Senior Risk and Audit Specialist

Posted An Hour Ago
Be an Early Applicant
Mississauga, ON, CAN
In-Office
84K-110K Annually
Senior level
Fintech • Information Technology • Other • Payments
The Role
Manage risk assessments, control evaluations, compliance reviews, and internal and external audits for Canadian Student Lending. Coordinate assurance engagements, prepare audit documentation and reports, assess regulatory and technology risks, advise business stakeholders, and monitor remediation plans. The role also supports governance, process improvement, risk metrics, special projects, and continuous enhancement of risk and compliance frameworks.
Summary Generated by Built In

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

The Senior Risk and Compliance Officer plays a key role in supporting the organization's Canadian Student Lending line of business by ensuring risks are appropriately identified, assessed, monitored, and managed. The role partners closely with business leadership and key stakeholders to support risk management, regulatory compliance, governance, and internal audit activities.
This position is responsible for evaluating the effectiveness of internal controls, conducting risk and compliance reviews, supporting internal and external audits, and providing independent assessments of business processes and initiatives. The successful candidate will act as a trusted advisor to the Canadian Student Lending business, helping ensure compliance with applicable regulatory requirements, contractual obligations, industry standards, and company policies while supporting the achievement of strategic business objectives.
Compensation Range for this Role: $84,000-$110,000 CAD (based on experience)
This role has a hybrid work requirement of 2 days minimum in office per week.
Additionally, this position requires the successful completion of a Government of Canada Reliability Clearance (PERC) as a condition of employment. Candidates must be eligible to obtain and maintain the required clearance throughout their employment.

JOB RESPONSIBILITIES:

Risk Assessment & Control Management

  • Conduct risk assessments of Canadian Student Lending products, processes, and operational activities to identify emerging risks, control gaps, and areas requiring enhanced oversight.
  • Evaluate the design and operating effectiveness of controls to ensure risks are managed within established risk appetite and tolerance levels.
  • Validate control exceptions by quantifying risk exposure, investigating root causes, and collaborating with business owners to develop corrective action plans.
  • Partner with business leaders and stakeholders to develop, implement, and monitor mitigation strategies for identified risks and control deficiencies.

Compliance, Audit & Assurance

  • Manage third-party and client-mandated audits, acting as the primary liaison with external audit firms for engagements such as CSAE 3416, SOC 2, CSAE 3530, IT General Controls (ITGC), and Information Security audits.
  • Prepare and maintain comprehensive audit workpapers and supporting documentation to substantiate testing performed and conclusions reached.
  • Draft formal audit and risk assessment reports, communicate findings and recommendations to management, and monitor the timely remediation of identified issues.
  • Maintain current knowledge of regulatory requirements, auditing standards, risk management practices, Information Security frameworks, and industry trends.

Advisory & Business Partnering

  • Support business initiatives, product enhancements, and operational changes by assessing regulatory, compliance, operational, technology, and reputational risks.
  • Participate in project teams to provide risk and compliance guidance during the development of business processes, system specifications, policies, procedures, and controls.
  • Act as a trusted advisor to business stakeholders by providing practical risk-based recommendations that balance regulatory and client obligations with business objectives.

Process Improvement & Operational Excellence

  • Identify opportunities to strengthen controls, improve processes, enhance operational efficiency, and reduce risk exposure.
  • Recommend and support the implementation of system, process, and procedural improvements that drive compliance, efficiency, and cost savings.
  • Contribute to the continuous enhancement of the organization's risk management, governance, and compliance frameworks.

Reporting & Special Projects

  • Prepare presentations, reports, and risk metrics for management and governance committees, as required.
  • Track, monitor, and report on remediation activities to ensure sustainable resolution of identified issues.
  • Lead or participate in special projects, investigations, and enterprise risk initiatives as required.

EXPERIENCE:

  • Minimum 3+ years in Risk Management, Compliance, Internal Audit, External Audit, Information Security, or a related field.

  • Proven track record supporting or leading assurance engagements, including CSAE 3416, SOC 1/SOC 2, CSAE 3530, IT General Controls (ITGC), Information Security, and regulatory compliance audits.

  • Demonstrated ability to conduct risk assessments, evaluate control effectiveness, manage audit findings, and drive remediation activities.

  • Experience applying data analytics and reporting techniques to support risk-based decision-making and assurance activities.

  • Experience coordinating with external auditors, clients, and senior stakeholders to support assurance and compliance objectives.

