Job Description
About the role: We are looking for someone to lead and execute third party cyber risk assessments of TD's global suppliers.
The assessor will provide specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect TD.
The assessor may also participate in department initiatives of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level.
·Coordinate with key risk stakeholders to initiate, scope and plan third party cyber risk assessments of recent and existing suppliers of all risk levels.
·Lead or contribute to the completion of third-party cyber risk assessments at the business application, portfolio, or overall enterprise level.
· Communicate the cyber risk assessment results to internal and external stakeholders.
·Coordinate with risk stakeholders to identify appropriate risk mitigation and remediation plans.
Perform validation of the risk mitigation and remediation plans upon implementation.
·Complete assessments in accordance with internal procedures and standards, industry frameworks and best practices.
·Adhere to internal policies and procedures, technology control standards, and applicable regulatory guidelines.
·Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement.
·Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
Skills and Requirements
1.) 10+ years of third party cyber risk assessment/assessor experience
2.)
Expert knowledge of IT security risk disciplines and practices
3.) Demonstrated ability to participate in complex, comprehensive or large projects and initiatives
4.) Ability to serve as a lead expert resource in technology controls and information security with the business organization and 3rd party's
Soft Skills
1.) Strong communication – verbal and written (ability to communicate with key stakeholders and non-technical/technical audiences)
2.) Strong collaboration skills with internal and external partners
3.) Strong Assessment/coordination skills
1.) CISSP certification (Information Security Certification / Accreditation is an asset) Information Security Certification / Accreditation is an asset
2.) Prior banking or financial institution experience
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day.
We are an equal employment opportunity/affirmative action employer that believes everyone matters.
Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.
If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to
[email protected].
📌 Information Security Analyst (Toronto)
🏢 Insight Global
📍 Toronto