Enable job alerts via email!

Senior Lead, Security Advisory Transformation

Scotiabank

Toronto

Hybrid

CAD 90,000 - 150,000

Full time

6 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Senior Lead in Security Advisory Transformation to drive security practices across business lines. This role involves developing strategic plans for security risk management, enhancing compliance, and providing technical expertise on threat assessments. You will work closely with various teams to ensure the implementation of sound security controls and contribute to a culture of continuous improvement. Join a dynamic team that values diversity and offers opportunities for professional growth, all while making a significant impact in safeguarding the bank's information and data resources.

Benefits

Flexible vacation
Tuition assistance
Community engagement programs
Diversity and inclusion initiatives

Qualifications

  • 5+ years of experience in threat risk assessments on complex applications.
  • Strong knowledge of cloud security governance frameworks.
  • Experience in providing security advisory services.

Responsibilities

  • Provide guidance on security practices for technology solutions.
  • Conduct comprehensive security assessments as needed.
  • Mentor teams on transformed threat risk assessment processes.

Skills

Threat Risk Assessment
Security Solution Architecture
Cloud Security
Project Management
Communication Skills

Education

Post-secondary education in Computer Science

Tools

NIST 800-53
ISO 27001
AWS
Azure
Kubernetes

Job description

Senior Lead, Security Advisory Transformation

Join to apply for the Senior Lead, Security Advisory Transformation role at Scotiabank

Senior Lead, Security Advisory Transformation

1 week ago Be among the first 25 applicants

Join to apply for the Senior Lead, Security Advisory Transformation role at Scotiabank

Requisition ID: 223022

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Responsibilities

The Senior Lead Transformation is responsible for providing guidance to business lines to ensure the design, development and implementation of technological solutions that integrate security practices, assisting them in making informed decisions to protect Bank information and data resources, by:

  • Working with business lines, Solution Architects and Enterprise Architects to develop sound security strategic and tactical plans towards the reliable implementation of consistent and secure control processes, by assessing security risk.
  • Designing and developing sound risk management controls in accordance with Bank's standards that ensure the Bank's compliance with industry regulations.
  • Pursuing security and control process improvements to advance security compliance.

Reporting to management on the status of the system of internal controls with recommendations for remediation of risks

Is this role right for you? In this role, you will:

Threat risk assessment advisory & governance

  • Review and work on initiatives to improve threat risk assessment (TRA) process
  • Manage overall initiatives under TRA transformation such developing processes and documentation.
  • Work with different control function within the bank (e.g. Pattern & Policy as Code, Application security, cloud security and Threat Modelling teams) and Enterprise Architecture organization, to improve current threat risk assessment processes.
  • Provide strategic guidance and technical expertise to business lines, IT support functions, and IS&C Control functions to implement the transformed TRA processes.
  • Manage and align TRA transformation processes with IS&C and Enterprise Architecture, providing strategic guidance and technical expertise.
  • Provide training and mentorship on transformed TRA processes to the Enterprise

Security Solutioning

  • Provide inputs to security assessment processes for platforms and applications to ensure inclusion of sound security controls.
  • Conduct comprehensive security assessments, as needed.
  • Evaluate existing security solutions and propose enhancements or new designs to address emerging threats and business requirements.
  • Provide guidance and technical expertise on threat methodology and risk assessment frameworks and the creation of relevant threat modelling artifacts, as needed.
  • Conduct or provide Quality Assurance on Threat Modelling as required.
  • Support the development of security patterns.
  • Enforce security patterns, policies, standards, and procedures to protect the integrity, availability, and confidentiality of the Bank applications and infrastructure.
  • Conduct and enhance security assessments and solutions, ensuring the application of security patterns, policies, and threat modeling

Mentoring and Training

  • Provide guidance and training to the Enterprise on the transformed TRA processes

Compliance

  • Ensure that TRA transformed processes align with industry regulations and organizational compliance requirements.
  • Contribute to the audit process, responding to compliance assessments and audits

Skills

Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have:

  • Post-secondary education in Computer Science or in a related field.
  • At least 5 years of hands-on technical work experience in performing threat risk assessments on complex applications, network environments and threat modelling.
  • Experience in security solution architecture, software development, and/or hands-on experience with implementations of security controls will be an added advantage.
  • Strong experience leading complex projects providing security advice to ensure information security risks are mitigated.
  • Certifications (CISSP, CISM, CCSP, CRISC, Cloud oriented Google, Microsoft or AWS certificates) are nice to have.
  • Familiar with industry standards and frameworks e.g. NIST 800-53, ISO 27001, ISO27002, ISO 27017, ISO27018, PCI DSS.
  • Solid knowledge of cloud technologies and cloud security (GCP or Azure or AWS, Kubernetes and IAM, CI/CD pipelines, Terraforms, infrastructure as a code).
  • Advanced communication (verbal/written/presentation) skills in English

Technical Skills

  • Experience in threat modeling, identifying risks in cloud environments, and advising on security best practices during cloud migration and modernization projects.
  • Strong knowledge of cloud security governance frameworks (e.g., NIST, ISO 27001, SOC 2, CIS Benchmarks) and regulatory compliance requirements (e.g., GDPR, PIPEDA, PCI DSS).
  • Experience in providing security advisory services, guiding teams through cloud security best practices and modernization security strategies

What's in it for you?

  • Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias-free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employee to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans.
  • Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements.
  • Upskilling through online courses, cross-functional development opportunities, and tuition assistance.
  • Competitive Rewards program including bonus, flexible vacation, personal, sick days and benefits will start on day one.
  • Community Engagement - no matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs such as hackathons, contests, Humans of Digital and much more!

Work arrangements: Hybrid

Location(s): Canada : Ontario : Toronto

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Other, Information Technology, and Management
  • Industries
    Banking

Referrals increase your chances of interviewing at Scotiabank by 2x

Get notified about new Security Lead jobs in Toronto, Ontario, Canada.

Chief Information Security Officer (11103)

Greater Toronto Area, Canada CA$177,377.20-CA$221,803.40 3 weeks ago

West Park Healthcare - Full-Time Security Team Lead
West Park Healthcare - Full-Time Security Team Lead
Senior Information Security and Compliance Manager
Manager, Payments Security (Global Security)
Manager, Payments Security (Global Security)
Senior Manager, Security Exceptions & Reporting
UK Chief Information Security Officer (CISO)
Assistant Manager Security Operations Centre
Security Manager, Technical Customer Assurance
Senior Manager, Cybersecurity Operations
Retail Security Supervisor, Full-Time, GTA
Audit Manager, IT & Cyber Security Audit
Manager, Cyber Resilience & Offensive Security
Deputy Director, Information Technology (IT)
Strategic Security Consultant, Mandiant, Google Cloud

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Lead, Security Advisory Transformation

Scotiabank

Old Toronto

Hybrid

CAD 80.000 - 120.000

7 days ago
Be an early applicant

Senior Lead, Security Advisory Transformation @ Scotiabank

Cyber Crime

Toronto

Hybrid

CAD 80.000 - 120.000

17 days ago