Senior Specialist, Compliance and Quality Assurance
Job Requisition ID: 11769
Position Status: Permanent Full Time
Position Type: Hybrid
Office Location: Ottawa (ON); Montreal (QC); Toronto (ON)
Travel Requirement: Limited
Language Designation: English Essential
Language Skill Levels (Read/Write/Speak): ZZZ
Security Requirement: Secret
Salary: Our salaries generally range from $ 101639.3 to $ 127049.13 and are based on qualifications and experience.
About CMHC
The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.
At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.
Join us and be part of a team that's committed to making a real difference and be part of something meaningful.
What’s in it for you
We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:
- Annual Paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
About the role
Join the chief risk officer’s team, in the Senior Specialist, Compliance and Quality Assurance position. In this role, you will provide strategic insight and independent challenge on technology and cyber risks. You will work closely with first-line teams to enhance risk practices, improve control effectiveness, and ensure proactive management of technology-related exposures.
What you’ll do:
- Provide second line oversight of technology and cyber security risks, including IT General Controls (ITGCs), change management, and system resilience.
- Offer independent challenge and expert advice on major technology initiatives, programs and incidents.
- Partner with first line (Information Technology, Information Security and 1B teams) to support implementation of risk management practices across technology programs, including cloud transformation, system changes, and cyber resilience initiatives.
- Support oversight of incident management, threat and vulnerability management, and technology capacity risks, ensuring timely identification and escalation of key exposures.
- Review and assess Risk Acceptance Memos and security standards, providing insight and recommendations to management.
- Contribute to the development and enhancement of technology cyber risk metrics and dashboards to improve visibility and reporting to senior management and the Board.
- Collaborate across risk disciplines to integrate technology and cyber risk perspectives into broader operational risk oversight.
- Support enterprise risk training and awareness initiatives related to technology and cyber security.
What you should have:
- An undergraduate degree in computer science, information systems, business administration, commerce, economics,
or related fields.
- A professional certification or designation in risk management, technology risk, or information security (e.g. CISA, CRISC, CISSP, CRA, CIA).
- A minimum of seven (7) years of experience in operational risk oversight,
internal audit, or a related function, with a focus on technology and/or cyber security risk management.
- Strong understanding of IT frameworks and standards (NIST, ISO 27001, COBIT, etc.)
- Exceptional interpersonal and communication skills
,with the ability to translate technical risk insights into clear business language for senior audiences. - Proven project management and stakeholder engagement capabilities, with experience handling multiple initiatives with high complexity and strategic importance.
It would be great if you also had:
- Experience developing or overseeing risk metrics and visualization dashboards, such as Power BI.
- Demonstrated experience conducting or overseeing ITGC reviews, cyber incident response exercises, and/or cloud risk assessments.
- Familiarity with risk management practices within Federally Regulated Financial Institutions, Government or Crown Corporations, including relevant legislation and accountability frameworks.
Posting closing date: Note, the competition will remain active until filled.
Our commitment to diversity, equity, and inclusion
We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.
CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.
Learn more about our commitment to diversity and inclusion
What happens after you apply
We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.
If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!