Maplesoft Group is currently seeking an Enterprise Risk Management Architect (Legal, HR, and Cyber Security) consultant for our client.
Tasks and Responsibilities include, but are not limited to the following:
The Enterprise Insider Risk Management Architect is responsible for establishing the architecture for risk management within the organization. They oversee risk management activities, monitor and analyze risks, and report on them to the Board. The role involves creating sustainable and future-proof system designs, providing risk management and controls, and advising on technical strategy for risk management platforms.
Experience Required:
- 10 plus years of Enterprise Risk Management with a major Bank or Financial Institution
- This is a senior level role.
- Strong background in insider risk management from legal, HR and cyber perspectives. In particular, HR is high experience weight, followed by Cyber Security. Intelligence and Defense experience are an asset.
- Experience and expertise in IT security systems including firewalls, intrusion detection/prevention systems, and security event consolidation/correlation & reporting systems, authentication systems and assesses system and network vulnerabilities and works with responsible groups to address them.
Key responsibilities typically include:
1. Risk Assessment & Strategy
- Conduct insider risk assessments to identify vulnerabilities related to people, processes, and technology.
- Develop or refine insider risk programs tailored to the organization’s size, industry, and risk appetite.
- Define and implement governance structures for insider threat management.
2. Policy and Program Development
- Create and implement insider threat policies and procedures (e.g., acceptable use, employee monitoring, data access).
- Advise on data classification and access control policies to minimize unnecessary exposure of sensitive data.
- Help organizations balance privacy, legal, and ethical considerations with security needs.
3. Tools and Technology Integration
- Recommend and support deployment of insider risk tools (e.g., UEBA, DLP, SIEM, CASB).
- Integrate technical controls with business workflows (e.g., HR systems, IAM, data protection platforms).
- Assist in tuning detection rules and creating behavior-based alerting.
4. Monitoring and Detection
- Define risk indicators (technical and behavioral) to identify potential insider threats.
- Set up or optimize monitoring and alerting processes for anomalous behavior.
- Collaborate with SOC or threat detection teams to refine alert triage and escalation workflows.
5. Training and Awareness
- Develop and deliver training programs for employees, managers, and executives on insider threats.
- Conduct tabletop exercises and awareness campaigns to promote vigilance and reporting.
6. Investigation and Incident Response Support
- Create playbooks for insider threat response and support investigations.
- Work with HR, Legal, and Security during investigations of suspicious behavior or policy violations.
- Ensure evidence handling complies with legal and privacy requirements.
7. Cross-Functional Collaboration
- Liaise with departments such as HR, Legal, Compliance, and IT Security to align risk strategies.
- Facilitate cross-functional insider risk working groups or steering committees.
- Advise on processes for onboarding, role changes, and offboarding employees securely.
8. Reporting and Continuous Improvement
- Provide executive-level risk reports and program maturity assessments.
- Recommend and implement metrics/KPIs to track program effectiveness.
- Continuously update the program based on threat landscape, incidents, and organizational changes.
Maplesoft Group prides itself on its distinct corporate culture and recognizes that success is a direct reflection of our most valuable asset - our people. Therefore, attitude and ambition are key personality traits we seek out, along with skill and aptitude, in potential employees.
Maplesoft Group is committed to having a diverse, representative workforce and continuing to build an inclusive environment. We encourage applications from all qualified individuals. Maplesoft Group is an equal opportunity employer committed to diversity and inclusion. We are pleased to consider all qualified applicants irrespective of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veterans’ status, Aboriginal peoples or any other legally protected factors.
All employment decisions are made based on business needs, job requirements, and individual qualifications.
We are committed to developing inclusive, barrier-free recruitment and selection processes, and a work environment that supports our diverse workforce. Please let us know if you require accommodations at any stage of the recruitment process. We can be reached at Maplesoft Info at info@maplesoftgroup.com.
We thank you for your interest in Maplesoft Group and wish to advise you, that only candidates under consideration will be contacted.