Senior Consultant, Cyber Risk & Governance
Duration: 6-Month Contract (Potential Contract-to-Hire)
Work Location: Hybrid (1–2 days/week, Downtown Toronto)
Hours: 37.5 hrs/week; Monday–Friday, 9:00 AM – 5:00 PM
What does the LOB do?
Enterprise Cyber Risk and Governance team focused on identifying, assessing, and managing technology and cybersecurity risk across the organization.
The team partners closely with Cybersecurity, Information Security, Technology, and Business stakeholders to strengthen controls, address risk exposures, and support regulatory and governance initiatives.
Summary
The Senior Consultant, Cyber Risk & Governance will provide expert consultation on cybersecurity, technology risk, and governance initiatives across the enterprise.
The successful candidate will bring a strong technical cybersecurity foundation combined with risk and governance experience. This role requires someone who can confidently engage with cyber and technology teams, assess risks and controls, challenge stakeholders, and translate technical issues into meaningful business discussions.
This position operates with a high degree of autonomy and will support risk assessments, control reviews, remediation efforts, governance activities, and regulatory initiatives.
Job Responsibilities
- Assess cybersecurity, technology, and operational risks across business initiatives
- Identify control gaps and support remediation activities
- Partner with Cybersecurity, Information Security, Technology, and Infrastructure teams
- Conduct risk assessments and recommend mitigation strategies
- Support governance, risk, and compliance initiatives
- Review and evaluate technology and security controls
- Support regulatory, audit, and compliance activities
- Develop executive reporting and presentations related to risk posture and control effectiveness
- Facilitate discussions with technical stakeholders to understand risks, controls, and remediation requirements
- Contribute to the development and enhancement of governance frameworks, policies, and standards
- Provide guidance and subject matter expertise on cyber risk, technology risk, and controls
- Build strong partnerships across technical and business teams
Must Have Requirements
- 7+ years of experience in Cyber Risk, Technology Risk, Information Security, IT Audit, Cybersecurity Governance, or GRC
- Strong cybersecurity and technology background
- Experience working directly with Cybersecurity, Information Security, Infrastructure, Engineering, or Technology teams
- Ability to communicate effectively with technical stakeholders and "speak the language" of cyber teams
- Experience performing risk assessments, control reviews, gap analyses, and remediation activities
- Knowledge of technology risk, cyber risk, and information security control frameworks
- Experience supporting governance, audit, compliance, or regulatory initiatives
- Strong stakeholder management and relationship-building skills
- Excellent communication and presentation skills
- Ability to work independently in a complex and fast-paced environment
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- Other Information Security, Cybersecurity, or Technology Risk certifications
Nice to Have
- Banking or Financial Services experience
- Experience supporting OSFI or other regulatory requirements
- Experience with Information Security, Cybersecurity, Technology Controls, or Technology Risk programs
- Experience working across 1st, 2nd, and 3rd Lines of Defense
- Experience with cloud security, infrastructure security, or emerging technology risk
Apex Compensation Disclaimer
Apex pay scales are determined by role, experience, skill set, and location. For this position, the estimated hourly range is provided below as a guideline; however, total compensation may vary based on individual circumstances.
Pay: $52.00-$57.00 per hour
Work Location: Hybrid remote in Toronto, ON (Toronto District)