23 Aug
|
Cyberium Group
|
Richmond
23 Aug
Cyberium Group
Richmond
Role Description
We are looking for a Manager – IT Risk & Compliance to work as an integral part of our consulting and service delivery team, serving clients across financial services, the public sector, high technology, and other industry sectors.
In this role, you will lead and support client engagements focused on assessing, designing, implementing, and operationalizing practical IT risk and compliance programs. You will manage client delivery activities and contribute to initiatives including IT risk assessments, internal audits, control testing, compliance readiness, governance framework design, policy development, and control implementation aligned with recognized standards such as ISO 27001, SOC 2, NIST, and related frameworks.
The role requires solid consulting, stakeholder management, and communication skills, as well as the ability to manage engagement scope, timelines, deliverables, quality, and client expectations. Exposure to AI-related risks and AI governance is required, particularly where emerging technologies intersect with cybersecurity, regulatory compliance, data governance, and enterprise risk management.
What You Will Be Doing
You will be an integral part of our team, providing support on some or all of the following activities:
- Lead the planning and delivery of IT risk, compliance, internal audit, and AI governance engagements for clients across various industries.
- Manage engagement scope, workplans, timelines, budgets, deliverable quality, project risks, and client expectations throughout the engagement lifecycle.
- Conduct IT risk assessments, internal audits, control assessments, compliance gap analyses, and readiness reviews for systems, processes, vendors, and business initiatives.
- Help clients identify, assess, prioritize, and address technology risks through practical, risk-based, and business-aligned recommendations.
- Support the design, implementation, and operationalization of IT risk management programs, governance frameworks, policies, procedures, and control environments.
- Lead control design and effectiveness assessments against recognized standards and frameworks such as ISO 27001, SOC 2, NIST CSF, SOX ITGC, and other applicable requirements.
- Assess risks associated with AI systems and use cases, and support the development of AI governance frameworks, policies, risk assessments, and oversight processes.
- Facilitate workshops and stakeholder discussions with technical, operational, and executive teams to gather information, validate findings, and agree on remediation priorities.
- Translate complex technical, regulatory, and risk considerations into clear, actionable recommendations for technical and non-technical audiences.
- Prepare high-quality reports, executive summaries, presentations, risk registers, remediation roadmaps, and governance reporting.
- Liaise with external auditors, certification bodies, and other third parties to support audit, compliance, and certification activities.
- Provide guidance and quality oversight to consulting team members, supporting their development and ensuring consistent delivery standards.
- Contribute to proposals, client relationship management, and the identification of opportunities to expand or enhance client engagements.
What We Are Looking For
- Minimum of five years of relevant experience in IT risk, compliance, IT audit, cybersecurity, risk advisory, consulting, or a related field.
- Demonstrated client-facing consulting experience supporting mid-size to large organizations across complex technology, risk, audit, or compliance initiatives.
- Proven experience managing client engagements, including scope, workplans, timelines, budgets, deliverable quality, project risks, and stakeholder expectations.
- Practical experience conducting IT risk assessments, internal audits, control assessments, compliance gap analyses, or certification readiness reviews.
- Strong knowledge of recognized standards and frameworks such as ISO 27001, SOC 2, NIST CSF, NIST 800-53, SOX ITGC, or other applicable requirements.
- Experience designing, implementing, testing, or improving IT controls, governance frameworks, policies, procedures, and remediation plans.
- Exposure to AI-related risks or AI governance activities, such as AI risk assessments, use-case reviews, responsible AI policies, or frameworks such as ISO 42001 and the NIST AI RMF.
- Experience supporting the design, implementation, or operationalization of Enterprise Risk Management (ERM) frameworks and processes is preferred.
- Demonstrated ability to lead workshops, manage stakeholder discussions, and communicate effectively with technical, operational, and executive audiences.
- Polished written, verbal, presentation, and facilitation skills, with the ability to translate complex risk and technical matters into actionable business recommendations.
- Experience providing guidance, quality oversight, or coaching to junior team members.
- Previous experience with a Big Four firm or another recognized consulting organization is considered a strong asset.
- Relevant professional certifications such as CISSP, CISA, ISO 27001 Lead Auditor or Lead Implementer, or ISO 42001 are preferred.
- Bachelor’s degree or diploma in a relevant field, such as business, accounting, information systems, technology, cybersecurity, risk management, or a related discipline.
Why Join Us
- Competitive Compensation and Comprehensive Benefits
- Flexible Work Arrangements that support work–life balance
- Opportunities for Career Advancement
- Semi-casual Work Attire
- Collaborative, Dynamic, and Fast-growing Team Environment
- Continuous Learning and Skill Development Opportunities
- Regular Team Events
- Convenient office location near the SkyTrain station
📌 Manager – IT Risk & Compliance (Richmond)
🏢 Cyberium Group
📍 Richmond