in IT contract management, IT vendor management, third-party risk, vendor governance, technology risk, cybersecurity risk, or a related field. Robust experience with
IT contract review and interpretation . Strong understanding of
IT security clauses and contractual security requirements . Experience reviewing or negotiating complex technology/vendor agreements. Experience with
vendor information security reviews or assessments . Working knowledge of at least one or more of the following: NIST 800-53 NIST Cybersecurity Framework (CSF) ISO 27001 Strong stakeholder management and communication skills. Ability to identify contractual risks and recommend practical solutions. Strong attention to detail and ability to manage multiple contracts and stakeholders. Preferred Qualifications
Experience within
financial services, banking, insurance, wealth management, or technology
organizations. Knowledge of
OSFI B-10, OCC guidance, PIPEDA, GLBA, GDPR, and CCPA . Experience with
SaaS, cloud, software licensing, and cybersecurity agreements . Experience with vendor risk/security platforms such as
Archer, Ivalua, or ProcessUnity . Experience with
Power BI and Microsoft Office . Project management or change management experience. Knowledge of vendor security assessments and third-party cybersecurity controls. Japanese and/or Chinese language skills are an asset.