Director, Internal Audit - Technology, Information Security and AI NUMÉRO DE POSTE: 480324
The Director, Internal Audit – Technology, Information Security, and AI leads the planning and delivery of risk-based audits and advisory work across the Bank’s technology and digital risk domains. This role provides independence assurance over technology risks across ITGCs, cybersecurity governance, cloud governance, data management, AI, and technology operations. The Director is expected to exercise independent authority and credible challenge with senior technology leaders including the Chief Technology Officer (CTO) and their leadership team ensuring that technology risks, control gaps, and remediation commitments are appropriately identified, debated, and addressed.
The role requires sufficient technical knowledge and professional competence to engage in difficult, sometimes adversarial conversations with technology leadership, while maintaining a constructive, respected, and independent relationship. Co-sourced SMEs may support deep technical assessments; however, the Director must independently interpret results, synthesize risk implications, and challenge management where standards or practices are insufficient.
About the Opportunity
Risk Assessment & Strategy Planning (20%)
- Own and maintain the technology audit universe for core domains: Technology Strategy, Data, and AI, Technology Integration, Software Engineering, Digital Services, Technical Services & Performance, Technology Operations, and Information & Cyber Security.
- Maintain awareness of technological changes in both external and internal environments including trends in risk management practices and regulatory expectations, and changes in business activities to perform quarterly risk assessments for the technology audit entities within the Internal Audit Universe.
- Lead the annual technology risk assessment, identify appropriate audits to be included in the annual audit plan and help develop the Plan for the Audit Committee approval.
- Identify emerging risks within the Technology audit portfolio (e.g., cyber threats, cloud adoption, data privacy), monitor these risks to determine their impact, and assess changes needed for the annual audit plan or planned audits. Incorporate changes as appropriate.
- Oversee execution and end-to-end delivery of all audit projects within the Technology audit universe, ensuring all documentation and audit reports are complete, and projects are appropriately and effectively staffed. Coordinate use of co-sourced technical experts for deep cyber/cloud/AI testing where needed.
- Lead opening and closing meetings, ensuring audit project planning is appropriately completed, reviewing audit working papers, and preparing/reviewing draft internal audit report for each project. Review control design and effectiveness using industry frameworks (NIST CSF, ISO 27001, COBIT).
- Deliver balanced and insightful reporting to the Chief Internal Auditor and Audit Committee on technology risk posture, themes, and systemic gaps.
- Oversee remediation/closure of IT audit findings, OSFI findings including tracking closure to due dates, the validation of findings with management, ensuring appropriate responses are received, and appropriate quality assurance practices are followed.
- Provide independent advice during major technology initiatives (policy& standards enhancements, modernization, cloud migration, data platform enhancements) from governance and risk lens and collaborate with stakeholders to embed controls early.
- Develop and maintain independent and influential relationships with senior technology stakeholders, including the CTO, CISO, Data & Privacy leadership, and enterprise risk partners (i.e., ERM, ORM, Compliance).
- Develop and maintain working relationships with the Bank’s external auditors to support their direct assistance and or audit reliance model.
- Demonstrate the authority, credibility, and technical understanding necessary to challenge technology decisions, risk acceptances, and control deficiencies especially in areas where management believes risks are mitigated.
- Facilitate difficult discussions with technology leadership by articulating risk impacts, regulatory expectations, and control considerations in a clear and authoritative manner.
- Lead a team of IT audit professionals with a mix of internal capabilities and co-sourced specialists.
- Mentor team members to deepen expertise in ITGCs, cyber governance, and foundational cloud/data risks.
- Ensure all technology audit work adheres to the Global Internal Audit Standards (GIAS) and Internal Audit methodology. Contribute to annual review of audit practices and methodology against relevant benchmarks.
- Map controls to recognized frameworks as appropriate: NIST CSF/800-53, ISO 27001/27701, COBIT, CIS Controls, CSA CCM, PCI DSS (if applicable), and applicable privacy regulations. Recommend changes to audit processes, methodology and reporting to improve effectiveness.
- Champion continuous improvement, agile auditing methods, and data-driven audit techniques (CAATs, automation, scripts, and continuous monitoring).
- Promote tooling: GRC, ticketing/ITSM (e.g., ServiceNow), CI/CD, CSP native security tooling, CSPM/CWPP, SIEM/SOAR, data lineage/governance tools, and model monitoring platforms.
- University degree in information systems, Computer Science, Engineering, Accounting, or related field.
- Certified Information Security Audit designation.
- Certifications in the following are preferred:
- Audit: CIA, Risk: CRISC, CGEIT, Security: CISSP, CISM, CCSP, ISO 27001
- Cloud: AWS/Azure/GCP security or architecture certifications
- Data/Privacy: CDMP, CIPT/CIPM/CIPP, ISO 27701
- 10 years of progressive experience within the Financial Services Industry.
- Solid Information Technology (IT)/Information Security (IS) audit and/or similar management experience in a regulated financial institution.
- Strong experience leading audits of information technology, information security, data management, and project management, in conformance with IIA Standards.
- Excellent understanding of risk management and related governance concepts, tools, techniques and best practices gained from practical financial services experience.
- Strong command of at least three of the following: ITGCs, cybersecurity operations, cloud security/ governance, data governance/quality/privacy, SDLC/DevSecOps, AI/ML governance/model risk.
- Strong understanding of the Bank’s risk tolerance, risk management, & risk assessment activities.
- Technical auditing proficiency in a regulated financial services environment, including strong analytical risk assessment and problem-solving skills.
- Ability to counsel and advise on complex risk situations affecting the organization, within the context of audit assignments, including recommendations on related risk management.
