Information Security Consultant

Manulife
Chicago, IL, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$86,100.0 - $136,100.0
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Generative AI Data Analytics RSA Archer Platform Virtual Agents Servicenow

Job description

Manulife is hiring an Information Security Consultant to lead Risk Control Self Assessments (RCSA) and Risk Governance across technology, data, and information/operational risk. Reporting to the Director, IRM, this first-line role oversees risk execution and control operations aligned to Manulife’s risk appetite, standards, and regulatory expectations. You will act as a trusted advisor to functional risk teams, centers of excellence, and senior technology/data leaders-driving effective control design, monitoring, issue remediation, and clear risk reporting to enable informed decisions and strong governance., * Perform internal control testing for RCSA, Informational, and Operational Risk and Resilience Oversight, regulatory, and audit activities

  • Design and implement new controls; test design and operating effectiveness
  • Coordinate research and responses for completeness, data analytics, compliance monitoring, internal reviews, regulatory requirements, and external audits
  • Analyze processes and controls using data analytics to identify gaps, trends, and remediation needs
  • Recommend system enhancements and operational improvements to increase efficiency and strengthen risk governance
  • Troubleshoot and resolve complex operational and control-related issues
  • Drive continuous improvement of business processes and controls
  • Act as an internal SME for escalations, consulting, and problem-solving
  • Provide governance over issue resolution and corrective actions
  • Ensure integrity of processing and workflows through cross-department collaboration
  • Maintain and manage the department’s procedures and documentation library, ensuring accuracy and currency

Requirements

Do you have experience in Risk management compliance audits?, * 3-5 years of experience in Information Risk, Technology Risk, Cyber Risk, GRC, or Operational Risk.

  • Experience performing independent L1B oversight or audit-style review activities.
  • Strong understanding of technology, data, cloud, infrastructure, and operational resilience risks.
  • Ability to evaluate complex risk scenarios.
  • Experience with risk programs (RCSA, third-party risk, issues, incidents, BC/DR, change risk).
  • Familiarity with GRC platforms such as Archer, ServiceNow, or Fusion.
  • Knowledge of regulatory frameworks and standards (ISO, NIST, COBIT, CSA/CCM, OSFI, etc.).
  • Exposure to Generative AI, Agentic AI, automation tools, or continuous monitoring technologies.

Benefits & conditions

3.93.9 out of 5 stars Chicago, IL Hybrid work $86,100 - $136,100 a year - Full-time, Pulled from the full job description

  • AD&D insurance
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Disability insurance
  • Paid holidays, * We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

The role being advertised is an existing vacancy.

About the company

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:37 min

Tracing the evolution from early AI to generative AI

Mike Mike · WWC 2025

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:14 min

Introduction to generative AI and content warnings

Cheuk Ho · WWC 2023

Videos

See all

Related articles

See all