Director, Information Risk Management (Second Line Of Defense) At Manulife Financial
CurrentManages team of 3 people (full time & contractor) to provide the following services utilizing Archer GRC Solution1) Project Risk Oversight (budget > $1 Million, 50+ projects per year)• Provide advice and guidance to project team to manage and mitigate operational and informational Risks• Regular meeting to review Risk Register and Information Risk Assessment2) Issues and Remediation Closure Review (120+ Issues per year)• Review closed Issues to ensure the non-compliance/gaps are completely remediated with appropriated evidence• Follow up with Business and IT with closed Issues that the remediation may not be effective or incomplete3) Vendor Risk Oversight (Contract cost > $3 Millions)• Provide advice, guidance, and concurrence on contract negotiation from Information Security perspective to ensure the Third Party has robust IT/Security control and governance for data resilience/protection/recovery, cyberattack prevention, and regulatory compliance (Financial and Privacy)4) Exception Request Review• Review Exception Request (Technical or Third Party Contract related) with relevant documents and corresponding compensation controls for preparation for CRO/CIRO approval5) Acted as Subject Matter Expert for Information Security and Third Party Standards Revision