Share this Job



  • Job ID: 30655
  • Division & Section: Office of the CISO, Cyber Diplomacy & Governance
  • Work Location: METRO HALL, 55 John Street
  • Job Type & Duration: Full-time, Permanent  
  • Salary:$112,075.60-$131,677.00, TM 5098, and Wage Grade 8. (2022 rate)
  • Shift Information: Monday to Friday, 35 hours per week per week
  • Affiliation: Non-Union.
  • Number of Positions Open: 1 
  • Posting Period: 05-DEC-2022 





Risk Assurance is the internal process or methodology the Office of the CISO (OC) employs to create 'checks' within the City of Toronto’s governance and risk frameworks. The main focus of the risk assurance practice is to ensure cyber risks are effectively managed.

In this role, the Senior Specialist Risk Management will ensure that all risks identified, during risk assessment processes, are assigned to risk owners, Risk Treatment Plans (RTP) are developed and signed by key stakeholders. In addition, RTPs are monitored, control owners identified, and controls effectiveness are addressed. Further, the Senior Specialist Risk Management will work with key cybersecurity partners such as the City’s Internal Audit Division, Technology Services Division, and Auditor General’s Office to ensure cybersecurity related audit findings are effectively closed.




  • Supports the implementation and post production activities of the Integrated Risk Management Team
  • Supports the implementation of Governance, Risk, and Compliance (GRC) tools
  • Supports the implementation of cyber audit management tools
  • Supports the implementation of the City’s Cyber Risk Management Framework
  • Leads or supports Third Party Risk Management activities
  • Develops artifacts to support the implementation of a risk assurance program 
  • Oversees the execution of cybersecurity controls to ensure appropriate evidence required due care and due diligence exists to meet compliance with applicable statutory, regulatory and City of Toronto standards and policies.
  • Executes an impartial assessment process to validate the existence and functionality of appropriate cybersecurity controls, prior to a system, application or service being used in a production environment or post implementation.
  • Builds collaborative and productive working relationships across the organization to establish, maintain, and continuously improve cyber risk management capabilities, and promote risk awareness, and intelligent risk taking.
  • Conducts research into assigned area ensuring that such research takes into account developments within the field, corporate policies and practices, legislation and initiatives by other levels of government.
  • Provides input into assigned project budgets, ensuring that expenditures are controlled and maintained within approved budget limitations.
  • Provides subject matter expertise and senior level strategic advice on cyber security issues affecting the organization, identifying potential exposures, and conducting reviews to ensure that undesirable effects are detected, mitigated and/or corrected, and providing pragmatic advice to clients to ensure that cyber risks are managed appropriately.
  • Serves as the internal/external point of contact and subject matter expert in their respective function.
  • Determines cyber security requirements of business strategies in order to provide appropriate advice, guidance, and technical solutions.
  • Develops, reviews, and ensures approvals of security strategies within industry-accepted frameworks.
  • Provides leadership in the evaluation, selection and recommendation of technical solutions and professional services. Identifies and evaluates emerging security technologies.
  • Anticipates, analyzes and identifies organizational impacts of emerging requirements; recommends and coordinates innovative solutions using conflict resolution and negotiation skills to successfully manage sensitive and controversial matters.
  • Participates in the development of transformation strategies focused on security, integrating and managing new or existing technology systems to deliver continuous operational improvements and detect, respond, and remediate threats.
  • Resolves cyber risk issues. Escalates significant cyber risk matters to senior management when required.
  • Deals with confidential information affecting the organization and its resources. Prepares and presents reports to management supporting recommendations on changes/improvements in business processes, training and services standards that impact appropriate staffing levels and resource allocation. Makes recommendations based on investigation results which could lead to the discipline or dismissal of staff.
  • Participates in the development, implementation, administration, monitoring and maintenance of security tools collecting confidential information on infrastructure and application weaknesses Maintains up to date knowledge of City's confidential cyber infrastructure.
  • Works with senior management within the division to address active internal/external cyber threats to the City. Attends senior management meetings, makes recommendations to mitigate the threats, and takes appropriate urgent action as needed.
  • Provides a confidential assessment of organizational issues and makes recommendations for next steps, including policy, procedural and structural change.
  • Takes a proactive approach to identify gaps and opportunities for improvement to mitigate risk.
  • Organizes and works with multidisciplinary business and technical teams from across the organization to formulate and execute project plans and tasks according to established project management principles and methodologies.
  • Provides oversight and monitors cyber risk activities performed by project teams. Reviews and supports the implementation of processes and controls by various teams as outlined in the information risk policy and related operating directives, standards and procedures.
  • Provides project coordination and management support, and ensures comprehensive and effective information communication across various functional and project teams.
  • Communicates effectively to stakeholders, clients, project managers, and team members regarding any business and technical decisions and actions that may impact solution delivery, staff performance, business processes, management workflow and technical support of public services.
  • Provides support in the design, implementation, maintenance, and enforcement of policies, procedures, and controls.
  • Plans, prioritizes and coordinates internal and/or external assigned project resources to meet project objectives.
  • Prepares and/or supervises the preparation of various formal contractual documents such as Request For Information/ Proposal/Quotation, Statement of Work, Memorandum of Understanding and Service Level Agreements.
  • Maintains accurate reporting of key risk metrics and associated measurements in alignment with the cyber risk appetite.
  • Prepares regular cyber risk management reports, briefing notes, and presentations as required and leveraging cyber risk subject matter expertise.
  • Builds and maintains strong relationships with internal and external stakeholders. Establishes relationships with strategic partners, collaborating on the advancement of cyber programs.
  • Participates in meetings with executive leadership and strategic partners to review City's cyber security posture.
  • Maintains an up-to-date and in-depth knowledge of cyber security, emerging threats, trends, and associated techniques and technologies as well as key business drivers and opportunities.






