Apply now »

Cybersecurity - Financial Services (FSO) - Senior Consultant

Location:  Toronto
Other locations:  Primary Location Only
Salary: Competitive
Date:  Sep 11, 2026

Job description

Requisition ID:  1744297

At EY, we’re all in to shape your future with confidence.

 

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

 

Join EY and help to build a better working world. 

 

We are seeking a Senior Consultant to support the delivery of enterprise cybersecurity assessments. This role combines cybersecurity advisory, structured assessment, stakeholder engagement, analytical judgment, and executive reporting. The successful candidate will independently own assigned cybersecurity domains, assess the maturity of relevant capabilities, and translate complex technical and operational information into clear findings and practical improvement recommendations.

 

The opportunity

 

The Senior Consultant will work with large, complex organizations to evaluate how effectively cybersecurity capabilities are designed, implemented, governed, measured, automated, and sustained. The role is broader than compliance mapping or control testing. It requires the ability to understand how people, process, technology, governance, and risk considerations work together across an enterprise cybersecurity program.

 

This job posting relates to an existing vacancy within our organization.

 

Key responsibilities 

  • Own assigned cybersecurity domains through assessment planning, artifact requests, document review, stakeholder workshops, maturity analysis, quality review, and reporting.

  • Translate framework outcomes and other industry guidance into practical, capability-based assessment criteria appropriate to the client environment. 

  • Review policies, standards, procedures, operating models, architectures, inventories, metrics, reports, and technical documentation to understand the current state. 

  • Plan and facilitate interviews and workshops with cybersecurity leaders, architects, engineers, risk teams, and control or capability owners. 

  • Ask targeted follow-up questions, appropriately challenge unsupported statements, and identify where further validation is required. 

  • Synthesize stakeholder input, artifacts, metrics, and technical context into consistent and defensible maturity conclusions. 

  • Draft concise current-state observations, maturity rationales, opportunities for improvement, risk implications, and practical recommendations. 

  • Connect detailed domain findings to broader themes, business impacts, target-state considerations, and prioritized improvement actions. 

  • Prepare clear, executive-ready materials and support presentations to client leadership. 

  • Guide Consultants, review draft analyses and workpapers, maintain consistency across domains, and escalate issues early. 

  • Contribute to the refinement of assessment methodologies, capability libraries, reporting approaches, and reusable intellectual property. 

 

To qualify for the role you must have

  • Hands-on experience delivering cybersecurity maturity, capability, risk, controls, assurance, or transformation assessments. 

  • Demonstrated ability to independently lead a workstream or assessment domain from information gathering through final reporting. 

  • Working knowledge of common cyber and IT frameworks, with the ability to explain how framework outcomes apply to real cybersecurity capabilities and operating environments. 

  • Broad understanding across multiple cybersecurity domains, with meaningful depth in at least two or three areas. 

  • Experience facilitating stakeholder interviews or workshops and communicating with both technical practitioners and senior leaders. 

  • Strong analytical judgment, including the ability to form supportable conclusions from incomplete, varied, or conflicting information. 

  • Excellent written communication skills, including findings, recommendations, presentations, and executive summaries. 

  • Ability to manage multiple domains, stakeholders, and deliverables while maintaining quality and consistency. 

  • Experience coaching junior team members and reviewing their work. 

 

Ideally, you’ll also have

  • Experience applying NIST CSF 2.0, including Functions, Categories, Subcategories, Current Profiles, and Target Profiles. 

  • Familiarity with NIST SP 800-53, CIS Controls, ISO/IEC 27001 and 27002, COBIT, CRI Profile, CSA CCM, or related cyber-risk frameworks. 

  • Experience in banking, insurance, payments, or another highly regulated and federated enterprise environment. 

  • Familiarity with Canadian financial-services expectations such as OSFI B-13 or other relevant regulatory guidance. 

  • Experience developing maturity models, target states, cyber roadmaps, benchmarking insights, or transformation recommendations. 

  • Relevant cybersecurity or risk certification such as CISSP, CISM, CRISC, CISA, ISO 27001, CCSP, or equivalent credential. Certifications are considered supporting qualifications rather than a substitute for practical delivery experience. 

 

Cybersecurity domain coverage 

 

Candidates are not expected to be specialists in every domain. The strongest profiles will demonstrate depth in selected areas and working fluency across several others. 

 

Domain grouping 

Illustrative areas 

Governance and risk 

Cyber governance, policy and standards, security metrics, second-line cyber risk, third-party risk, privacy 

Identity and data 

IAM, PAM, customer identity, data protection, data security, cryptography 

Applications and engineering 

Application security, API security, DevSecOps, secure software development, cloud security, AI security 

Infrastructure and operations 

Network security, endpoint security, vulnerability management, configuration management, asset management 

Detection and resilience 

Security operations, threat management, incident response, insider risk, forensics, disaster recovery, business continuity 

 

What we look for

 

We’re interested in intellectually curious people with a genuine passion for cybersecurity. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.

 

What we offer you

 

The EY benefits package is designed to support your physical, emotional, financial, and social wellbeing. Our extensive benefits include comprehensive medical, dental, and prescription drug coverage, as well as mental health benefits, a robust Employee Assistance Program and group savings plans to promote your overall wellbeing. We offer generous time off, including personal days, vacation days, and additional firm-wide holidays, along with the option to purchase extra vacation days. Employees can take advantage of EY's exclusive learning programs tailored just for them. We also provide internal opportunities for career development and advancement, enabling you to grow within the firm. Get involved in meaningful volunteering through EY Ripples and make a positive impact in the community.

 

EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.

  • Toronto/Calgary/Vancouver/Edmonton/Montreal: $90,000 to 136,000 per year

 

Are you ready to shape your future with confidence? Apply today.

 

To help create the best experience during the recruitment process, please describe any accommodations you may need.

 

Inclusiveness at EY 

  

Inclusiveness is at the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. We embrace diversity and are committed to combating systemic racism, advancing gender equity and women in leadership, advocating for the 2SLGBTQIA+ community, promoting our neuroinclusion and accessibility initiatives, and are dedicated to amplifying the voices of Indigenous peoples (First Nations, Inuit, and Métis) nationally as we strive towards reconciliation. Our diverse experiences, abilities, backgrounds, and perspectives make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world. 

 

Learn about our commitment to Inclusiveness at https://www.ey.com/en_ca/about-us/corporate-responsibility/equity 

 

EY | Building a better working world 

 

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

 

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

 

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

 

At EY, we use artificial intelligence (AI) tools as one element of our recruitment process to enhance efficiency and improve the candidate experience. While AI supports us in our process, human judgment and decision-making remain integral in our candidate experience. We are committed to the responsible use of AI, and our practices are continuously reviewed and refined to ensure they align with ethical principles and regulatory requirements.

 

To all recruitment agencies: EY does not accept unsolicited resumes from recruitment agencies. Any resumes submitted without a prior agreement or request from our hiring team will not be considered. EY is not responsible for any fees related to unsolicited resumes.

Apply now »