Hiring.Camp

Senior Manager, GRC Regulatory Assurance

TMX group of companies includes

·

Yesterday

Salary
$125k – $145k
Location
Toronto - 100 Adelaide St W, Canada
Type
Full-time
Department
Legal
Seniority
Senior
Education
Bachelor
Visa
Not sponsored
Source
Workday

Description

Venture outside the ordinary - TMX Careers

The TMX group of companies includes leading global exchanges such as the Toronto Stock Exchange, Montreal Exchange, and numerous innovative organizations enhancing capital markets.  United as a global team, we’re connecting cross-functionally, traversing industries and geographies, moving opportunity into action, advancing global economic growth, and propelling progress. Through a rich exchange of ideas, meaningful collaboration, and a nimble operating model, we're powering some of the nation's most critical systems, fueling capital formation and innovation, bringing increased opportunity to business visionaries, product ingenuity to consumers, and career exploration to our team.

Ready to be part of the action?

The Senior Manager, GRC Regulatory Assurance is responsible for providing tactical and operational leadership to ensure TMX Group’s assets are protected and that the organization maintains robust regulatory compliance. This role will drive the maturation of the regulatory assurance program, serving as a critical bridge between TMX Group of subsidiaries and the Information Security Office. You will manage a high-performing team tasked with maturing the information security program, ensuring alignment with global regulatory frameworks, and fostering a culture of risk-aware compliance across the enterprise.


Key Accountabilities
 

  • Regulatory Oversight and Audit Management:

    • Oversee activities to maintain regulatory compliance across TMX Group’s regulated entities (e.g., BOC, OSFI, AMF, and SWIFT).

    • Perform mapping and control testing of regulatory expectations and principles to control requirements to validate compliance coverage.

    • Collaborate with internal stakeholders and Legal to manage regulatory inquiries, audit examinations, and the development of formal responses.

    • Track and report on remediation of findings from internal and external audits to ensure timely closure.

  • GRC Program Strategy and Maturing:

    • Define and maintain the overarching cybersecurity strategy and policy framework lifecycle.

    • Manage the continuous improvement of the GRC program, ensuring alignment with industry standards such as NIST, ISO 27001, and ITIL.

    • Oversee the refresh of technical security standards and policies to address emerging threats and cloud-native requirements.

    • Develop, manage, and enhance GRC risk management tooling capabilities.
       

  • Governance and Reporting:

    • Establish and track metrics (KPIs/KRIs) to monitor the effectiveness of the Information Security GRC program.

    • Provide monthly and quarterly reporting on the status of regulatory compliance, risk registers, and remediation efforts for executive leadership, CISO, RMC, and Board.
       

  • TPRM Supply Chain Cybersecurity:

    • Perform vendor products and services security assessments. Provide purchase and merger and acquisitions advice to CISO, ERM, Procurement, and Legal.
       

  • Team Leadership and Development:

    • Lead, mentor, and manage a team of security advisors and analysts.

    • Ensure that team members have established SMART objectives aligned with ITSS and overall TMX goals.

    • Foster a culture of "Client-Centricity," courage, and trust, promoting proactive engagement with business units.
       

  • Stakeholder Engagement:

    • Develop strong working relationships within the Information Security Office, Enterprise Risk Management (ERM), ITSS Architecture, to ensure seamless execution of risk management initiatives.

    • Collaborate with the business units to integrate security into business continuity and operational processes.
       

Skills and Experience

  • Education: University undergraduate degree in Computer Science, Engineering, or a related field.

  • Experience: 10+ years of information technology experience, with a minimum of 7 years specifically in information security, risk, or regulatory compliance.

  • Leadership: 5+ years of people management/leadership experience with a proven track record of developing high-performing teams.

  • Regulatory Knowledge: Proficiency in interpreting and applying regulatory frameworks (e.g., BOC, OSFI, AMF, and SWIFT) within a financial market infrastructure context.

  • Technical Proficiency: Strong understanding of cybersecurity governance, policy frameworks, and risk assessment methodologies (e.g., TRAs).

