Job Search and Career Advice Platform

Enable job alerts via email!

Customer Identity & Access Management (CIAM) Risk and Controls Manager

TD

Canada

On-site

CAD 108,000 - 164,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A major financial institution in Toronto is seeking a CIAM Risk and Controls Senior Manager. You will oversee the development and compliance of IAM standards, ensuring alignment with regulatory requirements. The ideal candidate has extensive IAM knowledge, strong leadership skills, and the ability to collaborate with various stakeholders effectively. This position offers competitive compensation and growth opportunities in a dynamic environment.

Benefits

Growth opportunities
Skill development programs

Qualifications

  • Extensive background in IAM principles and industry standards.
  • Solid understanding and experience in compliance enforcement of IAM standards.
  • Thorough understanding of the Three Lines of Defense.

Responsibilities

  • Own the CIAM Standard and associated Technical Specifications.
  • Support regulatory and internal audit remediation efforts.
  • Identify IAM control weaknesses in customer-facing processes.

Skills

Identity and Access Management (IAM) principles
Risk and control gap identification
Knowledge of CIAM tools
Compliance standards
Analytical skills

Education

Undergraduate degree in Information Security, Risk Management, or related discipline
Advanced degree (MBA, MS in Cybersecurity) preferred

Tools

IAM tooling and system architecture
GRC platforms
Job description

Work Location: Toronto, Ontario, Canada

Hours: 37.5

Line of Business: Enterprise Enabling Functions

Pay Details: $108,800 - $163,200 CAD

TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs. As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.

Job Description

Customer Identity and Access Management (CIAM), part of TD Global Technology & Solutions, is responsible for safeguarding the Bank and its customers from fraud, financial crimes, and other data protection risks.

Role Overview

We are seeking a seasoned, detail-oriented, and results-driven CIAM Risk and Controls Senior Manager to join our team to support risk governance, control oversight, and compliance initiatives in a highly regulated environment. Reporting to the AVP, CIAM Risk & Controls, this is a People Leadership role responsible for all aspects of development, maintenance, and compliance enforcement of the CIAM Standard and supporting Controls Library across the Bank. This is a highly-visible role and the successful candidate will play a key part in maturing our CIAM program and ensuring alignment with internal policy and external regulatory and industry standards.

Ideal Candidate
  • Extensive background in identity and access management (IAM) principles and direct exposure to relevant industry standards related to information and cybersecurity (e.g., NIST CSF, NIST 800.63, ISO 27001, CIS Controls).
  • Deep technical understanding of IAM tools and architecture supporting identity proofing and authentication functions.
  • Solid understanding and experience in compliance enforcement of IAM and/or other information/cybersecurity standards.
  • Comprehensive experience in risk and control gap identification and remediation, working collaboratively with technology and business stakeholders to ensure timely and effective resolution.
  • Thorough understanding and prior working experience in one or more of the Three Lines of Defense.
  • Working experience with operational risk management, internal audit, and regulatory exams and remediation efforts, including documentation and management of evidence artifacts, progress reporting, and support to executive leadership updates.
  • Identifying opportunities to improve program and team effectiveness and embracing innovation and automation where practicable.
  • Knowledge of CIAM tools and systems, and integration with governance, risk, and controls (GRC) tools is a requirement.
Key Responsibilities

CIAM Subject Matter Expertise (SME):

  • Owns the CIAM Standard, associated Technical Specifications, and Controls Library, including ongoing maintenance and enhancements throughout the Standards lifecycle, ensuring alignment with industry peer benchmarks, industry standards, and regulatory requirements.
  • Acts in a consultative advisory role to TD technology asset owners and lines of business, providing definitive guidance and support related to CIAM standards, risk governance, control design, and best practices.
  • Understand cross-segment end-to-end customer interaction and transaction process flows, ensuring alignment to CIAM Standards and raising risk awareness of identified control gaps.
  • Consult with internal stakeholders (e.g., Risk Management, other control functions, Business Segments, etc.) and external experts and counterparts (e.g., industry and professional associations, peer banks, etc.) on the implications of risks related to customer identity and authentication in current and emerging technology and banking trends.
  • Stay current with applicable regulatory expectations and emerging IAM trends.

