Spécialiste, Sécurité de l’information Lieu de travail: Canada
Horaire: 37.5
Secteur d’activité: Solutions technologiques
Détails de la rémunération : Nous avons à cœur d’offrir une rémunération juste et équitable à tous nos collègues. En votre qualité de candidat ou de candidate, nous vous encourageons à avoir une conversation franche avec votre recruteur et à poser des questions sur la rémunération, notamment les particularités salariales de ce poste.
Description du poste:
KEY ACCOUNTABILITIES
CUSTOMER
Consult on Regulatory compliance requirements, reporting and questions
Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
Provide support and consulting in preparation for Operational Risk Management assessments and in composing management responses and appropriate remediation activities
Provide support and consulting in composing management responses and appropriate remediation activities for First Line control exceptions and Self-Declared findings
Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for AIVM
Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
Lead or contribute to completion of risk and control design assessments for AIVM activities, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
Contribute to the definition, development, and oversight of a global security management strategy and framework
Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG’s business
Support development and maintenance of ongoing Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank’s overall Enterprise Architecture, and any control gaps are addressed.
Participate if required in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
SHAREHOLDER
Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines
Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement
Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities
Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise
Remain informed of emerging issues, industry trends and/or relevant changes
Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness
Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements
Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank
Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required
Maintain a culture of risk management and control, supported by effective processes and sound infrastructure an in alignment with risk appetite
Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to identify risk / provide guidance
May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level
EMPLOYEE / TEAM
Continuously enhance knowledge / expertise in own area
Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
Prioritize and manage own workload to deliver quality results and meet assigned timelines
Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
Establish effective relationships across multiple business and technology partners, program and project managers
Participate in knowledge transfer within the team and business units
BREADTH & DEPTH
Expert knowledge of IT security and risk disciplines and practices
Advanced knowledge of organization, technology controls / security/ risk issues
May participate on complex, comprehensive or large projects and initiatives
Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
Generally reports to Senior Manager or above
EXPERIENCE & EDUCATION
University degree
Information security certification / accreditation an asset (e.g. CRISC, CISM, CISA, CISSP)
Familiarity with dimensions of Application Security, Infrastructure Vulnerability Management and Application Programming Interfaces (APIs)
Experience with risk partner engagement (including ORM, Audit, and Regulators)
Experience with testing of technology controls
Experience with development and management of Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs)
Excellent knowledge of cybersecurity industry control standards
Experience developing and managing issue remediation plans
Familiarity with various GRC platforms and alternative tracking methods (e.g. SharePoint, Confluence, JIRA)
Working knowledge of ServiceNow Security Operations modules a plus (e.g. Vulnerability Response, Configuration Compliance)
7+ years of relevant experience
À propos de nous :
La TD est un chef de file mondial dans le secteur des institutions financières. Elle représente la cinquième banque en Amérique du Nord de par son nombre de succursales. Chaque jour, nous offrons une expérience client légendaire à plus de 27 millions de ménages et d’entreprises au Canada, aux États-Unis et partout dans le monde. Plus de 95 000 collègues de la TD mettent en commun leurs compétences, leur talent et leur créativité au service de la Banque, des clients qu’elle sert et des économies qu’elle appuie. Nous sommes guidés par notre vision d’être une meilleure banque et par notre objectif d’enrichir la vie de nos clients, de nos collectivités et de nos collègues.
La TD est une entreprise profondément engagée à être une leader en matière d’expérience client. Voilà pourquoi nous croyons que chaque collègue, peu importe son secteur d’activité, est en contact avec la clientèle.
Notre programme de rémunération globale
Notre programme de rémunération globale reflète les investissements que nous faisons pour aider nos collègues et leur famille à atteindre leurs objectifs en matière de bien-être mental, physique et financier.
Renseignements supplémentaires :
Nous sommes ravis que vous envisagiez une carrière à la TD. Sachez que nous avons à cœur d’aider nos collègues à réussir dans leur vie tant personnelle que professionnelle.
Mesures d’adaptation
L’accessibilité est importante pour nous. N’hésitez pas à nous faire part de toute mesure d’adaptation (salles de réunion accessibles, sous-titres pour les entrevues virtuelles, etc.) dont vous pourriez avoir besoin pour participer sans entraves au processus d’entrevue.
Nous avons hâte d’avoir de vos nouvelles!
#J-18808-Ljbffr