  • Certifications: CISSP is required. CISA, CISM, or ISO 27001 Lead Auditor certifications are considered significant assets.

  • Soft Skills: Proven track record as a business partner who can translate complex technical risk into actionable business language for non-technical stakeholders.

Salary Range: $125,000 - $145,000/year CAD. Please note that the salary range included is a guideline only. The salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience.
 

The recruiting efforts for this role are intended to fill a vacant position.

In the market for…

Excitement - Explore emerging technology and innovation, as well as ventures and digital finance that shape the future of global markets! Experience the movement of the market while grounded in the stability of close to 200 years of success.

Connection - With site hubs in some of the world’s most multicultural cities, we leverage our size and structure to create rich connections and belonging while experiencing powerful global impact through our work.

Impact - More than a platform, we use our talents to power mission-critical systems that drive global economic advancement, innovation, and growth. As well, our employee-led Team Impact spreads social good via our giving strategy.

Wellness - From empathetic leadership to a culture of flexibility and balance, we believe wellness at work creates the maximum yield and a stronger “we”. Plus, with a cloud-first and hybrid workstyle, as well as generous time-off and leaves, we support a life well lived! 

Growth - From a growth mindset in our work, to expansion in our business, TMX is home to action-takers energized by the achievement of ambitious growth.

Ready to enrich your career with impactful work, leaders who truly care, and the flexibility and programs to help you thrive as part of #TeamTMX ? Apply now.

Please note that our company is not currently sponsoring work permit applications and the applicant must be authorized to work in the country where this position is located. 

TMX is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide accommodations for applicants and employees who require it.

Skills

CybersecurityRisk ManagementComplianceProcurementITILISO 27001CISSP

Similar Jobs

18

Senior GRC Manager

Converge Technology Solutions · United States · Remote

2 days ago

Sr. Manager GRC

Bloom Energy Careers · Office - 4353 North 1st Street, United States of America · Onsite

3 months ago

GRC/IRM ServiceNow Technology Implementation Solutions – Senior Manager

Pwc · Chicago - One North Wacker Drive, United States of America +11

Yesterday

Senior Information Security Manager (GRC)

Deepl · Munich +2

1 week ago

Senior Manager, GRC Engineering (Special Programs)

Workstreet · United States (Remote) · Remote

1 week ago

Sr. Manager, Application Development – Member Engagement/CRM & GRC

FHL Bank Chicago · Chicago, United States of America · Remote, Onsite

2 weeks ago

Sr Risk Manager, GRC Systems

Transamerica · Cedar Rapids, Iowa, United States of America +1

2 weeks ago

Sr.Technical Program Manager, Security & GRC - 11740

Coupa · Pune, India · Onsite

3 weeks ago

Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop · Boston, MA · Onsite

3 weeks ago

Senior Product Manager, GRC Platform

Vanta · Remote U.S. · Remote

1 month ago

Senior Manager, GRC People and Policy

Ffive · Guadalajara, Mexico · Hybrid

1 month ago

Senior Manager – Cybersecurity & Governance, Risk & Compliance (GRC)

Fortna · Fortna Inc.- Corporate office, United States of America

1 month ago

Manager / Senior Manager | Cybersécurité | GRC | F/H

Pwc · Paris - Crystal Park, France

2 months ago

GRC and AI Governance - Senior Manager

Cfgi · United States · Hybrid

3 months ago

Senior Manager, GRC Engineering

Workstreet · Remote (United States) · Remote

4 months ago

Senior Manager, GRC System Product Owner: Enterprise Risk & Internal Audit

Invesco · Atlanta, United States of America +1 · Hybrid

5 months ago

Senior Consultant / Manager (m/w/d) Insurance GRC

Capgemini Invent · Berlin, Frankfurt am Main, Hamburg, Köln, München, Stuttgart

1+ year ago

Sr Product Manager GRCx

Capitalone · McLean, VA, United States of America +1

2 weeks ago