Job Search and Career Advice Platform

Enable job alerts via email!

Cyber Assurance Operations Manager

TD Bank Group

Canada

On-site

CAD 91,000 - 137,000

Full time

17 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial institution in Canada seeks a dedicated professional to manage security operations and provide strategic consultation on technology controls and risk management. Candidates should have over 7 years of relevant experience and a university degree. The position offers a competitive salary range and location in Toronto, Ontario.

Qualifications

  • 7+ years of relevant experience related to technology controls or information security.
  • University degree required, information security certification is an asset.

Responsibilities

  • Management of direct reports and oversight of engagement processes.
  • Conduct assessments and provide consultation on security risks.
  • Ensure compliance with internal policies and regulatory guidelines.
  • Contribute to the development of a security management framework.

Skills

Management of a small team
Knowledge of cyber assurance operations
Data management
Risk assessment
Consultation and advice provision
Influencing risk culture
Emerging technology monitoring

Education

University degree
Information security certification
Job description
Work Location

Toronto, Ontario, Canada

Hours

37.5

Pay Details

$91,200 - $136,800 CAD

KEY ACCOUNTABILITIES
  • Management of a small number of direct reports.
  • Knowledge or previous exposure to cyber assurance operations such as Penetration Testing or Red Teaming is an asset.
  • Data management including tracking of engagements, findings, and documentation of best practices.
  • Reporting and analytics including both ad-hoc requests and the definition of KRI/KPIs to align with the broader EVM strategy.
  • Vendor and contract management including renewals and new vendor onboarding.
  • Process design and oversight to ensure that required artifacts are identified and memorialized in a system of record.
  • Administration related to engagement oversight such as the submission of artifacts, management of oversight processes, and storage of approvals required.
  • Management of deliverables from regulatory, audit, second line, and self-identified findings.
  • General budget / financial management including the team's education budget.
  • Management of the team's development environment.
CUSTOMER
  • Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area.
  • Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas.
  • Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable.
  • Contribute to the definition, development, and oversight of a global security management strategy and framework.
  • Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business.
  • Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area.
  • Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
  • Consult on Regulatory compliance requirements, reporting and questions.
  • Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities.
  • Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team.
SHAREHOLDER
  • Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines.
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement.
  • Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities.
  • Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
  • Remain informed of emerging issues, industry trends and/or relevant changes.
  • Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness.
  • Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements.
  • Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank.
  • Assess / identify key issues and elevate to appropriate levels and relevant stakeholders where required.
  • Maintain a culture of risk management and control, supported by effective processes and sound infrastructure an in alignment with risk appetite.
  • Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to identify risk / provide guidance.
  • May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level.
EMPLOYEE / TEAM
  • Continuously enhance knowledge / expertise in own area.
  • Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques.
  • Prioritize and manage own workload to deliver quality results and meet assigned timelines.
  • Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest.
  • Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency.
  • Establish effective relationships across multiple business and technology partners, program and project managers.
  • Participate in knowledge transfer within the team and business units.
BREADTH & DEPTH
  • Expert knowledge of IT security and risk disciplines and practices.
  • Advanced knowledge of organization, technology controls / security/ risk issues.
  • May participate on complex, comprehensive or large projects and initiatives.
  • Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors.
  • Generally reports to Senior Manager or above.
EXPERIENCE & EDUCATION
  • University degree.
  • Information security certification / accreditation an asset.
  • 7+ years of relevant experience.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.