

Location: Toronto, ON

Expected salary:

Job date: Fri, 17 Jan 2025 02:53:44 GMT

Job description: Requisition ID: 214621Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.As the Senior Manager, Cyber Security and IT Risk, you will contribute to the overall successful development and execution of a second line of defense program for Cyber Security and IT Risk, perform assessments of risk management practices carried out by the first lines of defense, and carry out quantitative analysis of threat and vulnerability scenarios which may impact IT systems operations as well as business processes supporting the Bank’s multiple delivery channels, ensuring all operate within the Bank’s risk appetite levels for Cyber Security and IT services.You will contribute to the development, execution and ultimately the overall success of a second line of defense function within the Global Cyber Security and IT Risk Management Program. You will also deliver challenge and carry out independent assessment and oversight of risk management practices carried out by the first line of defense.This role particularly supports the Tangerine portfolio.Is this role right for you? In this role, you will:

  • Deliver objective evaluation and oversight of risk management practices carried out by the first line of defense to ensure that the Tangerine’s processes and controls relating to Cyber Security and IT Risks are sufficient to maintain the consistent operation of systems, the continuous availability and integrity of data and the confidentiality of sensitive information.
  • Rank and quantify cyber, IT, and related risks in terms of probability of event and potential dollar impact.
  • Design scoring and quantification methodologies to support risk appetite discussions and enable sound decision making.
  • At Tangerine, guide IT, Security, and other control functions on Cyber Security and IT Risk management processes, systems and procedures; review and provide advice relating to policies frameworks, standards and control objectives; and ultimately build and sustain a risk aware culture.
  • Collaborate with internal and external partners to ensure information sharing and support complementary and contrasting risk oversight initiatives as appropriate
  • Establish and maintain effective relationships with all key stakeholders and applicable support areas across Tangerine Bank and the BNS ERM team, to remain current on new developments and emerging risks
  • Participate in major incident investigation when necessary, validating root cause of; IT and Cyber related incidents and loss events to the relevant failures in IT control processes, as well as quantitative loss impacts as assessed by the 1st line of Defense
  • Monitor the IT Risk Profile, KRIs and associated Risk Metrics of Tangerine Bank to proactively identify changes in the profile and emerging risks, while reporting on identified information technology and cyber-security vulnerabilities in terms business executives can understand and use
  • Periodically analyze risks to identify common themes, patterns or trends at an aggregate level
  • Support in-depth analysis on areas with high inherent risk and evaluate the effectiveness of risk responses
  • Monitor and report the status of Management’s IT risk response plans
  • Support the identification and reporting submissions for Tangerine IT Risk related information for regulatory requirements.

Do you have the skills that will enable you to succeed? We’d love to work with you if you have:

  • 7 to 10 years of experience with IT Operations, IT System Development Life Cycle (SDLC), IT and/or Cyber Risk Management, Governance, and/or Audit. Information/Cybersecurity subject matter expertise is an asset.
  • Strong communication, listening, presentation and facilitation skills
  • Excellent interpersonal, leadership and relationship-building skills to deal with senior levels of management and local and remote business partners
  • Demonstrated ability to analyze complex data in order to arrive at succinct messages and conclusions
  • Strong strategic and critical thinking to influence enterprise risk program
  • Experience across multiple Cyber and IT Operations areas (Change, Capacity, Continuity, Incident, Problem, etc.) in a large organization
  • Experience using of GRC risk management tools
  • Experience using COBIT, ITIL and other IT Operation specific industry frameworks
  • Professional certifications and membership of associations such as CRISC, CISA, CISSP, CISM, etc. are an asset

What’s in it for you?

  • An inclusive & collaborative working environment that encourages creativity, curiosity, and celebrates success!
  • We offer a competitive rewards package: Performance bonus, Employee Share Ownership Program, and Pension Plan Matching, Health Benefits from day one!
  • Your career matters! You will have access to career development and progression opportunities.

