Manager, Technology Governance – Controls

Posted 1ds ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Manager in Technology Governance & Controls at Manulife overseeing risk assessments and security controls implementation. Collaborating across teams to ensure compliance and mitigate risks in technology operations.

Responsibilities:

  • Perform information risk assessments in alignment with global methodologies, policies, and standards across new and existing tools, technologies, and business areas
  • Recommend new or enhanced security controls to strengthen enterprise security
  • Collaborate with developers, engineers, and support teams to implement and automate security controls, including cloud and container security within CI/CD pipelines
  • Perform and maintain RCSAs by evaluating control design and effectiveness, identifying gaps or emerging risks, and partnering with SMEs on remediation and documentation updates
  • Develop and support corrective action plans for key controls or measures where deficiencies are identified
  • Collaborate with ETS cloud, architecture, IT Asset Management, Infrastructure, Line 2, and control owners to ensure effective execution of risk processes and alignment with enterprise governance standards
  • Partner with Line 3 Audit and SMEs to gather/validate evidence, coordinate audit responses, challenge findings, and track deliverables throughout the audit lifecycle
  • Govern, operate, and mature the organizational technology risk management program, including reporting program status and key risk metrics
  • Review and maintain current knowledge of Information Risk Standards and Technology Risk Policies

Requirements:

  • Minimum 5 years of progressive experience in Technology Risk, Information Security, or IT Infrastructure/Architecture
  • Strong understanding of cybersecurity and technology risk domains (risk assessment, incident response, network security, cloud security, and regulatory expectations)
  • Familiarity with regulatory and industry frameworks such as OSFI B‑13, NIST CSF, ISO 27001, CIS Controls, SOC 1/SOC 2, and Cyber/Tech Risk Management practices
  • Hands‑on experience with platforms such as Archer, Jira, Confluence, and ServiceNow
  • Strong understanding of cloud environments — Azure required, AWS an asset
  • University degree in Computer Science, IT, Risk Management, or related discipline; professional certifications (CISSP, CISA, CRISC, CISM) preferred

Benefits:

  • Health insurance
  • Dental insurance
  • Mental health support
  • Vision insurance
  • Short- and long-term disability insurance
  • Life and AD&D insurance coverage
  • Adoption/surrogacy benefits
  • Wellness benefits
  • Employee/family assistance plans
  • Retirement savings plans including pension and employer matching contributions
  • Financial education and counseling resources
  • Generous paid time off program including holidays and personal days