- Excellent communication, decision making, time management, negotiation, and influencing skills.
- Leads and demonstrates knowledge, teamwork, cross-unit cooperation and information and consistently demonstrates and reinforces organizational values.
- Solution-focused and takes initiative ensuring self and team work effectively and efficiently within established guidelines.
- Ability to lead a strategic and progressive approach to provide value-added recommendations to leaders across the Bank.
Pay Rate:
$80/Hour
How to Apply
Click the “Apply Now” button and follow the instructions to submit your resume. Please note that we only accept documents in MS Word or Rich Text formats. When referencing this job, quote #480324.
This position for employment is for a current vacancy with Vaco/Highspring’s client. You must currently reside within the Greater Toronto Area and be permitted to work in Canada to be considered for this opportunity. A recruiter will be in touch with you if your profile meets our client’s requirements for this role
Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company’s 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products.
Avis sur l’égalité en matière d’emploi
Vaco by Highspring est un employeur qui souscrit au principe de l’égalité en matière d’emploi et qui ne pratique aucune discrimination à l’égard des employés ou candidats à un emploi sur le plan de la race (notamment en ce qui a trait aux caractéristiques historiquement associées à la race, comme la texture des cheveux et la coiffure), couleur de la peau, le sexe (ce qui inclut l’état de grossesse ou les conditions connexes), la religion ou les croyances, l’origine nationale, la citoyenneté, l’âge, le handicap, le statut d’ancien combattant, l’adhésion à un syndicat, l’appartenance ethnique, le genre, l’identité de genre, l’expression de genre, l’orientation sexuelle, l’état civil, l’affiliation politique ou autre caractéristique protégée par les lois fédérales, d’État ou locales.
Vaco by Highspring et sa société mère, ses sociétés affiliées et ses filiales s’engagent à la pleine inclusion de toutes les personnes qualifiées. Dans le cadre de cet engagement, Vaco by Highspring et sa société mère, ses sociétés affiliées et ses filiales veilleront à ce que les personnes handicapées bénéficient de mesures d’adaptation raisonnables. Si des mesures d’adaptation raisonnables sont nécessaires pour vous permettre de participer au processus de candidature ou d’entretien d’embauche, d’exercer les fonctions essentielles du poste et/ou de bénéficier d’autres avantages et privilèges liés à l’emploi, veuillez contacter HR@vaco.com.
Vaco by Highspring souhaite également que tous les candidats sachent que la loi interdit la discrimination dans le milieu de travail.
Avis de représentation
En soumettant votre candidature à ce poste, vous convenez que vous accordez à Vaco by Highspring le droit exclusif de vous présenter en tant que candidat eu égard à l’offre d’emploi susmentionnée. Vous reconnaissez en outre que vous avez fourni des renseignements exacts sur vous-même et que vous n’avez pas volontairement dénaturé vos qualifications. Dans toute la mesure permise par la loi, vous vous engagez également à garder confidentiels tous les renseignements que vous obtiendrez de Vaco by Highspring concernant le poste et à ne divulguer les renseignements relatifs au poste que si cela est absolument nécessaire pour respecter une obligation afférente à votre candidature. En contrepartie, Vaco by Highspring s’engage à déployer des efforts raisonnables pour vous représenter dans le cadre de toute sollicitation, présélection en matière d’emploi et diffusion de CV.
Concernant les résidents de l’Ontario, Canada : d’après ce que Highspring retient de ses discussions avec son Client ce poste est actuellement vacant (soit par le truchement de Highspring en tant que sous-traitant, soit auprès du Client).
Avis de confidentialité
Vaco by Highspring, ainsi que sa société mère, ses sociétés affiliées et ses filiales (« nous », « notre/nos » ou « Vaco by Highspring ») respectent votre vie privée et s’engagent à vous informer de ses politiques en toute transparence.
- Les résidents de la Californie peuvent consulter l’Avis de collecte par les RH de Vaco by Highspring concernant les candidats et les employés de la Californie ici.
- Les résidents de la Virginie peuvent consulter nos politiques propres à l’État ici.
- Les résidents de tous les autres États peuvent accéder à nos politiques ici.
- Les résidents canadiens peuvent consulter nos politiques en anglais ici et en français ici.
- Les résidents des pays régis par le RGPD peuvent consulter nos politiques ici.
De plus, les candidatures à ce poste seront soumises à une présélection des candidats effectuée par l’IA visant à vérifier que les exigences minimales indiquées au titre du poste sont respectées. Vous trouverez plus de détails sur l’utilisation de l’IA par Vaco by Highspring ici (https://www.highspring.com/ai-use-notices/). L’évaluation des candidatures après cette phase initiale sera menée par des recruteurs et gestionnaires d’embauche. Vaco by Highspring n’a pas d’information ni d’opinion sur l’utilisation de solutions d’IA par son client dans le cadre de l’embauche.
Avis sur la transparence salariale
La rémunération fixée pour ce poste, et d’autres, auprès de Vaco by Highspring dépend de nombreux facteurs,notamment :
- les compétences, l’expérience et la formation de la personne;
- les exigences en matière de permis d’exercice et de certification;
- l’emplacement du bureau et autres considérations géographiques;
- d’autres besoins commerciaux et organisationnels.
Cela étant, conformément à la loi locale, Vaco by Highspring estime qu’en fonction des critères susmentionnés, la fourchette salariale suivante constitue une estimation raisonnable de la rémunération de base pour une personne embauchée à ce poste dans les régions géographiques exigeant la divulgation de la fourchette salariale. Le ou la titulaire du poste peut également être admissible à des primes discrétionnaires.