Skip to content
← Back to job listings

Senior Risk and Audit Specialist

Nelnet Diversified Services Canada, Inc. · CAN - MISSISSAUGA, Canada

CybersecurityExternal listingfull-timeabout 1 hour ago

About The Role

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

The Senior Risk and Compliance Officer plays a key role in supporting the organization's Canadian Student Lending line of business by ensuring risks are appropriately identified, assessed, monitored, and managed. The role partners closely with business leadership and key stakeholders to support risk management, regulatory compliance, governance, and internal audit activities.

This position is responsible for evaluating the effectiveness of internal controls, conducting risk and compliance reviews, supporting internal and external audits, and providing independent assessments of business processes and initiatives. The successful candidate will act as a trusted advisor to the Canadian Student Lending business, helping ensure compliance with applicable regulatory requirements, contractual obligations, industry standards, and company policies while supporting the achievement of strategic business objectives.

Compensation Range for this Role: $84,000-$110,000 CAD (based on experience)

This role has a hybrid work requirement of 2 days minimum in office per week.

Additionally, this position requires the successful completion of a Government of Canada Reliability Clearance (PERC) as a condition of employment. Candidates must be eligible to obtain and maintain the required clearance throughout their employment.

JOB RESPONSIBILITIES

Risk Assessment & Control Management

  • Conduct risk assessments of Canadian Student Lending products, processes, and operational activities to identify emerging risks, control gaps, and areas requiring enhanced oversight.
  • Evaluate the design and operating effectiveness of controls to ensure risks are managed within established risk appetite and tolerance levels.
  • Validate control exceptions by quantifying risk exposure, investigating root causes, and collaborating with business owners to develop corrective action plans.
  • Partner with business leaders and stakeholders to develop, implement, and monitor mitigation strategies for identified risks and control deficiencies.

Compliance, Audit & Assurance

  • Manage third-party and client-mandated audits, acting as the primary liaison with external audit firms for engagements such as CSAE 3416, SOC 2, CSAE 3530, IT General Controls (ITGC), and Information Security audits.
  • Prepare and maintain comprehensive audit workpapers and supporting documentation to substantiate testing performed and conclusions reached.
  • Draft formal audit and risk assessment reports, communicate findings and recommendations to management, and monitor the timely remediation of identified issues.
  • Maintain current knowledge of regulatory requirements, auditing standards, risk management practices, Information Security frameworks, and industry trends.

Advisory & Business Partnering

  • Support business initiatives, product enhancements, and operational changes by assessing regulatory, compliance, operational, technology, and reputational risks.
  • Participate in project teams to provide risk and compliance guidance during the development of business processes, system specifications, policies, procedures, and controls.
  • Act as a trusted advisor to business stakeholders by providing practical risk-based recommendations that balance regulatory and client obligations with business objectives.

Process Improvement & Operational Excellence

  • Identify opportunities to strengthen controls, improve processes, enhance operational efficiency, and reduce risk exposure.
  • Recommend and support the implementation of system, process, and procedural improvements that drive compliance, efficiency, and cost savings.
  • Contribute to the continuous enhancement of the organization's risk management, governance, and compliance frameworks.

Reporting & Special Projects

  • Prepare presentations, reports, and risk metrics for management and governance committees, as required.
  • Track, monitor, and report on remediation activities to ensure sustainable resolution of identified issues.
  • Lead or participate in special projects, investigations, and enterprise risk initiatives as required.

EXPERIENCE

  • Minimum 3+ years in Risk Management, Compliance, Internal Audit, External Audit, Information Security, or a related field.
  • Proven track record supporting or leading assurance engagements, including CSAE 3416, SOC 1/SOC 2, CSAE 3530, IT General Controls (ITGC), Information Security, and regulatory compliance audits.
  • Demonstrated ability to conduct risk assessments, evaluate control effectiveness, manage audit findings, and drive remediation activities.
  • Experience applying data analytics and reporting techniques to support risk-based decision-making and assurance activities.
  • Experience coordinating with external auditors, clients, and senior stakeholders to support assurance and compliance objectives.

KNOWLEDGE/SKILLS

Technical Knowledge

  • Strong knowledge of risk management, internal controls, audit methodologies, and governance practices and the Three Lines Model.
  • Solid understanding of control and compliance frameworks, including COSO, COBIT, NIST, ITSG-33, SOX, and SOC reporting requirements.
  • Understanding of the Three Lines Model and corporate governance principles.
  • Knowledge of information technology, cybersecurity, information security, operational risk concepts and regulatory compliance requirements.
  • Familiarity with industry best practices and emerging trends in risk, compliance, audit, and information security.
  • Ability to evaluate risks, controls, processes, and systems and recommend practical, risk-based improvements.

Skills & Competencies

  • High degree of integrity, professionalism, and discretion in handling confidential and sensitive information.
  • Strong analytical and problem-solving skills with the ability to identify root causes, evaluate risks, and develop practical solutions.
  • Excellent communication and presentation skills, with the ability to influence and effectively engage stakeholders at all levels, including senior leadership.
  • Self-motivated and detail-oriented, with the ability to work independently while maintaining a strategic and risk-based perspective.
  • Strong organizational and project management abilities, capable of managing multiple priorities in a dynamic environment.
  • Flexible and adaptable, with the ability to support audits, projects, and business initiatives that may occasionally require evening or weekend work.

Preferred Qualifications

  • Professional certification such as CISA, CIA, CPA, CISSP, CISM, CRISC, or an equivalent designation.
  • Experience in FinTech, Banking, Financial Services, Technology, or other highly regulated industries.
  • Background in technology risk, cybersecurity, IT controls auditing, or public accounting/consulting.
  • Experience managing client-driven assurance engagements and external audit relationships.
  • Knowledge of regulatory and compliance requirements applicable to public companies or regulated entities.

This position is for an existing vacancy within our organization.

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc .

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.

Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net .

Nelnet is a Drug Free and Tobacco Free Workplace.

Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

This is an external listing. JobSpring does not represent or verify the employer. Report this listing