Manager, U.S. Information Security & Control
Scotiabank - Dallas, TX
Apply NowJob Description
Manager, U.S. Information Security & Control Requisition ID: 244792 Salary Range: 76,600.00 - 142,300.00 _Please note that the Salary Range shown is a guideline only. Salary offered may vary based on factors, including, but not limited to, the successful candidateu2019s relevant knowledge, skills, and experience._ Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. Global Banking and Markets Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabanku2019s strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world. Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group. Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries We work together to drive ambition for every future Purpose The Cyber and Regulatory Audit Manager will participate and manage various aspects of information security, cyber risk assessments, and contribute to the overall success of the U.S. IS&Cu2019s governance, regulatory compliance, and risk program. This role requires a seasoned professional with a strong background in information security, risk management, cybersecurity technology risk, compliance, policy, and governance. The IS&C Manager will assist with regulatory responses, audit requests, and participate in various cybersecurity risk assessments, risk mitigation strategies, and safeguard the Bank from potential informational security threats. The person will also play a role in reviewing and implementing security policies, procedures, and controls to protect the organization's data, systems, and networks. The position will be expected to work closely with cross-functional teams to establish and maintain a robust cybersecurity and technology risk management program to proactively safeguard the organization from security threats by ensuring that vulnerabilities are identified, monitored, and treated, as well as assuring the Bank meets regulatory compliance. What You'll Do u2022 Regulatory and Compliance Management (specific to cybersecurity): - Participates in engagements with external regulatory and internal/3rd party auditors requests for information security and cybersecurity. - Monitors, analyzes, and reports on cybersecurity requirements against relevant U.S. regulations and cybersecurity standards, such as NYSDFS, FFIEC, and NIST CSF. - Provides support to IT&S auditors and compliance with respect to regulatory and audit information requests. - Continuously monitors and assesses the effectiveness of security controls and processes. - Reviews cybersecurity control library periodically and provides updates as needed. - Participate in annual regulatory control testing exercises. u2022 Cybersecurity and Technology Risk Governance: - Understand how the Banku2019s risk appetite and risk culture should be considered in day-to-day activities and decisions. - Identifies and assesses cybersecurity and technology risks to ensure compliance with regulations and internal policies. - Performs cybersecurity risk assessments and provide updates to US IS&C senior management. u2022 Risk and Issues Management: - Reports and tracks all cybersecurity-related issues that pertain to audits, regulatory requirements, control testing, and other issues. - Provides guidance to internal stakeholders on cybersecurity best practices. - Prepares regular reports and presentation decks on risk management, gap assessment, cybersecurity-related issues for senior management and stakeholders. - Monitors and tracks the progress of risk mitigation efforts related to cybersecurity. - Participates in quarterly and annual Compliance Risk and Control Assessments for cybersecurity. u2022 Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabanku2019s Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk. u2022 Champions a high-performance environment and contributes to an inclusive work environment. What You'll Bring u2022 Required 5+ years of experience as an Information Security Analyst or related cybersecurity field with technology risk background. u2022 Experience in IT key security controls/mechanisms and risk assessment concepts pertaining to complex data, application, and networking environments. u2022 Prior experience and knowledge with NYDFS, FFIEC, or other US financial regulatory audits. u2022 Have strong verbal and written communication skills in English with excellent individual project management and tracking skills. u2022 Cybersecurity related certification is preferred (CISSP, CCSP, CRISC, CISM). u2022 University degree or college diploma in a cybersecurity related field is preferred. Interested? If your experience is closely related but doesnu2019t align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. Thatu2019s why we work to grow and diversify talent and engage employees in a performance-oriented culture. What's in it for you? Scotiabank wants you to be able to bring your best self to work u2013 and life, every day. With a focus on holistic well-being, our many flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs. #Dallas Location(s): United States : Texas : Dallas Scotiabank is a leading bank in the Americas. Guided by our purpose:
Created: 2025-12-17