Enable job alerts via email!

Senior Security Advisor

TMX Group

Mississauga

On-site

CAD 80,000 - 120,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Senior Security Advisor to enhance their cybersecurity governance and risk management. This role is pivotal in developing and implementing security policies, conducting risk assessments, and fostering a strong security culture across various business units. You will collaborate with technology teams to ensure compliance with industry standards and regulations while promoting resilience against cyber threats. If you have a passion for cybersecurity and a desire to make a significant impact, this position offers a unique opportunity to contribute to a dynamic and forward-thinking organization.

Qualifications

  • 5+ years of experience in information security, especially in financial markets.
  • Proficiency in conducting threat and risk assessments for financial systems.

Responsibilities

  • Support development of TMX Cybersecurity Policy Framework and risk assessments.
  • Contribute to cybersecurity awareness training and incident response planning.

Skills

Information Security
Cybersecurity Risk Assessments
Communication Skills
Analytical Skills
Problem-Solving Skills
Collaboration Skills
Knowledge of Python

Education

University undergraduate degree in Computer Science
Degree in Engineering or related field

Tools

NIST Cybersecurity Framework
ISO 27001
CISSP
CISA
CISM

Job description

Venture outside the ordinary - TMX Careers

The TMX group of companies includes leading global exchanges such as the Toronto Stock Exchange, Montreal Exchange, and numerous innovative organizations enhancing capital markets. United as a global team, we’re connecting cross-functionally, traversing industries and geographies, moving opportunity into action, advancing global economic growth, and propelling progress.

Ready to be part of the action?

Reporting to the Senior Manager - Governance Risk Compliance (GRC) department, the senior security advisor will contribute to the development, maturing, implementation and operation of the TMX information security program and cybersecurity governance structure. This role will provide support in assessing and managing cybersecurity risks, ensuring alignment with TMX Group security policies and industry best practices.

The Advisor will work collaboratively with various business units and technology teams to promote a strong security culture and enhance the overall security posture and resilience of TMX Group.

Key Accountabilities:

  1. Cybersecurity Policy Framework: Support the development and maintenance of the TMX Cybersecurity Policy Framework, considering specific security profiles and risk tolerances of various business units, systems, and cloud environments.
  2. Cybersecurity Risk Assessments: Conduct Threat and Risk Assessments (TRAs) on various business units and initiatives, focusing on financial systems and their associated threats. These assessments must reflect the specific threats and vulnerabilities faced by each business unit, while considering both their individual risk appetite and the enterprise risk appetite of TMX Group as a whole. Provide input to risk mitigation strategies and remediation plans.
  3. Security Standards and Guidelines: Assist in the development and implementation of security standards, guidelines, and best practices, ensuring alignment with industry standards such as NIST and ISO 27000 series.
  4. Security Awareness and Training: Contribute to the development and delivery of cybersecurity awareness training programs for personnel and teams across TMX Group, tailored to different roles and responsibilities.
  5. Cybersecurity Reporting: Assist in the development of security metrics: KRIs and KPIs. Contribute to reports related to the status of cybersecurity within TMX and the execution of risk remediation plans.
  6. Data Privacy and Protection: Support the implementation and maintenance of data privacy and protection policies and procedures, ensuring compliance with relevant regulations like PIPEDA (Canada), GDPR (EU), and CCPA (California).
  7. Third-Party Risk Management: Contribute to the development, maturing, and implementation of a third-party risk management program, assessing and managing risks associated with all third-party relationships, including vendor security assessments.
  8. Security Incident Response Planning: Participate in security incident response planning and contribute to the development and maintenance of incident response procedures.
  9. Cybersecurity Resilience: Work with business units to integrate cybersecurity considerations into their business resilience plans. Help guide them in establishing and operating adequate plans to ensure business continuity in the face of cyber threats.
  10. Cybersecurity Exercises and Testing: Contribute to the development and execution of cybersecurity Table Top Exercises for business units to enhance their preparedness for cyber incidents.
  11. Regulatory Compliance: Support compliance with relevant regulatory frameworks, such as PCI DSS, SOX, OSFI (Canada), or GLBA, by monitoring regulatory changes, conducting compliance assessments, and developing remediation plans.
  12. Business Continuity and Disaster Recovery: Ensure cybersecurity considerations are integrated into business continuity and disaster recovery planning efforts.
  13. Collaboration and Communication: Work closely with ITSS Architecture, Security Operations teams, Enterprise Risk Management, and other key stakeholders.
  14. Research and Innovation: Stay abreast of emerging cybersecurity threats, trends, and technologies, including those related to cloud environments, AI, and GenAI frameworks.
  15. Vendor Security Assessments: Support the assessment of vendor products and services from a security perspective, providing recommendations related to purchase and merger & acquisition activities.

Must Haves:

  1. University undergraduate degree in Computer Science, Engineering or a related field.
  2. 5+ years of experience in information security or a related field, with experience in financial market infrastructure strongly preferred.
  3. Proficiency in conducting threat and risk assessments, particularly within the context of financial systems.
  4. Experience in developing, implementing, and operating information security programs and practices.
  5. Strong understanding of cybersecurity frameworks and standards such as NIST, ISO 27001, and CISSP.
  6. Knowledge of capital markets and cloud environments, including their security considerations.
  7. Familiarity with AI and GenAI frameworks and their associated security risks.
  8. Excellent communication, collaboration, and interpersonal skills, with the ability to interact effectively with both technical and non-technical audiences.
  9. Strong analytical and problem-solving skills.
  10. Knowledge of Python and process automation is considered a plus.
  11. CISSP, CISA, CISM, or similar certifications are considered assets.

Ready to enrich your career with impactful work, leaders who truly care, and the flexibility and programs to help you thrive as part of #TeamTMX? Apply now.

TMX is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide accommodations for applicants and employees who require it.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Network Security Consultant

Telescope Recruitment

Quebec

Remote

CAD 100,000 - 130,000

4 days ago
Be an early applicant

Senior Security Consultant, Digital Forensics & Incident Response

eSentire, Inc.

Remote

CAD 80,000 - 130,000

4 days ago
Be an early applicant

Senior Security Consultant, Digital Forensics & Incident Response

eSentire, Inc.

Remote

CAD 80,000 - 120,000

4 days ago
Be an early applicant

Senior IT Security Advisor (Application Security)

goeasy Ltd.

Mississauga

Hybrid

CAD 80,000 - 120,000

5 days ago
Be an early applicant

Senior IT Security Advisor (Application Security)

goeasy Ltd

Mississauga

Hybrid

CAD 80,000 - 120,000

6 days ago
Be an early applicant

Consultant or Senior Consultant, Offensive Security

BDO Canada

Oakville

Remote

CAD 70,000 - 110,000

5 days ago
Be an early applicant

Senior Information Security Advisor

Tangerine Bank

Toronto

Hybrid

CAD 80,000 - 120,000

Yesterday
Be an early applicant

Senior Security Advisor - IAM

Intact

Mississauga

Hybrid

CAD 80,000 - 110,000

12 days ago

Senior Security Advisor - IAM

Intact

Toronto

Hybrid

CAD 80,000 - 120,000

13 days ago