Job Title or Location
RECENT SEARCHES

Director It Advisory Risk Assurance

OXARO
Ottawa, ON
Remote
Full-time
Management
Posted 23 days ago
Salary:

We are a member firm of the greater Raymond Chabot Grant Thornton & Grant Thornton Canada networks. Oxaro Inc. focuses on supporting public sector clients across Canada in advisory and placement services as well as digital solutions. Over recent years, we have been focusing on growing and expanding the value-added services we offer to our Public Sector clients. Through discoveries made during advisory engagements, Oxaro Inc. recognized a trending gap in the marketplace to deliver innovative digital solutions. Oxaro's Digital practice seeks to close this gap with the Public Sector through the delivery of modern technology, and services for our clients.

Now, let's get to the nitty gritty...

What we're looking for

Oxaro Inc. is seeking a Director (IT Advisory, Risk & Assurance) to manage and deliver client engagements and project plans in line with our guidelines and standards. Conduct fieldwork (remote or at client site) such as walkthroughs, interviews, technical testing, document findings and observations, conduct interviews, etc. The successful candidate will be highly motivated, committed and be able to multi-task while coping with changing priorities. They will bring forth a strong educational background, with extensive knowledge and experience within this field. They will be a team player and plays the role in mentoring and training junior staff. As well as contribute to enhancing Oxaro's IT Advisory, Risk and Assurance service line through market presence and working with senior management on achieving strategic goals.

A day in the life

  • Lead and execute client assessments in the following areas:
    • IT internal audit
    • IT Risk
    • Data Governance and Management
    • Artificial Intelligence Readiness
    • Cloud Security
    • Various IT security and Operational Audits
  • Conduct analysis of companies' internal control structure, performance, sustainability, productivity, and efficiency
  • Take an active role in Developing and maintaining relationships with internal staff and key client contacts, maintaining market presence through things such as attending networking events.
  • Conduct fieldwork (remote or at client site) such as walkthroughs, interviews, technical testing, document findings and observations, conduct interviews, etc.
  • Maintain knowledge of risk and governance frameworks, regulatory and compliance mandates, and latest industry trends
  • Provide clients with advice and guidance on their security posture, security controls and recommendations for improvement.
  • Support clients with remediation activities and control verifications.
  • Provide ongoing feedback to clients, project team and senior management alike through the preparation of reports and analyses, preparation of advisory and assurance reports and related deliverables.
  • Manage multiple projects while meeting deadlines.
  • Maintain a compelling and energetic work environment as well as provide coaching and guidance to junior staff to ensure timeliness and deliverables to clients with ease.

Role Requirements:

  • Bachelor's degree required in one of these disciplines: accounting, business, finance, economics, computer science, engineering, or other relevant degree.
  • One of the following designations: CPA, CISSP, CISA, CISM, CRISC, ISO27001 Lead Auditor.
  • 5 to 10 years of experience in deploying, assessing, or managing information technology risk with combined relevant experience in IT auditing, risk management methodologies, information security, and readiness assessments.
  • Strong understanding and experience with security controls audits or assessments (e.g., SOC 2, ISO 27001, NIST) is preferred.
  • Experience in ITGCs, ITACs, cyber security, project risk, security governance, Cloud, data governance, application security, IT business continuity management, etc.
  • Knowledge and experience with business and technology frameworks/standards such as NIST CSF, ISO 27001, ITIL, COBIT, COSO, SOX, SOC1/2, PCI, GDPR etc.
  • Excellent interpersonal and communication skills and strong attention to detail
  • A strong IT background is preferred including demonstratable knowledge of actively managing risks either as an IT control owner or within an IT risk, audit or information security team
  • Ability to work independently with little supervision in a fast-paced environment.
  • Independent thinker with keen attention to details and strong organization and analytical skills.
  • Willingness and ability to travel to client sites within Canada and Internationally when necessary. Flexible to work within varying time zones.
  • Demonstratable ability to develop strong relationships and be recognized as a trusted advisor to key stakeholders.
  • Valid secret clearance or ability to obtain as such.