The Opportunity
As the Senior IT Governance Specialist, you will establish, develop, and maintain the Global Data Technology risk management and cybersecurity governance frameworks, risk assessment methodologies, risk metrics reporting, and compliance protocols! You will coordinate risk analysis activities, control performance assessment and evaluate governance processes, and recommend improvement opportunities.
Responsibilities
- Supports development, implementation, and maintenance of Global Data Technology risk management and cybersecurity governance frameworks, policies, and procedures aligned with industry standards and regulatory requirements.
- Supports security and business leaders in defining KRIs/KPIs and metrics aligned with business initiatives and monitoring those to measure effectiveness of risk management and cybersecurity programs and initiatives.
- Coordinates risk analysis activities, IT general control performance assessment and evaluates governance processes supports development of complete information risk governance reporting capabilities.
- Monitors the implementation of IT general controls for technology and business project plans.
- Performs high quality analysis of risk data to identify causes of trends and works with information owners to document control plans.
- Maintains comprehensive documentation of governance-related processes and activities and supports updates of risk management and cybersecurity policies, standards, and guidelines.
- Collaborates with IT control execution teams to develop and maintain incident response plans, ensuring swift and effective responses to security incidents.
- Recommends improvements to enhance the overall risk, compliance and security processes, including the emerging AI technology.
Stays updated on evolving cybersecurity threats, risk assessment methodologies, and reports leading practices, contributing to the enhancement of risk reporting processes.
-
What motivates you?
- You obsess about customers, listen, engage and act for their benefit.
- You think big, with curiosity to discover ways to use your agile approach and enable business outcomes.
- You thrive in teams and enjoy getting things done together.
- You take ownership and build solutions, focusing on what matters.
- You do what is right, work with integrity and speak up.
You share your humanity, helping us build a diverse and inclusive work environment for everyone.
-
Required Qualifications:
- Degree holder of Computer Science, Information Technology, Software Engineering, Business Administration, or relevant educational and professional experience.
- Relevant professional designations (e.g. CISSP, CGEIT, CRISC, CISM, CISA).
- 8+ years of IT/Information Risk management experience: vendor risk management, project risk management, IT audit or IT controls assessment.
- 8+ years of experience in a combination of relevant technical disciplines in the field of Information Security: network security, application security, identity and access management, IT operations security, vulnerability management, information protection, physical security, cybersecurity.
- Deep knowledge of cloud computing security and IaaS, PaaS or SaaS environments.
- Knowledge of risk, security and AI frameworks (e.g. ISO 27001, COBIT, NIST), regulatory requirements and standards related to cybersecurity, privacy, and data protection laws relevant to the organization (e.g., GDPR, CCPA, AIDA, FEAT, Sarbanes-Oxley).
- Solid understanding of information security controls and risks, risk management, IT governance, and security tools and technologies
- Good communication, presentation, and facilitation skills to all levels and audiences.
- Problem solving, analytical, and innovative approach.
- Strong time management and organizational skills to manage multiple tasks and changing priorities.
Preferred Qualifications:
- Influence behavior to reduce risks and foster a strong information security risk management culture.
- Familiarity with information technology, operational risk, cybersecurity and regulatory compliance governance frameworks and their implementation
- Knowledge of security technologies
- Proficiency in using data visualization tools (e.g., Power BI, Grafana, etc.)
- Knowledge of statistical data analysis and reporting toolsets
Knowledge and understanding of the financial industry is preferred.
-
What can we offer you?
- A competitive salary and benefits packages.
- A growth trajectory that extends upward and outward, encouraging you to follow your passions and learn new skills.
- A focus on growing your career path with us.
- Flexible work policies and strong work-life balance.
Professional development and leadership opportunities.
-
Our commitment to you
- Values-first culture: We lead with our Values every day and bring them to life together.
- Boundless opportunity: We create opportunities to learn and grow at every stage of your career.
- Continuous innovation : We invite you to help redefine the future of financial services.
- Delivering the promise of Diversity, Equity and Inclusion: We foster an inclusive workplace where everyone thrives.
- Championing Corporate Citizenship: We build a business that benefits all partners and has a positive social and environmental impact.
#LI-Hybrid
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html .
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected] .
Toronto, Ontario
Hybrid
Salary range is expected to be between
$92,190.00 CAD - $171,210.00 CAD
If you are applying for this role outside of the primary location, please contact [email protected] for the salary range for your location. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance.
Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S., please contact [email protected] for more information about U.S.-specific paid time off provisions.