Manager, Technology Risk Management, Information & Corporate Security (12 Month Contract) (Ontario)

Manager, Technology Risk Management, Information & Corporate Security (12 Month Contract) (Ontario)

08 Aug
|
CPP Investments
|
Ontario

08 Aug

CPP Investments

Ontario

Purpose. Performance. People. Joining CPP Investments means joining one of the world’s most admired and respected institutional investors to drive a single mandate: to deliver strong, sustainable returns for generations of Canadians. With a long-term horizon and global reach, we deploy capital at scale across public and private markets. Our size, stability, and disciplined investment philosophy allow us to pursue complex opportunities and build enduring partnerships worldwide. For our people, this means meaningful work with tangible impact, real opportunity, and collaboration with exceptional colleagues who value partnership and performance. Here, you’ll contribute to outcomes that matter alongside team members committed to excellence and shared success.
The Role Reporting to the Managing Director, Cyber & Technology Risk Management, you will execute first line of defence Technology and Information Security control testing to assess the design and operating effectiveness of key controls across the technology environment. You will partner with Technology, Engineering, Infrastructure, Cloud, Application, and Information Security teams to identify control gaps, support remediation, and strengthen CPP Investments' technology control environment through disciplined, risk-based testing and continuous improvement. The Team Technology & Operations enables CPP Investments' global investment platform by delivering secure, resilient, and innovative technology capabilities that support our long-term investment mandate. The department partners across the organization to manage technology risk while enabling business performance through effective governance, security, and operational excellence. The Cyber & Technology Risk Management team provides first line oversight of technology and information security controls by embedding risk management practices into day-to-day operations. The team partners closely with technology stakeholders to strengthen the control environment through consistent, scalable, and risk-based control testing practices.
Accountabilities Execute end-to-end Technology and Information Security control testing, including planning, walkthroughs, evidence review, sampling, re-performance, and documentation. Assess the design and operating effectiveness of technology and security controls using a risk-based approach aligned to applicable standards.



Develop and maintain control documentation, testing procedures, evidence requirements, and centralized control libraries to support consistent testing practices. Identify control deficiencies, determine root causes, and partner with control owners to develop practical and sustainable remediation plans. Track remediation activities, perform validation testing, and support audit readiness through coordination with second line risk and Internal Audit teams. Leverage data analytics, automation, and GRC tools to improve testing efficiency, evidence collection, and continuous control monitoring. Contribute to the ongoing enhancement of first line control testing methodologies, documentation standards, and quality assurance practices.
What You Bring Undergraduate degree in Computer Science, Information Security, Engineering, Risk Management, Business, or a related discipline.
6–8 years of progressive experience in Technology Risk, IT Audit, Information Security, Internal Controls, or a related discipline within a complex organization.
Professional certification such as CISA, CISM, CRISC, CISSP, or an equivalent designation is considered an asset.
Demonstrated experience executing Technology and Information Security control testing, including evidence inspection, sampling methodologies, and re-performance.
Strong understanding of technology risk and control frameworks including NIST CSF, NIST 800-53, ISO 27001, COBIT, COSO, and modern technology environments such as cloud platforms and DevSecOps.
Experience using automation, analytics, scripting, and GRC platforms (such as ServiceNow) to enhance control testing and monitoring.
Excellent analytical, communication, stakeholder management, and problem-solving skills, with the ability to translate technical findings into clear business risk insights.
You are motivated to contribute to something larger than yourself, approach complex challenges with rigor,



and hold yourself to high standards in a team-oriented, performance-driven environment. We provide colleagues with cutting-edge AI tools, dedicated learning time, and practical support to help them deliver with greater impact.
Inclusion & Accessibility CPP Investments is committed to equitable access to employment and building a workforce that reflects diverse talent and perspectives. If you require accommodation at any stage of the recruitment process, please let us know and we will work with you to meet your needs.
Attention: Protect Yourself from Fraud CPP Investments is committed to a secure and transparent recruitment process. We will never ask candidates for payment or financial information at any stage of hiring. All legitimate opportunities are posted on our careers page, and communications will come from our applicant tracking system, Workday. CPP Investments may use AI tools to help screen and assess applicants by analyzing resumes and applications for relevant skills and experience. These tools support, but do not replace, human decision-making.
About Us Why Work With Us For 25 years, we’ve proudly invested the Canada Pension Plan Fund, helping to secure retirement for more than 22 million Canadians. We invest for the long term — and that includes our people. Here, you’ll work alongside high-calibre colleagues on meaningful challenges that have real-world impact. Our purpose drives us, our performance sets us apart, and our people make it possible.
Our Guiding Principles Our guiding principles shape our culture. They define how we work and represent the values that guide our behaviours. They are Integrity, Partnership and High Performance.
Our Impact We invest globally across public and private markets, managing capital on behalf of millions of contributors and beneficiaries. We focus on long-term value creation and responsible investing, with offices in major financial centres around the world.
What You Can Expect Meaningful work with measurable impact
Exposure to complex, global challenges
Opportunities for learning and growth
Competitive total rewards and benefits
Comprehensive wellness programs
Inclusive and respectful of diverse perspectives
Stay Connected Follow us on LinkedIn Sign Up for Job Alerts Learn More About CPP Investments

#J-18808-Ljbffr

📌 Manager, Technology Risk Management, Information & Corporate Security (12 Month Contract) (Ontario)
🏢 CPP Investments
📍 Ontario

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager, technology risk management, information & corporate security (12 month contract) (ontario) / ontario

Subscribe to this job alert:

Get the latest job offers by email for: manager, technology risk management, information & corporate security (12 month contract) (ontario) / ontario