Ottawa or Toronto, ON, CA
Senior Supervisor, Cyber Risk Supervision
Take a central role
The Bank of Canada has a vision to be a leading central bank—dynamic, engaged and trusted—committed to a better Canada. No other employer in the country offers you the unique opportunity to work at the very center of Canada’s economy, in an organization with significant impact on the economic and financial well-being of all Canadians. You will be challenged, energized and motivated to excel in our environment.
Building on the principles that have always guided us – excellence, integrity and respect – we strive to be forward-looking and innovative, to welcome people with diverse perspectives and talents, and to earn trust by living up to our commitments and by clearly explaining the intent of our policies and actions.
With our defined-benefit pension plan, benefits, and high flexibility for work life balance - find out more about why we are annually ranked as one of Canada's top employers: Working Here - Bank of Canada
Find out more about the next steps in our Recruitment process.
Application Process
Your application must include the following:
- curriculum vitae
- cover letter outlining why you are applying for this position and how your skills and qualifications meet the requirements for the role.
About the Payments and Regulatory Oversight Department
The payments landscape in Canada and globally is evolving rapidly, driven by technological advancements that are introducing innovative ways for consumers and businesses to make payments. Under the Retail Payment Activities Act (RPAA), the Bank of Canada is responsible for registering retail payment service providers (PSPs) that perform retail payment activities, maintaining a public registry of PSPs, and supervising PSPs’ compliance with operational risk management, fund safeguarding and reporting requirements.
What you will do
As a Senior Supervisor in the Risk Supervision team, you will play a crucial role in shaping the Bank’s retail payments supervisory framework in a fast-paced and dynamic environment. Being at the forefront of Canada’s rapidly evolving payments landscape, you will strengthen resilience and help protect the integrity of the payments ecosystem.
You will apply your knowledge of cyber and information security risk management practices to help implement the Bank’s framework for PSP supervision, and assess the compliance of PSPs with their regulatory obligations.
Your responsibilities will include:
- Assessing PSPs' cyber and information security risks,vulnerabilities, and control effectiveness
- Analyzing PSP reporting related to cyber and information security incidents
- Communicating with PSPs on ongoing risk assessment activities
- Collaborating with colleagues on supervisory assessments and actions
- Developing and maintaining business documentation and information repositories
- Contributing to the development of processes and policies to optimize the Bank’s approach to PSP risk supervision
What you need to succeed
As a self-motivated critical thinker, you have the following industry knowledge and experience:
- Cybersecurity principles and risk experience
- Strong understanding of cyber security principles and risk management practices
- Knowledge of cyber defence mechanisms and industry best practices.
- Experience assessing, managing or supervising cybersecurity practices, ideally in regulatory , consulting or second or third line of defence roles.
- Strong theoretical and practical knowledge of IT and cyber risk including risk identification evaluation and mitigation.
- Understanding of risk management frameworks such as the NIST cybersecurity framework, ISO 27001 etc.
- Cybersecurity landscape awareness
- Solid understanding of emerging cybersecurity threats, trends, and leading practices
- Regulatory compliance knowledge
- Understanding critical financial sector regulations and frameworks (such as PCI DSS, SOC 2, GDPR, PIPEDA, RPAA) and their implications for cyber security and risk management.
- Cyber tools knowledge
- Familiarity with tools used for risk management, incident response and monitoring .
You are able to synthesize complex information and provide high quality analysis while considering multiple factors and perspectives often within contexts of ambiguity and evolving information.
You are flexible and able to adapt to an evolving work environment and changing priorities. Furthermore, you are able to organize and balance a variety of tasks. You have a proven ability to communicate clearly and adapt your communication style for a wide range of audiences, including senior management and external stakeholders.
You are equally comfortable working collaboratively within a team, or independently. You develop and maintain harmonious relationships with a wide range of business contacts and build supportive working relationships with peers, your leader, as well as internal and external stakeholders.
Nice-to-have
- Knowledge of incident management and response processes.
- Knowledge of cloud technologies and cloud security practices and understanding how they apply to risk management and cybersecurity within cloud environments.
- Understanding of secure system architecture and design principles .
- Knowledge of DevOps or DevSecOps practices
- Familiarity with retail payment services, the retail payments ecosystem, or financial technology companies (paytechs or fintechs)
- Strong interest in supervisory technology, including artificial intelligence to support efficient supervisory practices
- At least one of the following certifications:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CGRC (Certified Governance, Risk and Compliance)
- CISA (Certified Information Systems Auditor)
Your education
The position requires:
- a masters degree in Computer Science, Information Technology, Cybersecurity or a related discipline, with at least five years of relevant experience; or
- a minimum bachelors degree in Computer Science, Information Technology, Cybersecurity or a related discipline, with at least six years of relevant experience.
A combination of education and experience may be considered. Candidates with degrees in other fields may be considered where they demonstrate significant practical cybersecurity experience.
Innovative Mindset
We value candidates who demonstrate adaptability, curiosity, and a willingness to learn new technologies, including AI and digital tools. We seek individuals who can think critically about data, question existing processes, and find ways to simplify our work while embracing change and new ways of doing things.
Language requirement
The Bank’s work environment is conducive to the use of both of Canada’s official languages - English and French. The position language requirement is Level 5 (Fully Functional). If a qualified candidate who meets the language requirement of the position is not found, a qualified candidate who does not meet the language requirement may be considered. Training may be provided to help reach the required level. Both bilingual and unilingual candidates are encouraged to apply.
What you need to know
- Priority will be given to Canadian citizens and permanent residents
- Security level required: Be eligible to obtain Secret
- Relocation assistance may be provided, if required
- Please save a copy of the job poster. Once the closing date has passed, it will no longer be available.
- The official title for this position is “Senior Supervisor, Risk Supervision ”
Hybrid Work Model
The Bank offers work arrangements that provide employees with flexibility, enable high-performing teams, and support an excellent workplace culture. Most employees can telework from home for a portion of each month as part of the Bank’s hybrid work model, and they are expected on site at the Bank location a minimum of 12 days per month to help build connections between colleagues. You must live in Canada, and within reasonable commuting distance of the office.
What you can expect from us
This is a great opportunity to join a leading organization and be part of a high-performing team. We offer a competitive compensation and benefits package designed to meet your needs at every stage of your life and career. For more information on key benefits please visit A great deal to consider.
- Salaries are based on qualifications and experience and typically range from $111,051 to $130,649 (job grade 17)
- The Bank offers an incentive for successfully meeting expectations at 7 to 10% of your base salary. The Bank offers additional performance pay (5%) for those who exceed expectations. Exceptional performers who far exceed expectations may be eligible for higher performance pay.
- Flexible and comprehensive benefits so you can choose the level of health, dental disability and life and/or accident insurance coverage that meets your needs
- Extra vacation days (up to five each year) that you can purchase to add to your vacation entitlement
- Indexed, defined-benefit pension
We wish to thank all applicants for their interest and effort in applying for this position. Only candidates selected for interviews will be contacted.