Location(s): Canada : Ontario : TorontoScotiabank is a leading bank in the Americas. Guided by our purpose: “for every future”, we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please . Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

VP – Audit Manager – Cyber/ InfoSec (Hybrid) – Citigroup – Mississauga, ON

Company: Citigroup

Location: Mississauga, ON

Expected salary:

Job date: Thu, 16 Jan 2025 00:04:13 GMT

Job description: The Audit Manager– Cyber/InfoSec Audit, is an intermediate level role responsible for leading an audit team… in performing Cyber/IS audits and assessments of Citi’s risk and control environments. In addition to being Audit Lead, the manager

Scotiabank – Senior Manager, Cyber & IT Risk, Global Risk Management – Toronto, ON

Company: Scotiabank

Location: Toronto, ON

Expected salary:

Job date: Thu, 16 Jan 2025 23:45:12 GMT

Job description: Requisition ID: 214621Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.As the Senior Manager, Cyber Security and IT Risk, you will contribute to the overall successful development and execution of a second line of defense program for Cyber Security and IT Risk, perform assessments of risk management practices carried out by the first lines of defense, and carry out quantitative analysis of threat and vulnerability scenarios which may impact IT systems operations as well as business processes supporting the Bank’s multiple delivery channels, ensuring all operate within the Bank’s risk appetite levels for Cyber Security and IT services.You will contribute to the development, execution and ultimately the overall success of a second line of defense function within the Global Cyber Security and IT Risk Management Program. You will also deliver challenge and carry out independent assessment and oversight of risk management practices carried out by the first line of defense.This role particularly supports the Tangerine portfolio.Is this role right for you? In this role, you will:

  • Deliver objective evaluation and oversight of risk management practices carried out by the first line of defense to ensure that the Tangerine’s processes and controls relating to Cyber Security and IT Risks are sufficient to maintain the consistent operation of systems, the continuous availability and integrity of data and the confidentiality of sensitive information.
  • Rank and quantify cyber, IT, and related risks in terms of probability of event and potential dollar impact.
  • Design scoring and quantification methodologies to support risk appetite discussions and enable sound decision making.
  • At Tangerine, guide IT, Security, and other control functions on Cyber Security and IT Risk management processes, systems and procedures; review and provide advice relating to policies frameworks, standards and control objectives; and ultimately build and sustain a risk aware culture.
  • Collaborate with internal and external partners to ensure information sharing and support complementary and contrasting risk oversight initiatives as appropriate
  • Establish and maintain effective relationships with all key stakeholders and applicable support areas across Tangerine Bank and the BNS ERM team, to remain current on new developments and emerging risks
  • Participate in major incident investigation when necessary, validating root cause of; IT and Cyber related incidents and loss events to the relevant failures in IT control processes, as well as quantitative loss impacts as assessed by the 1st line of Defense
  • Monitor the IT Risk Profile, KRIs and associated Risk Metrics of Tangerine Bank to proactively identify changes in the profile and emerging risks, while reporting on identified information technology and cyber-security vulnerabilities in terms business executives can understand and use
  • Periodically analyze risks to identify common themes, patterns or trends at an aggregate level
  • Support in-depth analysis on areas with high inherent risk and evaluate the effectiveness of risk responses
  • Monitor and report the status of Management’s IT risk response plans
  • Support the identification and reporting submissions for Tangerine IT Risk related information for regulatory requirements.

Do you have the skills that will enable you to succeed? We’d love to work with you if you have:

  • 7 to 10 years of experience with IT Operations, IT System Development Life Cycle (SDLC), IT and/or Cyber Risk Management, Governance, and/or Audit. Information/Cybersecurity subject matter expertise is an asset.
  • Strong communication, listening, presentation and facilitation skills
  • Excellent interpersonal, leadership and relationship-building skills to deal with senior levels of management and local and remote business partners
  • Demonstrated ability to analyze complex data in order to arrive at succinct messages and conclusions
  • Strong strategic and critical thinking to influence enterprise risk program
  • Experience across multiple Cyber and IT Operations areas (Change, Capacity, Continuity, Incident, Problem, etc.) in a large organization
  • Experience using of GRC risk management tools
  • Experience using COBIT, ITIL and other IT Operation specific industry frameworks
  • Professional certifications and membership of associations such as CRISC, CISA, CISSP, CISM, etc. are an asset

What’s in it for you?

  • An inclusive & collaborative working environment that encourages creativity, curiosity, and celebrates success!
  • We offer a competitive rewards package: Performance bonus, Employee Share Ownership Program, and Pension Plan Matching, Health Benefits from day one!
  • Your career matters! You will have access to career development and progression opportunities.

Location(s): Canada : Ontario : TorontoScotiabank is a leading bank in the Americas. Guided by our purpose: “for every future”, we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please . Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.