Interac

Tech/Cyber Oversight Risk Lead

Toronto Full time

Who We Are:

 

Every transaction matters. Every Canadian matters. At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives.
 
Founded in 1984, Interac connects Canadians through secure digital payments, advanced identity verification and industry-leading fraud protection. Connecting banks, businesses, and individuals, Interac enables millions to send, receive, and manage money safely and effortlessly every day — across both digital and physical environments.

 

As the backbone of Canada’s financial ecosystem, Interac facilitates over 20 million transactions daily, supported by trusted partnerships with government and financial institutions. Consistently ranked as Canada’s most reputable financial technology brand, Interac is deeply embedded in the daily lives of Canadians.

Who You Will Work With:  

The vacant role will report to the Head, Risk Management. This senior, strategic role provides independent second-line oversight of technology and cyber risk and serves as the enterprise subject-matter expert and credible challenger across all platforms and business units. The role is accountable for advancing cyber resilience and technology risk maturity, ensuring alignment with enterprise risk frameworks, risk appetite, and evolving threat landscapes.

A critical component of this role is supporting the organization’s delivery of, and ongoing compliance with, regulatory expectations set by the Bank of Canada and other relevant regulators, from a second-line risk perspective. This includes providing independent challenge, oversight, and assurance over first-line readiness, execution, and sustainability of regulatory requirements related to technology, cyber security, operational resilience, and third-party risk.

Acting as a trusted advisor to first-line technology and business teams, the role balances partnership with clear accountability for independent challenge, escalation, and executive-level engagement.
 

What You Will Do:  

  • Oversee and embed effective technology and cyber risk management practices across platforms, services, and business units, in alignment with enterprise risk frameworks and risk appetite.

  • Serve as the enterprise’s independent second-line lead for technology and cyber risk, providing objective challenge, oversight, and thought leadership.

  • Play a key role in supporting and overseeing the organization’s response to Bank of Canada regulatory expectations, ensuring second-line assurance over design, implementation, and ongoing effectiveness.

  • Drive continuous improvement in cyber resilience, technology risk management, and operational resilience within a rapidly evolving digital and regulatory environment

Technology and Cyber Risk Leadership

  • Provide strategic second-line guidance and oversight for technology and cyber risk management across platforms and services, integrating enterprise risk frameworks and regulatory requirements into planning, delivery, and change management.

  • Lead and oversee technology and cyber risk assessments, including Change Initiative Risk Assessments (CIRAs) and Risk & Control Self-Assessments (RCSAs), ensuring consistency with enterprise standards and regulatory expectations.

  • Support and challenge first-line teams in the design and operation of controls related to cyber security, technology risk, and operational resilience.

  • Coach and influence first-line leaders to strengthen technology and cyber risk capability and reinforce a strong, consistent risk culture.

Enterprise-Wide Tech/Cyber Risk Oversight

  • Serve as the independent second-line expert for technology and cyber risk, providing objective oversight and effective challenge across all business units.

  • Oversee threat identification, control design, mitigation strategies, and incident response practices, ensuring risks are appropriately identified, assessed, and managed.

  • Monitor technology and cyber Key Risk Indicators (KRIs), escalate emerging risks, and assess compliance with applicable regulatory standards and frameworks (e.g., Bank of Canada expectations, OSFI, NIST, ISO 27001, PCI DSS).

  • Provide second-line oversight of emerging and cross-cutting risk areas, including:

    • Third-party and vendor risk

    • Cloud security and digital infrastructure

    • AI governance and model risk

    • Operational resilience and critical service continuity

Regulatory Oversight

  • Provide second-line oversight and challenge of the organization’s readiness for, and adherence to, Bank of Canada supervisory expectations, including those related to cyber security, technology risk, operational resilience, and third-party dependencies.

  • Partner with Legal, Compliance, and first-line teams to assess regulatory impacts, review remediation plans, and ensure sustainable risk management practices are embedded.

  • Support regulatory examinations, supervisory interactions, and responses by providing independent risk perspectives, evidence of effective oversight, and clear articulation of risk posture.

