- Company Name
- Fidelity Canada
- Job Title
- Cyber Security Risk Director
- Job Description
-
**Job Title:** Cyber Security Risk Director
**Role Summary:**
Lead the second‑line cyber risk management function, developing, implementing, and continuously improving Fidelity Canada’s cybersecurity risk framework across all business units. Act as the primary advisor to senior leadership on cyber risk, regulatory compliance, and incident response, ensuring alignment with enterprise risk appetite and industry standards.
**Expectations:**
- Deliver a mature, enterprise‑wide cyber risk oversight program that satisfies regulatory, internal, and external stakeholder requirements.
- Provide strategic guidance on cyber risk assessment, mitigation, and monitoring, and influence risk‑aware decision‑making across the organization.
- Manage and mentor a cross‑functional team, fostering collaboration between Information Security, Technology Risk, and Business units.
- Maintain proactive engagement with external cyber experts and regulatory bodies.
**Key Responsibilities:**
1. Own and continuously enhance the cyber risk framework, policies, and methodologies.
2. Conduct planned and ad‑hoc technical risk reviews; evaluate technology and business initiatives for cyber implications.
3. Represent Fidelity Canada on FIL cyber governance committees and external advisory panels.
4. Develop and oversee the Cyber Risk Oversight Program, aligning with enterprise risk appetite and regulatory requirements.
5. Identify, assess, and communicate cyber risks to business units and Information Security stakeholders; ensure accountability and risk awareness.
6. Monitor global cyber threat trends; deliver analytical insights to senior management on risk posture.
7. Challenge first‑line risk management processes, providing risk opinions and remediation recommendations.
8. Lead second‑line involvement in major cyber incidents, including privacy events, coordinating response and post‑incident reviews.
9. Produce regular risk reporting to senior management and governance committees.
10. Manage relationships with external cyber risk experts, consultants, and auditors.
11. Ensure all deliverables meet established quality, timeliness, and accuracy standards.
**Required Skills:**
- Executive stakeholder engagement and communication.
- Deep knowledge of cyber risk management best practices.
- Expertise in NIST CSF, ISO 27001, and COBIT frameworks.
- Experience designing and implementing cyber risk oversight programs in financial services.
- Strong analytical and problem‑solving abilities.
- Incident response leadership and crisis management.
- Project management and cross‑functional team leadership.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Finance, Risk Management, or equivalent.
- 7+ years of cyber risk experience, including 5+ years in a management or second‑line role.
- Professional certifications: CISSP, CISM, CRISC, or equivalent.
- Proven experience with regulatory compliance in the financial sector (e.g., FFIEC, PCI‑DSS, GDPR, PIPEDA).
---