Job Search and Career Advice Platform

Enable job alerts via email!

Senior Information Security Specialist, AI (B3617)

TD

Canada

On-site

CAD 108,000 - 164,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services company in Canada is seeking a Business Information Security Officer (BISO) for AI to provide technology risk guidance and consultation, ensuring effective risk management within business objectives. The ideal candidate has over 10 years of experience, a university degree, and expertise in AI security. Responsibilities include conducting risk assessments, developing security strategies, and leading governance initiatives. This role offers competitive compensation and opportunities for professional growth.

Qualifications

  • 10+ years of relevant experience in information security and risk management.
  • Autonomous work on high-profile, complex technology projects.

Responsibilities

  • Provide technology risk advice and consultation to business partners.
  • Conduct risk assessments on business applications, third parties, and infrastructure.
  • Lead development and implementation of information security strategies and policies.
  • Guide ongoing technology risk reporting and monitor key trends.

Skills

Knowledge of secure AI development lifecycle
Expertise integrating AI security controls
Ability to communicate complex AI risk concepts
Experience with incident response for AI threats
Commitment to continuous learning in AI

Education

University degree
Information security certification or accreditation
Job description

Work Location: Toronto, Ontario, Canada

Hours: 37.5

Line of Business: Technology Solutions

Pay Details: 108,800 - 163,200 CAD

Overview

The Business Information Security Officer (BISO) for AI provides technology risk advice and consultation to business partners, enabling effective risk management within their risk appetite and supporting business objectives. This role facilitates communication and execution of enterprise-wide information security programs, delivers awareness training, and conducts risk assessments on business applications, third parties, and infrastructure. The BISO validates that security and technology controls are implemented to support business requirements and oversees control and governance activities, identifying and assessing potential security risks and exposures that impact complex or high-risk businesses and strategic initiatives.

Key Responsibilities
  • Provide technology risk advice and consultation to business partners.
  • Enable businesses to effectively manage risk within their risk appetite and meet objectives.
  • Facilitate communication and execution of enterprise-wide information security programs.
  • Develop enterprise awareness training for AI.
  • Conduct risk assessments on business applications, third parties, and infrastructure.
  • Validate that security and technology controls are implemented to support business requirements.
  • Lead development and implementation of technology controls and information security strategies, policies, and programs.
  • Oversee control and governance activities, identifying and assessing potential security risks, breaches, and exposures.
  • Provide technical leadership and expert consultation on technology controls, information security programs, policies, standards, and incidents.
  • Lead project consulting on risk assessment, definition of required controls, vulnerability assessments, and control procedures.
  • Conduct comprehensive risk and control design assessments for application portfolios.
  • Document and articulate the impact of control gaps, develop risk mitigation and remediation plans, and provide information security solutions.
  • Define, develop, and oversee a global security management strategy and framework.
  • Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to security threats.
  • Guide and lead ongoing technology risk reporting, monitor key trends, and define metrics to measure control effectiveness.
  • Act as a primary technical expert, working with technology partners and service/platform owners to integrate security components into enterprise architecture.
  • Consult on regulatory compliance requirements, reporting, and questions.
  • Adhere to internal policies, procedures, technology control standards, and regulatory guidelines.
  • Proactively review internal processes and identify opportunities for improvement.
  • Advise on, oversee, monitor, and enforce enterprise frameworks and methodologies related to technology controls and information security.
  • Influence behavior to reduce risk and foster a strong technology risk management culture.
  • Remain informed of emerging issues, industry trends, and relevant changes.
  • Define, develop, implement, and manage standards, policies, procedures, and solutions that mitigate risk and maximize security, service availability, efficiency, and effectiveness.
  • Manage relationships with other technology areas, businesses, and control functions to ensure alignment with enterprise and regulatory requirements.
  • Maintain a culture of risk management and control, supported by effective processes and sound infrastructure.
  • Ensure business operations comply with internal and external requirements (e.g., financial controls, segregation of duties, transaction approvals, physical control of assets).
  • Participate in cross-functional and enterprise initiatives as a subject matter expert.
  • Lead governance meetings or committees and related deliverables/outcomes.
  • Lead, facilitate, and implement action or remediation plans to address performance, risk, and governance issues.
  • Develop, provide, or contribute to complex reporting, analysis, and assessments at the functional or enterprise level.
  • Assess and identify key issues, escalating to appropriate stakeholders as needed.
AI-Specific Skills & Industry Best Practices
  • Knowledge of secure AI development lifecycle and best practices for model validation and monitoring.
  • Expertise integrating AI security controls into enterprise architecture and technology platforms.
  • Awareness of emerging AI threats, adversarial attacks, and evolving regulatory requirements.
  • Ability to communicate complex AI risk concepts to executive stakeholders and non-technical audiences.
  • Experience with incident response and remediation for AI-related security events.
  • Commitment to continuous learning and staying current with industry trends, frameworks, and best practices in AI and financial services.
Leadership and Collaboration

The BISO acts as a top technical expert and individual contributor with advanced knowledge of IT security and risk disciplines. This role works autonomously on high-profile, complex, and high-risk technology projects, providing technical leadership, consulting, and foresight on emerging industry trends. The BISO supports a positive work environment, promotes service quality, innovation, and teamwork, and identifies opportunities to enhance productivity and operational efficiency.

Experience and Education
  • University degree required.
  • Information security certification or accreditation is an asset.
  • 10+ years of relevant experience.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.