Manager, Information Risk Management at Manulife in Halifax, NS
- Company: Manulife
- Location: Halifax, Nova Scotia
- Job type: full time
- Workplace: onsite
- Posted: 2026-09-14
Job description
The Manager, Information Risk Management, plays a critical role in supporting regulatory readiness by leading and coordinating Line 2 activities related to regulatory requests, data calls, and reviews across IT Protection and application security. In this role, you will help ensure risks, controls, and remediation activities are clearly documented and traceable to meet audit and regulatory expectations. You will also provide independent Line 2 oversight across Technology and Cyber Security Risk, leading complex risk assessments, delivering credible challenge to control owners and technology partners, and helping ensure that technology, cyber, data, AI, and emerging technology risks are effectively identified, assessed, managed, and governed. This role offers the opportunity to operate in Technology and Cyber Risk, shaping regulatory response and strengthening organizational resilience. You will contribute to the organization’s mission through independent oversight, strong risk governance, and regulatory readiness across critical technology domains. You will gain exposure to enterprise-wide risk areas—including cyber, data, AI, and emerging technologies—while building leadership capability and influencing stakeholders. Position Responsibilities: Independent Oversight & Support Provide Line 2 oversight and challenge of regulatory submissions to ensure accuracy, completeness, and alignment with internal standards; Interpret regulatory and audit expectations and provide Line 2 guidance to support compliant, risk-informed responses and remediation actions. Support audit and regulatory readiness by coordinating materials, reviewing evidence packages, and preparing stakeholders for reviews, examinations, and information requests. Lead Line 2 oversight activities across technology, cyber, data, AI, cloud, and emerging technology domains. Perform oversight and challenge on thematic reviews and targeted risk deep dives. Oversee and validate the quality of risk assessments, evidence, and remediation commitments provided by Line 1 partners. Monitor and escalate significant issues, risk exceptions, control gaps, and corrective action plans. Tracks and challenges remediation progress to closure. Escalate significant technology and cyber risk issues, control weaknesses, and regulatory concerns to appropriate governance forums and senior leadership. Provide effective challenge on the design and operating effectiveness of controls supporting key technology and cybersecurity risk areas. Governance, Reporting & Collaboration Manage new projects and initiatives as required Develop and deliver high‑quality risk reporting, dashboards, and insights for senior leadership, risk committees, and governance forums. Maintain and enhance oversight processes, documentation, templates, and guidance materials to support a consistent risk practice. Identify opportunities to uplift risk maturity, streamline processes, and strengthen the effectiveness of IRM oversight. Contribute to the development of policies, standards, and methodologies in collaboration with Standards Governance, Technology Risk, Operational Risk, Privacy, and Compliance. Represent IRM in cross‑functional forums, working groups, and strategic initiatives. Required Qualifications: 5 years of experience in technology risk, cybersecurity, IT audit, or related domains. Strong audit, risk assessment, and control evaluation capabilities, with the ability to assess the quality, completeness, and sufficiency of supporting documentation and evidence. Demonstrated ability to coordinate, review, and challenge evidence submissions across multiple stakeholders, ensuring deliverables are accurate, well-supported, and aligned with internal standards and review expectations. Solid understanding of regulatory, audit, and governance expectations, with experience interpreting requirements and supporting responses to regulatory reviews, examinations, and information requests. Proactive, adaptable, and able to op
Manager, Information Risk Management on JobPost.