24 Sep
|
TD Bank Group
|
Toronto
24 Sep
TD Bank Group
Toronto
Page for more information.**Work Location:**Toronto, Ontario, Canada**Hours:**37.5**Line of Business:**Governance & Control**Pay Details:**$115,600 - $163,200 CADTD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.**Job Description:**The BISO will collaborate with Business, Risk, Privacy, and Technology teams to assess and analyze cybersecurity risks. The individual will provide security recommendations based on identified threats and risks, while considering compliance and regulatory requirements relevant to the Business Unit. Additionally, the individual will document and track identified risks and recommendations and obtain necessary risk and security approvals where required.The ideal candidate will demonstrate strong knowledge of modern application lifecycle practices, security architecture, cloud platforms, Generative AI tools, frontier models, API security, and application security standards such as OWASP, along with familiarity with frameworks such as ITIL, ISO, COBIT.What you will do:* Serve as the primary information security liaison between the Business Unit and the IT.* Translate Firm security policies, procedures, and standards into practical, risk-based controls for the Business Unit technology ecosystem* Proactively unblock and manage security, risk, and compliance issues by bringing together Advisory, Audit, ITS, Risk,
Security stakeholders, driving decisions, tracking actions, and ensuring issues are worked through to a clear and timely end state* Monitor compliance with security policies, standards, and control requirements; identify non-compliance, initiate remediation actions, and track exceptions through formal risk acceptance processes with appropriate compensating controls* Act as the BU key point of contact to understand security risks related to evolving business requirements for technology and solutions, and apply security-by-design principles to provide proactive, business-focused, guidance aligned with Firm's security policies and standards* In coordination with 1B team, assess and review business-requested software, tools, and AI capabilities (including SaaS and Generative AI solutions) for security, privacy, and compliance risks; lead intake, risk evaluation, and provide delegated approval or whitelisting where necessary* Collaborate with Project, Technology, Business, and Risk teams to gather requirements and support the Security Assessment Review (SAR) process, led by Platform Security* Develop and maintain a business unit Risk Register to track security risks* Coordinate with stakeholders to ensure security requirements are documented and tracked throughout the project lifecycleGovernance* Maintain a strong understanding of Risk and Security policies* Maintain and validate a comprehensive inventory of business applications, tools, and technology assets (on-premises and cloud),
ensuring alignment with Firm security standards* Coordinate implementation and onboarding of current security programs and capabilities* Contribute to annual business planning processes and recommend initiatives to enhance security posture and operational efficiency* Represent the business unit and provide key metrics in monthly security governance forumsMonitoring* Monitor adherence to 1B security policies and standards* Review compliance reports generated by security tools and address identified issues* Maintain an accurate and up-to-date inventory of business applications (on-premises and cloud environments including Azure, AWS, and GCP)* Monitor control effectiveness across all technology assets within the business unit, understand how to 'test' controlsWhat you bring to this role:* Bachelor's or Master's degree in Information Technology, Computer Science, Cyber Security or a related field, or equivalent experience·* 10+ years of experience in application, technology, or solution design, architecture, development, and implementation* 10+ years of experience in secure design/architecture and project risk assessments across modern cloud and on-premises environments, including SaaS solutions* 5+ years of experience as a security practitioner in a leadership role* Deep understanding of modern application development ecosystems, open systems, Generative AI, and emerging technologies* Strong knowledge of information security standards and frameworks (e.G., CSA, ITIL, CCM, ISO 27001/27017/27018/42001, PCI DSS, NIST CSF, NIST 800-53) and data protection principles* Experience working with modern AI tools and capabilities* Proven experience in a consulting or advisory role, collaborating with Technology, Project, and Business stakeholders* Holding any of the following certifications would be considered an asset but not required: CISSP, CISA, CRISC, CISM, CGEIT**Who We Are:**TD is one of the world's leading global financial institutions and is the fifth largest
📌 Senior Manager, Governance & Control (Toronto)
🏢 TD Bank Group
📍 Toronto