- Company Name
- TMX Group
- Job Title
- Head of Security GRC & Regulatory Assurance
- Job Description
-
**Job title**
Head of Security GRC & Regulatory Assurance
**Role summary**
Senior security executive responsible for ensuring all TMX business units and legal entities comply with cyber security regulatory requirements and manage cyber risk in line with the TMX Information Security Policy. Leads strategy, governance, risk, and regulatory engagement across Canada, the U.S., and internationally, reporting to the CISO and the Board.
**Expectations**
- Deliver comprehensive regulatory compliance and cyber resilience across all TMX entities.
- Shape information security strategy in partnership with business leadership.
- Build and maintain relationships with regulators, international bodies, and senior stakeholders.
- Operate independently, managing multiple priorities in a fast‑paced environment.
**Key responsibilities**
1. **Governance & Strategy**
- Develop and implement the organization‑wide cyber security strategy aligned with supervisory and regulatory obligations.
- Lead the assessment program to evaluate business unit compliance and report findings to the CISO, CIA, and CRO.
2. **Regulatory & Regulatory Assurance**
- Advise and report to business unit heads, the Board, and the EORC on current and emerging cyber security regulations (e.g., Bank of Canada cyber resilience expectations, PFMI, IOSCO, CPMI).
- Manage relationships with key regulators (Bank of Canada, OSFI, OSC, provincial regulators) and represent TMX in international forums.
3. **Risk & Compliance Management**
- Identify, assess, and mitigate regulatory risk, including financial impact analysis of new cyber‑related requirements.
- Collaborate with Legal, Risk, Governance, and ERM to produce comprehensive cyber risk reports for the EORC and Board.
4. **Stakeholder Communication**
- Serve as the primary technical authority for cyber resilience regulatory requests, providing clear technical guidance to non‑technical audiences.
- Respond to client inquiries regarding TMX’s security posture and to public disclosures of security vulnerabilities.
5. **Leadership & Influence**
- Influence senior management and cross‑functional teams to adopt controls and best practices.
- Drive continuous improvement of governance, risk, and compliance processes.
**Required skills**
- Minimum 20 years of IT experience, including 10 + years in information security within the financial sector.
- Deep knowledge of Canadian cyber security and FMI regulations; familiarity with U.S. and global cyber resilience rules.
- Expertise in information security best practices, governance, risk management, and compliance frameworks (NIST, ISO 27001, COSO).
- Strong strategic planning, analytical, and decision‑making abilities.
- Excellent written and oral communication skills; ability to translate technical concepts for business leaders, board members, auditors, and regulators.
- Proven ability to work independently, manage multiple teams, and meet deadlines in a dynamic environment.
**Required education & certifications**
- Bachelor’s degree in Computer Science, Information Security, Cyber Security, Business Administration or related field.
- Advanced certifications preferred: CISSP, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent.
- Additional certifications (e.g., ITIL, CCSP, CPA/CA) considered an advantage.