Director, Cybersecurity, Resilience & Governance
ManulifeAbout the role
We are seeking a talented individual to lead our Business Unit Security Officers (BUSOs), Business Continuity Officers, Disaster Recover officers and onboarding Managers as a key pillar in the Cybersecurity, Resilience & Governance (CRG) team. As a lead, you will help business and IT partners to recognize and manage their information risk in a dynamic business environment. You will participate in critical projects and initiatives to ensure information risk is always considered and managed appropriately.
A successful lead will serve as a trusted partner and subject expert supporting his/her teams to empower and help the business protect their information assets and intellectual property. You will help implement new technologies and tools, foster consistency through common methodologies and stay fully aligned with cybersecurity, business continuity and disaster recovery and efforts.
Office location: Boston - USA or Toronto - Canada (alternate)
Work arrangement: 3 days in office, 2 days from Home; Remote working option is not available;
Required Qualifications:
5+ Years of experience managing a diverse team of SME’s in one or more of the following disciplines: Disaster Recovery, Business Continuity, Information Technology/Systems, Project Management, Information Risk Management, Information Security, ideally with some of that time spent in a large, complex organization.
Strong understanding of application security (OWASP Top 10, API security, secure coding practices)
Experience with modern authentication and identity systems (OAuth2, OIDC, SAML, service principals, workload identity)
Knowledge of secrets management and secure credential handling (e.g., Key Vault, vault-based patterns, eliminating hardcoded secrets)
Familiarity with cloud security architectures (Azure/AWS), including IAM, networking, and workload protection
Some familiarity with BCM Planning tools and/or relational databases – e.g., Fusion Risk Management.
Ability to interpret and assess security findings (e.g., Snyk, code scanning, penetration testing results) and guide remediation
Broad understanding of application system technologies and Business Continuity/Disaster Recovery tools and techniques.
Excellent communication skills (oral and written) including ability to develop and deliver effective user education sessions and a willingness to present to all organizational levels.
Achievement oriented with proven project management skills and the ability to work independently and as part of a team, managing multiple priorities within tight deadlines while maintaining a professional and friendly attitude.
Ability to work off-hours to help manage incidents or communicate with colleagues in different time zones, occasionally.
Proven ability to build relationships, engage and influence others, and work with diverse internal and international user communities as well as vendors
BUSO responsibilities
Lead and improve application and operational security consulting services to IT, partners and clients
Serve as a technical security advisor to BUSOs and business-aligned teams, elevating their ability to identify, assess, and remediate risk beyond checklist-based approaches
Provide hands-on guidance on secure architecture design, including application, cloud, and infrastructure security patterns
Act as an escalation point for complex security issues, including authentication, authorization, secrets management, and data protection
Guide teams on modern identity and access patterns (OAuth2, OIDC, SAML, service-to-service authentication, workload identity, etc.)
Provide technical oversight on cloud security (Azure/AWS) including IAM, network segmentation, and workload protection
Translate security requirements into practical, implementable solutions aligned with business and engineering constraints
Drive adoption of secure-by-design principles across new initiatives and onboarding efforts
Mentor BUSOs to become more technically fluent, enabling them to act as effective security consultants to the business
Oversee and technically validate application risk assessments, ensuring findings are grounded in real architecture, data flows, and threat models (not just control checklists)
Maintain a high level of awareness on security issues and control objectives among all levels of business line staff
Embrace and deploy innovati
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s