Risk Governance & Oversight:

  • Support CIAM Product and Technology teams risk assessments, including but not limited to, reviewing Change Risk Assessment (CRA), Privacy Impact Assessment (PIA), etc.
  • Support regulatory and internal audit remediation efforts from a CIAM Standards compliance perspective.
  • Review and deliver updates to governance committees (e.g., Identity Assurance Management Committee).

Control Monitoring & Reporting:

  • Support CIAM Standards compliance monitoring and upscale gaps or deficiencies.
  • Identify IAM control weaknesses in customer-facing processes and assets and work collaboratively with risk partners and technical and business stakeholders to drive remediation.
  • Drive continuous improvement in CIAM Standard, control effectiveness, operational efficiency, and internal stakeholder and customer experience.

Relationship Management:

  • Lead a team of dedicated CIAM professionals with expertise in compliance and risk controls.
  • Work closely with Cyber and Application Security teams for visibility into current and emerging IAM risks and engage CIAM Product and Engineering teams to adjust CIAM roadmap and Standards as necessary.
  • Collaborate with Workforce IAM counterparts to ensure alignment and identify efficiency opportunities.
  • Work closely with CIAM Product and Engineering, line of business, and supporting Technology leaders to ensure alignment between CIAM capability roadmap, provide guidance regarding CIAM Standards compliance, and identify where planned new technologies and customer platforms may require enhancements to the CIAM Standard.
  • Partner with Risk Marketplace (1B), second-line functions (AML, Compliance, Legal), and third-line audit teams.
Desired Qualifications
  • Undergraduate degree in Information Security, Risk Management, Computer Science, or related discipline is an asset.
  • Advanced degree (MBA, MS in Cybersecurity) preferred.
  • 7-10+ years in a technical capacity in Identity & Access Management (IAM), Risk Management, or Cybersecurity.
  • Compliance experience is a definite asset.
  • Financial services experience is an asset.
  • Proven experience in control standards, control design, and regulatory remediation.
  • Familiarity with IAM tools and GRC platforms.
Professional Certifications
  • Certified Identity and Access Manager (CIAM) or equivalent IAM certifications
  • Certified Information Systems Auditor (CISA)
  • CISM (Certified Information Security Manager)
  • CISSP (Certified Information Systems Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)
  • ITIL Foundation for process governance
Technical Acumen
  • Advanced knowledge of IAM tooling and system architecture for identity proofing, authentication, fraud prevention, and data protection.
  • Proficiency in risk frameworks (NIST, ISO, CIS) and regulatory compliance standards.
  • Hands‑on experience with CIAM platforms and integration with GRC tools.
  • Strong understanding of change management, and testing methodologies.
Soft Skills & Character Traits
  • Bias for Action: Make informed risk-based decisions quickly; take action to deliver on business objectives swiftly over endless deliberation and inaction.
  • Adaptability: Able to work effectively in an often high‑stress environment on high‑profile time‑bound initiatives.
  • Analytical and detail orientated: Stay connected to details, audit frequently, and are skeptical when data differs.
  • Strategic Thinker: Able to align CIAM initiatives with TD business objectives and regulatory requirements.
  • Effective Communicator: Excellent oral and written communication skills with ability to concisely and effectively translate complex technical risks into business impact messaging that resonates with executive audiences.
  • Relationship‑focused: Ability to build strong relationships across business and technology teams.
  • Integrity & Accountability: Uphold the highest standards of ethics and compliance; have conviction and do not compromise for the sake of team cohesion.
  • Leadership: Seeks and accepts responsibility.
  • Curiosity & Fearlessness: Willing to accept new challenges outside your comfort zone and are unafraid to fail fast and learn.
Why Join Us?

If you are passionate about ensuring TD customers can securely bank with us and making a tangible impact in a highly regulated banking environment, this role offers an opportunity to be a part of initiatives that shape the future of secure digital banking.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.