Manager, BRAC Technology
Application Deadline:
08/27/2026 Address:
VIRTUAL(R)59 - REMOTE/TELETRAVAIL - ON - BMO Job Family Group:
Business Management
Summary
This role provides risk governance and advisory support for the Technology Group with a focus on risk management, regulatory compliance, control effectiveness, metrics, , and risk appetite alignment. The Business Risk Advisory Controls Team (BRAC) operates in a matrix environment, driving oversight, strengthening the control environment, and leveraging data-driven insights to enhance risk management practices and decision making.
Key Responsibilities:
- Provide advisory support to risk assessments, control design, and issue identification and remediation to ensure appropriate risk mitigation and regulatory adherence.
- Communicate and support activities related to new or updated regulatory requirements in alignment to Enterprise Compliance Program (ECP).
- Oversee various Enterprise risk program execution against defined requirements, timelines, and deliverables; collaborate with key stakeholders to monitor progress, identify risks or delays, and escalate issues to ensure timely and compliant delivery.”
- Drive design, enhancement, and oversight of the Process, Risk & Control (PRC) environment, including control library integrity, coverage, and effectiveness.
- Leverage data analytics and insights to identify emerging risks, inform decision-making, and enhance risk monitoring.
Qualifications:
-
6+ years of experience in technology or financial services, with a degree in computer science, engineering, info systems, math, or business.
-
3+ years of experience in risk or compliance, with strong analytical and evaluation skills.
- Ability to leverage data analytics and insights to assess risk, identify trends, and support risk-informed decision-making.
- Ability to interpret regulatory requirements to support governance and related documentation.
- Strong data analytics and presentation skills; advanced Excel, PowerPoint, and experience with dashboard/analytics tools.
- Ability to explain complex technical topics in simple terms to business audiences.
- Certifications (asset): CRISC, CGEIT, CISA, CISM, PMP, cloud compliance .
- Strong understanding of control frameworks (e.g., COSO, NIST, COBIT ).
- Excellent communication, analytical thinking, collaboration, and problem‑solving skills.
- Able to work through ambiguity and make data‑driven decisions.
Supports the business/group leader in the effective implementation, maintenance and administration of first line of defense (1st LOD) programs (e.g., operational risk, AML, compliance, regulatory, etc.), including overseeing business operations within the jurisdiction to ensure adherence and efficiency. Contributes to a strong risk management culture through collaboration with other first line employees, and second & third line functions to ensure Compliance, AML or operational risks are identified, mitigated, monitored and reported on an ongoing basis.
- Supports multiple, varied business units with corresponding number of regulators.
- Monitors and advises on management of risk requirements within the defined risk appetite.
- Manages/supports large/complex risk programs/frameworks /projects/initiatives to ensure risks are appropriately mitigated and regulations adhered to.
- Monitors industry and legislative developments and continuously updates programs to ensure they are competitive and effective
- Supports the position on regulatory compliance Issues by interpreting requirements (existing, new and emerging) and identifying, analysing and addressing resultant gaps and issues, including those raised through the review of change initiatives. Understands the identified risk exposures and supports the development of action plans required to mitigate identified risks.
- Acts as a subject matter expert in the evaluation, development and implementation of an internal control system.
- Supports the execution of strategic ini