  • Monitor regulatory developments and emerging supervisory themes, advising senior leadership on implications for the technology and cyber risk profile.

Governance & Executive Engagement

  • Represent technology and cyber risk themes at governance forums and deliver executive-level reporting and Board insights, translating complex risk concepts into actionable intelligence.

  • Foster transparency, accountability, and operational effectiveness across the organization.

  • Represent second line technology and cyber risk oversight matters at management committees, governance forums, and risk committees, including delivery of executive-level reporting and Board insights.

What You Bring: 

  • 15+ years of progressive experience in technology risk management, cyber risk, ERM, or related disciplines within financial services or payments.

  • Expertise in second-line tech/cyber risk functions, including independent challenge and oversight.

  • Advanced knowledge of cyber risk management, including emerging threats, control frameworks (e.g., NIST, ISO 27001), and incident response.

  • Strong understanding of ERM principles, risk appetite, control frameworks, RCSAs, CIRAs, and the Three Lines of Defense model.

  • Experience engaging with regulatory bodies and leading enterprise-wide risk programs.

  • Exceptional communication skills for executive and Board-level engagement.

  • Professional designations such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are considered assets.

  • Eligibility to work for Interac Corp. in Canada in a full-time capacity.   

What We’re Offering: 

The hiring range for this position is $160,000 – $180,000, and you will also be eligible for our short-term incentive plan. The exact amount will depend on factors such as skills, experience, and job-related knowledge, but Interac’s commitment goes beyond compensation. Our Total Rewards package is designed to support your well-being and future, and includes: 

  • Generous vacation and wellness days to help you recharge 

  • Comprehensive employer-paid benefits coverage for peace of mind 

  • Market-leading employer-funded RRSP program to invest in your future 

  • Flexible hybrid work model for better work-life balance 

  • Access to a free and confidential 24/7 employee & family assistance program to offer support for you and your immediate family 

  • Pregnancy and parental leave top-up to support growing families 

  • Charitable donation matching with United Way to amplify your impact 

Why Join Us?

 

At Interac, the impact we make, and the people who drive it, is profound. When you become part of our team, you’re joining a purpose-driven organization that’s shaping the future of digital finance in Canada. Here’s what you can expect:

  • Investing in the Future – Help us unlock digital prosperity for all Canadians.

  • Innovative Thinking – Collaborate on products, practices, and platforms that redefine what’s possible.

  • Inclusive Culture – Be empowered to bring your whole self to work and realize your full potential.

  • Inspiring Community – Work in an ecosystem where we lift each other up and rise together.

  • Intentional Support – Enjoy flexible, supportive offerings that prioritize your total wellness.

Additional Pre-Employment Requirements:

 

To ensure the integrity of our organization, successful candidates will be required to complete background checks, which may include, Canadian Criminal Credit Check, Canadian ID Cross-Check, Public Safety Verification, 5-year Employment Verification, Education Verification, Credit Check, and Social Media Check.

Equal Opportunity Employer

 

Interac is also an equal opportunity employer committed to fostering a diverse and inclusive workplace. We believe that innovation thrives when people from different backgrounds, experiences, and perspectives come together. That’s why we are committed to providing fair and equitable employment opportunities for all individuals, without discrimination based on race, color, ancestry, ethnic origin, place of origin, citizenship, creed, sex, sexual orientation, gender identity or expression, age, marital or family status, disability, or any other characteristic protected by applicable law.

 

If you require accommodation during any stage of the application or recruitment process, please contact us at humanresources@interac.ca. We will work with you to meet your needs.

 

Please be aware that certain individuals are misusing Interac Corp.’s name and logo to promote fictitious employment opportunities. Interac Corp. never requests, solicits, or accepts any form of payment in exchange for employment. Any such offers are fraudulent and should be disregarded. Interac Corp. assumes no liability for any claims, losses, damages, expenses, or inconveniences arising from or related to these fraudulent activities. Such communications do not constitute an offer or representation by Interac Corp. or its subsidiaries and affiliates.