10 Oct
|
JobDiva
|
Ontario
Info Sec specialist- CISA,GRC
Location: Toronto, ON
Onsite Flexibility: Hybrid – currently 2 days but will be going in 4 days eventually
Contract Details
Position Type: Contract
Contract Duration: 6 months (with potential for extension)
Pay Rate: C$86.00–C$103.00 / Hour (CAD)
Shift / Schedule: Monday – Friday, 9:00 AM – 5:00 PM
Travel Requirements: Not required
Job Summary
TD Global Security & Defense is home to a team of highly valued professionals who support all Global Technology Solutions related regulatory and support interactions, which includes business, 2nd, or 3rd LOD led exams. They provide oversight and governance, independently challenging High / Med severity issues tied to Regulatory, Audit and ORM — including issue escalations tied to potential overdue and validation failures, issue support for insight, governance reporting and exams. The team also provides demand management support and assurance functions.
We are looking for someone who is well-versed at providing governance, risk, compliance, and issue remediation oversight and control best practices that meet TD's overarching Global Technology Solutions strategy and objectives. The individual will be responsible for partnering with Technology segments to support independent challenge and oversight of issue remediation plans impacting the information security control workplace.
Key Responsibilities
Lead assessments of audit and regulatory finding remediations required to mitigate risk within technology infrastructure and applications, working with stakeholders across the three lines of defense to ensure effective risk mitigation and remediation
Provide advice and guidance to Technology segments and Technology Risk Services on various areas requiring subject matter expertise and interpretation: Audit & Assurance Standards; IT Risk Governance Control Frameworks, and GRC (Governance, Risk, and Compliance) frameworks
Contribute to the development of mature Governance Oversight & Control practices, through improvement of Risk Identification, Control Design and Operating Effectiveness
Identify emerging themes, understand trends, and provide specialized business management advice to senior management and respective teams while raising industry, external and internal, enterprise and business awareness
Lead continuous improvement projects, leveraging agile / lean continuous improvement practices/methods that demonstrate sustainable and leading edge solutions (e.g., Artificial Intelligence (AI),
Machine Learning (ML), Power BI/Apps, Python, etc.)
Strengthen the independent assurance, governance and oversight operations, utilizing lean continuous improvement practices and tools
Apply core Agile frameworks (e.g., Scrum, Kanban) to execute operational workplan projects
Collaborate with data scientists, engineers, information security specialists, and business stakeholders to align AI initiatives with strategic objectives
Train colleagues and team members related to risk and compliance of issue remediations
Stay current with the latest research and trends in AI/ML and recommend relevant tools, frameworks and methodologies
Required Skills
Expert knowledge of IT Audit and Control methodology, IT Governance Controls and Standards, and associated tools to ascertain the quality and effectiveness of technology remediation plans
Competencies in technology controls, emerging threats, and technology risk disciplines and practices
Quality assurance as it relates to remediation plans – 10 years of experience
IT governance experience in information security and controls risk frameworks (i.e., ITIL, NIST, COBIT) – 10 years of experience
Experience with assessing and evaluation of audit and regulatory remediation – 10 years
Knowledge and experience with various lifecycle methodologies / frameworks, i.e., Agile, Project Management, IT Processes, Risk Management frameworks and process / operations
Knowledge and experience with various technology tools including, but not limited to, RSA Archer, JIRA, Confluence, SharePoint, MS Office, Excel, and ServiceNow
IOR methodology or comparable audit validation approaches
Strong auditor mindset
Experience developing sample-based test plans – 10 years
Governance frameworks experience
Excellent verbal and written business communication skills; meticulous documentation
Ability to manage multiple efforts simultaneously, prioritize demands, and strong organizational skills
Ability to effectively interact with individuals across the organization and at various levels (technical, business, Senior & Executive Management)
Attention to detail
Team player – collaborate well with other team members
Information Security or technology risk and controls background (financial industry experience a plus)
Preferred Skills
CISSP certification or equivalent experience a plus
Education Requirements
University degree in a relevant field or equivalent experience
CISA certification required
CRISC certification or equivalent experience
CISSP certification or equivalent experience (a plus)
Required Experience
10 years as an IT Risk Specialist with relevant experience in governance, risk, and compliance management within regulated industries
10 years of IT Audit – IT Governance Controls and Standards experience
10 years of quality assurance experience as it relates to remediation plans
10 years of IT governance experience in information security and controls risk frameworks
10 years of experience with assessing and evaluating audit and regulatory remediation
10 years of experience developing sample-based test plans
Medical, Vision, and Dental Insurance Plans
401k Retirement Fund
Important Notes
Interview process: 1 panel interview (technical and behavioral) – virtual
The contractor will have access to customer data
About the Client
This client is a leading financial services and banking institution operating across North America and globally, recognized for the breadth and scale of its technology, risk management, and regulatory compliance functions. The organization employs tens of thousands of professionals — including information security specialists, IT governance analysts, technology risk advisors, data scientists, engineers, and business stakeholders — who collaborate across agile, fast-paced teams to deliver enterprise-wide solutions. With a strong emphasis on Global Technology Solutions and a multi-line-of-defense governance model, this institution offers contractors meaningful exposure to large-scale regulatory, audit, and compliance programs.
About GTT
GTT is a minority-owned staffing firm and a subsidiary of Chenega Corporation, a Native American-owned company in Alaska. We highly value diverse and inclusive workplaces and support Fortune 500 organizations across banking, financial services, technology, life sciences, biotech, utilities, and retail sectors throughout the U.S. and Canada.
Job Number: 26-10988
#gttca #LI-GTT #LI-Hybrid
#J-18808-Ljbffr
📌 Info Sec specialist- CISA,GRC (Ontario)
🏢 JobDiva
📍 Ontario