Manager, Cybersecurity & IT Risk, CNB Internal Audit
Royal Bank of Canada Voir toutes les offres
- Vancouver, BC
- Permanent
- Temps-plein
- Execute on the annual Audit Plan for CNB IT Cybersecurity and Infrastructure audit universe, ensuring that audits conform to local and global regulatory and internal audit requirements.
- Implement the execution of the audit plan and ensure effective audit practices for traditional and continuous audits. Collaborate with broader Global RBC and CUSO IT teams and departments to achieve the plan (where needed).
- Make recommendations to clients on control deficiencies and follow up to ensure significant deficiencies are corrected. Assist business management to develop appropriate action plans to address identified deficiencies, and ensure corrective actions are implemented in a timely manner to effectively address the issues.
- Plan and execute on moderate to complex and confidential/special audit projects enterprise wide as requested by senior management of the Bank.
- Communicate trends in risk and control issues to senior management on the results of ongoing reviews of the businesses that are key relationships, or any other business as requested.
- Provide support for CNB IT and US-wide regulatory requests, responses and meetings.
- Build, direct, counsel, and instruct staff assigned to an engagement and review audit plan, findings and reports for sufficient scope and for accuracy.
- Bachelor's degree or equivalent.
- Minimum 3-5 years banking / audit experience within Information Technology, with Cybersecurity and IT Risk audit experience, including understanding of network, desktop & server technologies, and experience with network intrusion methods, network containment, segregation techniques, and technologies such as Intrusion Detection Systems (IDS) & Intrusion Protection Systems (IPS).
- Minimum 2-3 years of business experience in a financial institution or technology company, dealing with multiple business platforms, business processes, geographies, and legal entities.
- Experience with Windows Active Directory & related exploits / misconfigurations, SIEM technologies, log management tools, and security analytics platforms.
- Familiarity with the software development lifecycle, Data Loss Prevention (DLP), and Microsoft SQL database functionality & exploitation, including cyber security open source tools.
- Knowledge of cloud architecture designs and patterns in multi-cloud and hybrid cloud environments.
- Understanding of Advanced Persistent Threat (APT), insider threat detection, network security, and traffic analysis hunting for malicious activity and initiating response actions, and demonstrable Threat hunting experience.
- Ability to leverage data and perform data analytics on them.
- CISA, CISM, CISSP, and/or CIA certification.
- A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation
- Leaders who support your development through coaching and managing opportunities
- Work in a dynamic, collaborative, progressive, and high-performing team
- Opportunities to do challenging work
- Flexible work/life balance options