Senior Manager, IT Audit
Join a purpose-driven, winning team committed to results in an inclusive and high-performing culture. Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank’s strong U.S. presence provides clients an important bridge to this key global market for trade and investment flows across the Americas and the world.
About the role
As the 3rd Line of Defense, Internal Audit provides enterprise-wide, independent, and objective assurance over the design and operations of the Bank’s internal controls, risk management, and governance processes. The Senior Audit Manager assists in leading internal audit activities for Cybersecurity and Infrastructure, ensuring business strategies, plans, and initiatives comply with governing regulations, internal policies, and procedures. This role is dynamic and innovative, using data to deliver industry-leading assurance and insights to keep the Bank and its customers safe.
Responsibilities
- Act primarily as Officer in Charge (OIC) as a team member for assigned audits; may act as Audit Principal (AP) for low to medium complexity audits.
- Carry out IT audit projects related to Information Security, IT Infrastructure, Networks, IT Applications, with potential involvement in Data Governance and Cybersecurity.
- Oversee audit planning, execution, and reporting as OIC/AP, including developing risk-based audit approaches and scheduling resources.
- Analyze audit results, determine root causes of issues, and prepare findings for management presentation.
- Follow up on corrective actions and progress for reported issues; share relevant information impacting other audit areas.
- Support a client-focused culture to deepen relationships and leverage broader Bank systems and knowledge.
- Ensure compliance with Scotiabank standards and the Institute of Internal Auditors (IIA) Code of Ethics.
- Build and maintain strong relationships with internal and external stakeholders and regulators.
- Review workpapers to ensure internal control weaknesses are clearly documented with root-cause recommendations.
- Support ongoing monitoring of business, industry, and regulatory changes, emerging risks, and systemic issues.
- Foster a high-performance environment, implementing people strategies to attract, retain, and develop talent.
- Perform risk assessments of IT environments, including general IT controls and automated application controls.
- Evaluate technical controls such as cybersecurity, disaster recovery, digital, privacy, and cloud security for design and operating effectiveness.
Requirements
- University/Post-secondary degree in Business or equivalent.
- Relevant Audit or business certifications (e.g., CISA, CISSP, CISM).
- At least 7+ years of relevant experience.
- Working knowledge of operations and regulatory environments for applicable units.
- Proven ability to work in high levels of ambiguity and rapidly changing environments.
- Highly proficient in applying Scotiabank methodology and risk-based auditing standards.
- Strong analytical skills using data analytics or visualization tools.
- Ability to execute and supervise multiple projects simultaneously.
- Highly developed interpersonal and communication skills (verbal and written).
- Strong people management and coaching/development skills.
- Curiosity mindset.
Working Conditions
- Standard office-based environment; non-standard hours common, especially at quarter-end.
- Moderate travel required for audit assignments.
- Frequent deadlines and schedule changes due to unforeseen events.
Benefits
Scotiabank offers flexible benefit programs designed to support holistic well-being, including family, financial, physical, mental, and social health needs.
Candidates must apply directly online to be considered for this role.