About the job
Job ID: AR1019Direct Employer: The City of TorontoJob Title: Senior Specialist Risk Management Division: Office of the Chief Information Security OfficerReports to: Manager Risk Management Centre of ExcellenceLocation: Toronto, OntarioJob Type: Permanent, Full TimeSalary Range: $126,000 to $176,140Shift Information: Monday to Friday, 35 hours work week
Consider your new role with Aliant Resources and our municipal government client, The City of Toronto.
About UsAliant Resources is a dedicated provider of IT recruiting services, committed to promoting diversity, equity, inclusion, belonging, anti-racism, and accessibility in all facets of our operations.
Job Summary:To support the Manager of Risk Management Centre of Excellence and the Chief Information Security Officer (CISO) in maintaining a City-wide cyber security program that enhances protection across the organization.To provide strategic cyber risk management expertise by identifying, assessing, and mitigating enterprise-wide risks across City divisions, agencies, and corporations.To lead the development and execution of governance, risk, and compliance (GRC) frameworks, ensuring alignment with regulatory requirements, industry best practices, and corporate policies.To oversee risk remediation planning, monitor compliance initiatives, and provide guidance to senior leadership on risk-related decisions to enhance the organization’s overall risk posture.
- Major Responsibilities:Oversees risk remediation plans, ensuring timely implementation of mitigation strategies in collaboration with stakeholders.
- Drives the governance, risk, and compliance (GRC) program by developing policies, frameworks, and controls to manage enterprise risks effectively.
- Provides expert guidance on regulatory compliance, internal controls, and risk mitigation strategies to support business objectives.
- Monitors emerging risks, industry trends, and regulatory changes to proactively adjust risk management strategies.
- Prepares risk reports, dashboards, and presentations for executive leadership, identifying key risk exposures and recommended actions.
- Develops and delivers training programs to enhance risk awareness and promote a risk-conscious culture across the organization.
- Collaborates with senior leaders and cross-functional teams to integrate risk management into strategic planning and decision-making.
- Qualifications/Certifications: Post-secondary degree in Business or Technology or a related discipline.
- Over six years of experience in Risk Management primarily focused on cyber risk management.
- Extensive knowledge of elements of risk, including vulnerability, threat, likelihood, impact, mitigation, and remediation.
- Extensive expertise in Information Security or Governance, Risk & Compliance (GRC).
- Extensive experience in conducting third-party assessments, especially on small and medium-sized service providers.
- Must have extensive experience in a Soc 2 Type II report and ISO 27001 Certification.
- Experience in conducting PCI assessments or preparing an organization for PCI audits.
- Must have experience developing and implementing cyber policies and standards across an enterprise.
- Must have experience conducting risk assessments based on NIST cyber security framework and related standards.
- Preferred Certifications (at least two in the list): CISSP, CISA, CISM, CRISC.