KNOWLEDGE/SKILLS: 

Technical Knowledge

  • Strong knowledge of risk management, internal controls, audit methodologies, and governance practices and the Three Lines Model.

  • Solid understanding of control and compliance frameworks, including COSO, COBIT, NIST, ITSG-33, SOX, and SOC reporting requirements.

  • Understanding of the Three Lines Model and corporate governance principles.

  • Knowledge of information technology, cybersecurity, information security, operational risk concepts and regulatory compliance requirements.

  • Familiarity with industry best practices and emerging trends in risk, compliance, audit, and information security.

  • Ability to evaluate risks, controls, processes, and systems and recommend practical, risk-based improvements.

Skills & Competencies

  • High degree of integrity, professionalism, and discretion in handling confidential and sensitive information.

  • Strong analytical and problem-solving skills with the ability to identify root causes, evaluate risks, and develop practical solutions.

  • Excellent communication and presentation skills, with the ability to influence and effectively engage stakeholders at all levels, including senior leadership.

  • Self-motivated and detail-oriented, with the ability to work independently while maintaining a strategic and risk-based perspective.

  • Strong organizational and project management abilities, capable of managing multiple priorities in a dynamic environment.

  • Flexible and adaptable, with the ability to support audits, projects, and business initiatives that may occasionally require evening or weekend work.

Preferred Qualifications

  • Professional certification such as CISA, CIA, CPA, CISSP, CISM, CRISC, or an equivalent designation.

  • Experience in FinTech, Banking, Financial Services, Technology, or other highly regulated industries.

  • Background in technology risk, cybersecurity, IT controls auditing, or public accounting/consulting.

  • Experience managing client-driven assurance engagements and external audit relationships.

  • Knowledge of regulatory and compliance requirements applicable to public companies or regulated entities.

This position is for an existing vacancy within our organization.

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc.


Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.  


Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or [email protected].


Nelnet is a Drug Free and Tobacco Free Workplace.


Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

Skills Required

  • Minimum 3+ years of experience in risk management, compliance, internal audit, external audit, information security, or a related field
  • Experience supporting or leading assurance engagements involving CSAE 3416, SOC 1/SOC 2, CSAE 3530, IT General Controls, information security, and regulatory compliance audits
  • Ability to conduct risk assessments, evaluate control effectiveness, manage audit findings, and drive remediation activities
  • Experience applying data analytics and reporting techniques to risk-based decision-making and assurance activities
  • Experience coordinating with external auditors, clients, and senior stakeholders
  • Knowledge of risk management, internal controls, audit methodologies, governance practices, and the Three Lines Model
  • Understanding of COSO, COBIT, NIST, ITSG-33, SOX, and SOC reporting requirements
  • Knowledge of information technology, cybersecurity, information security, operational risk, and regulatory compliance
  • Strong analytical, problem-solving, communication, presentation, organizational, and project management skills
  • Professional certification such as CISA, CIA, CPA, CISSP, CISM, CRISC, or equivalent
  • Experience in FinTech, banking, financial services, technology, or another highly regulated industry
  • Background in technology risk, cybersecurity, IT controls auditing, or public accounting/consulting
  • Experience managing client-driven assurance engagements and external audit relationships
  • Knowledge of regulatory and compliance requirements for public companies or regulated entities
  • Eligibility to obtain and maintain Government of Canada Reliability Clearance (PERC)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lincoln, NE
5,001 Employees

What We Do

Nelnet is a leading student loan servicer – but we’re even more than that. We provide payment technology for over 1,300 higher education institutions and 11,500 K-12 schools. We deliver world-class fiber internet, TV, and phone services to residents of Nebraska and Colorado. We help borrowers achieve their educational goals with private student loan and refinance solutions. And we help businesses boost their performance with our cutting-edge technology and trusted expertise. Each day, over 6,500 Nelnet associates in more than 30 communities across the country work to serve our customers and make their dreams possible. And we’re on the lookout for new people to help us go even further.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Halton Hills, ON, CAN
16000 Employees
18-22 Hourly

Samsara Logo Samsara

Business Operations Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Toronto, ON, CAN
4000 Employees
113K-133K Annually

Justworks Logo Justworks

Software Engineer

HR Tech • Payments • Professional Services • Software
Easy Apply
Hybrid
Toronto, ON, CAN
1165 Employees
109K-136K Annually

Mastercard Logo Mastercard

Technical Program Manager

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Toronto, ON, CAN
38800 Employees
121K-169K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account