  • Post-secondary degree in Business or Technology or a related discipline.
  • Over 6 years experience in Risk Management, primarily focused on Risk Assurance/IT audit practices.
  • Knowledge of elements of risk, including vulnerability, threat, likelihood, impact, mitigation, and remediation
  • Third party assessments and audits: extensive experience conducting third part audits, especially on small sized service providers. 
  • Soc 2 type II audits: must have played a significant role in a Soc 2 type II audit team. 
  • PCI DSS audits: must have some experience at conducting PCI audits or preparing an organization for PCI audits 
  • Cyber Policy Framework: must have experience developing and implementing cyber policies and standards across an enterprise. 
  • NIST Cyber security framework: Must have experience conducting risk assessments based on NIST cyber security framework and related standards.
  • Extensive experience working with GRC tools, and good understanding of the risk management process.
  • Preferred Certifications (at least two in the list):  CISSP, CISA, CISM, CRISC




  • Mandatory
    • Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership and vendors.
    • Keen attention to detail and strong organizational skills.
    • Ability to lead efficient communication between all project stakeholders, including internal teams and clients.
    • Ability to achieve business objectives through influencing and effectively working with key stakeholders.
    • Excellent problem-solving skills with capability to identify solutions to unusual and complex problems.
  • Ability to work in transformative programs.
  • Highly organized, proactive, self-motivated team player who takes initiative and is able to work independently.
  • Ability to work in a fast-paced environment managing multiple priorities with proven time management skills.
  • Strong analytical skills and ability to prioritise and multitask.
  • Ability to prioritize and effectively manage competing priorities and projects.
  • Ability to manage multiple initiatives while adhering to strict deadlines.
  • Able to work extremely well under pressure while maintaining a high level of professionalism
  • Self-motivated person with desire to go above and beyond tasks
  • Transferable skills, like communication and decision-making, are equally important.
  • Being able to think on your feet and show good judgment are especially valuable in this field. “Security pros should always be ready to react to cyber-related incidents quickly.




A normal work week is 35 hours, however, unforeseen situation may require extended hours of work with little or no prior notice. In case of a cyber incident or breach, rotation shift, continuous extended hours may be required with little or no prior notice.


*Subject to a police check, background check, psychological assessment and/or any other checks on a regular basis as the Office of the CISO handles highly sensitive and confidential information.


Equity, Diversity and Inclusion

The City is an equal opportunity employer, dedicated to creating a workplace culture of inclusiveness that reflects the diverse residents that we serve. Learn more about the City’s commitment to employment equity.



The City of Toronto is committed to creating an accessible and inclusive organization. We are committed to providing barrier-free and accessible employment practices in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Should you require Code-protected accommodation through any stage of the recruitment process, please make them known when contacted and we will work with you to meet your needs. Disability-related accommodation during the application process is available upon request. Learn more about the City’s Hiring Policies and Accommodation Process.