Information Security Specialist (Security Posture Insights, Reporting And Remediation) (Toronto)

Information Security Specialist (Security Posture Insights, Reporting And Remediation) (Toronto)

06 Sep
|
TD Bank Group
|
Toronto

06 Sep

TD Bank Group

Toronto

Work Location: Toronto, Ontario, Canada Hours: 37.5 Line of Business: Technology Solutions Pay Details: $96,900 - $136,800 CAD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs. As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role. Job Description The Information Security Specialist – Security Posture Insights, Reporting and Remediation is responsible for turning infrastructure configuration and cyber technology compliance data into trusted insights, decision-ready reporting and measurable remediation outcomes. The role identifies material control gaps, assesses trends and root causes, prioritizes issues based on risk and business impact, and works with accountable technology owners to drive remediation within established timelines. As a key business and product partner for the ServiceNow Configuration Compliance Management module, the specialist defines reporting and workflow requirements, uses the platform to manage findings through closure, and develops dashboards, metrics and executive insights that improve accountability and risk decisions. The role also advances AI-enabled security insights and risk management by improving data quality, automating analysis and reporting, and enabling responsible use of predictive signals and remediation recommendations. The role reports to the Senior Manager, Security Compliance and Operations Management and works across infrastructure security governance, security engineering, technology operations, ServiceNow delivery, asset management, risk and audit teams. Role and Responsibilities Analyze infrastructure configuration, asset, security tool and control data to identify material compliance gaps, recurring trends, emerging risks and systemic root causes across server, workstation, network, database, middleware, cloud and container environments. Produce accurate, timely and decision-ready operational and executive reporting on security posture, including compliance performance, control coverage, configuration drift, issue aging, remediation progress, threshold breaches, exceptions and residual risk. Develop and maintain dashboards, scorecards, KRIs, KPIs and management insights that clearly communicate what is non-compliant, why it matters, who is accountable, the required action and when remediation is due. Use ServiceNow Configuration Compliance Management as the system of record for findings, ownership, remediation tasks, service-level commitments, exceptions, evidence, validation, escalation and closure. Define and prioritize ServiceNow Configuration Compliance requirements for data ingestion,



findings normalization, assignment logic, remediation workflows, notifications, escalations, dashboards, metrics and executive reporting. Develop actionable insights from ServiceNow Configuration Compliance, CMDB, Splunk and security assessment tools by correlating compliance gaps with asset criticality, exposure, business context, control criticality and remediation history. Establish risk-based prioritization and reporting models that direct remediation capacity to the gaps with the greatest potential business and security impact. Work directly with accountable technology and remediation owners to establish corrective action plans, clarify deliverables and due dates, resolve blockers, monitor progress, validate remediation evidence and confirm sustainable closure. Lead governance routines for outstanding gaps, including remediation reviews, aging analysis, challenge of recovery plans, dependency management and escalation of overdue or material issues to accountable leaders and risk partners. Identify systemic or recurring gaps and recommend broader corrective actions, including process improvements, engineering fixes, configuration baselines, automation, ownership changes and preventative controls. Validate reporting completeness and accuracy by reconciling authoritative asset inventories, source-tool results, ServiceNow records and remediation evidence; investigate data quality or control coverage gaps that could affect management decisions. Partner with ServiceNow platform, data and engineering teams to improve Configuration Compliance integrations, analytics, workflow performance and reporting usability. Drive the roadmap toward AI-enabled security insights and risk management, including anomaly detection, trend forecasting, root-cause analysis, predictive risk indicators, automated executive summaries and risk-based remediation recommendations. Define data quality, validation, explainability, human oversight, access and governance requirements so AI-assisted insights and recommendations are trusted, traceable and appropriate for risk decisions. Develop automation requirements that reduce manual analysis, improve reporting timeliness, accelerate issue assignment and escalation, and increase remediation velocity. Maintain clear data definitions, reporting standards, control mappings, remediation procedures, RACIs, evidence requirements and decision records that support consistent operations and an auditable trail. Provide concise, traceable evidence and reporting for senior management, second-line risk, audit and regulatory requests, clearly distinguishing current posture, open gaps, remediation commitments and residual risk. Maintain a prioritized backlog and roadmap for insight generation, reporting modernization,



ServiceNow Configuration Compliance improvements, remediation enablement and AI-assisted analytics. Qualifications University or post-graduate degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, Data Analytics or a related discipline is an asset. Seven or more years of experience in cybersecurity, technology compliance, security posture management, infrastructure security, risk reporting, remediation management or security operations. Demonstrated ability to transform complex security and technology data into actionable insights, concise executive reporting and clearly prioritized remediation actions. Advanced analytical skills, including data correlation, trend and aging analysis, root-cause identification, risk prioritization, data reconciliation and interpretation of KRIs, KPIs and control effectiveness measures. Hands-on experience developing dashboards, scorecards and operational or executive reports that communicate material gaps, ownership, due dates, progress, dependencies and residual risk. Experience driving remediation with technology owners, including corrective action planning, milestone tracking, blocker resolution, evidence validation, challenge, escalation and closure. Experience with ServiceNow Security Operations capabilities; experience using or defining requirements for the ServiceNow Configuration Compliance Management module, CMDB, findings workflows, remediation tasks, dashboards and integrations is strongly preferred. Experience using security assessment and posture data from tools such as Qualys, CrowdStrike, Wiz, Azure Policy, Tenable, AppOmni, Splunk or comparable platforms. Strong understanding of configuration compliance, control completeness and correctness, asset inventory, configuration drift, exception management, service-level commitments and risk-based remediation. Ability to assess reporting accuracy and data quality across multiple sources and explain the limitations, assumptions and risks that could affect management decisions. Working knowledge of AI and machine-learning use cases for security analytics, including anomaly detection, summarization, recommendations and predictive risk signals, with an understanding of explainability, validation, governance and human oversight. Ability to communicate complex technical and risk information in concise business language for technology owners, senior leaders, risk partners, auditors and regulators. Experience coordinating cross-functional delivery across security governance, security engineering, technology operations, asset management, data, platform teams and first- and second-line risk functions. Solid organizational, prioritization and influencing skills, with the ability to establish accountability, manage competing remediation priorities and deliver outcomes with limited supervision. Experience working within Agile delivery frameworks and using tools such as Jira is an asset. Certifications GIAC (GCIA, GPEN, GWAPT, GCIH, GSEC and etc) CCNP CCNA CISSP CCSP CISM CISA Who We Are TD is one of the world's leading global financial institutions and is the fifth largest

📌 Information Security Specialist (Security Posture Insights, Reporting And Remediation) (Toronto)
🏢 TD Bank Group
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security specialist (security posture insights, reporting and remediation) (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: information security specialist (security posture insights, reporting and remediation) (toronto) / toronto