Senior Associate, Risk
Job description
About the role
You will partner with project teams to define technology risk strategies and translate complex risk concepts into clear, actionable advice for senior stakeholders. You will design and execute risk assessments, control testing, and cybersecurity advisory engagements across diverse client environments. You will lead the scoping and planning of technology risk initiatives, ensuring realistic timelines, team structure, and effort estimates align with client needs. You will facilitate client workshops and interviews, gathering requirements while building trusted relationships at all levels of the organization. You will synthesize findings into concise reports, visual presentations, and prioritized recommendations that drive measurable improvements. You will monitor project risks, issues, and dependencies, escalating appropriately and coordinating mitigation plans with the project team. You will contribute to the development of internal tools, playbooks, and knowledge assets that enhance our collective delivery capability.
Key facts
What you'll do
Conduct proactive technology risk identification and assessment activities to uncover potential issues before they impact clients.
Apply recognized risk and control frameworks such as COSO, COBIT, NIST CSF, and ISO standards to evaluate client technology environments.
Review policies, standards, procedures, and control documentation to assess completeness, consistency, and alignment with best practices.
Evaluate the effectiveness of IT and business controls through testing, interviews, and evidence analysis to validate control design and operating effectiveness.
Support regulatory and industry-standard assessments, ensuring relevant risks and requirements are appropriately addressed and documented.
Lead scoping and planning for technology risk and advisory engagements, defining workstreams, timelines, and resource requirements.
Facilitate client meetings and interviews, translating technical concepts into clear narratives for diverse audiences.
Develop structured reports, presentations, and recommendations that are practical, actionable, and aligned with client constraints.
Identify opportunities to standardize, rationalize, or automate risk and control activities across complex client portfolios.
Monitor and escalate project risks, issues, dependencies, and resource constraints to maintain delivery integrity.
Provide day-to-day direction, coaching, and mentoring to junior team members, fostering a growth-oriented team environment.
Lead cross-functional project teams, coordinating efforts to deliver security-focused initiatives on schedule and within scope.
Contribute to business development by shaping compelling proposals, insights, and thought leadership that support client acquisition.
Support employee growth and capability building through Optimus SBR's Career Development Program and structured learning initiatives.
Requirements
You must possess a minimum of 6 years of cumulative experience in technology risk, IT audit, cybersecurity, control testing, regulatory compliance, or advisory consulting.
You must demonstrate a strong understanding of IT and business controls, including hands-on experience assessing control design and evaluating operating effectiveness.
You must have a proven track record of reviewing policies, procedures, risks, and controls, identifying gaps, and recommending standardization opportunities.
You must be comfortable applying recognized frameworks such as COSO, COBIT, NIST CSF, and ISO standards to assess client environments and deliver practical recommendations.
You must have experience conducting control testing and evidence evaluation to confirm that controls are designed effectively and operating as intended.
You must be able to interpret regulatory and industry-standard requirements, assessing whether risks and controls are appropriately addressed within client contexts.
You must possess strong analytical, problem-solving, and critical-thinking skills, with the ability to synthesize complex information into clear conclusions.
You must have excellent written and verbal communication skills, enabling you to engage confidently with senior stakeholders and cross-functional partners.
Nice to have
Experience contributing to business development, including crafting proposals, pitches, and client-facing materials that support growth initiatives.
Familiarity with technology advisory and delivery for cybersecurity, privacy, digital transformation, or cloud environments.
Background in managing and developing high-performing teams, including mentoring junior consultants and fostering collaborative delivery.
Practical notes
This is a full-time position based in Toronto.
The role may involve occasional travel, as required by client project needs.
Candidates must be eligible to work in Canada without sponsorship for this role.