Spécialiste, Sécurité de l’information
Lieu de travail : Toronto, Ontario, Canada
Horaire : 37.5
Secteur d’activité : Solutions technologiques
Détails de la rémunération: $91,200 - $136,800 CAD
LaTD a à cœur d’offrir une rémunération juste et équitable à tous les collègues. Les occasions de croissance et le perfectionnement des compétences sont des caractéristiques essentielles de l’expérience collègue à laTD.
Description du poste :
Responsibilities:
- Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
- Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
- Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
- Contribute to the definition, development, and oversight of a global security management strategy and framework
- Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG’s business
- Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
- Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank’s overall Enterprise Architecture, and any control gaps are addressed.
- Consult on Regulatory compliance requirements, reporting and questions
- Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
- Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
- Continuously enhance knowledge / expertise in own area
- Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
- Prioritize and manage own workload to deliver quality results and meet assigned timelines
- Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
- Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
- Establish effective relationships across multiple business and technology partners, program and project managers
- Participate in knowledge transfer within the team and business units
Requirements:
- 7+ years of relevant experience
- 3-5 years' experience in one of the following core areas DevSecOps, ITIL Management, SDLC Management, or Cloud Infrastructure (AWS, Azure, GCP)
- CRISC or CISSP certification
- Expert knowledge of IT security and risk disciplines and practices
- Advanced knowledge of organization, technology controls / security/ risk issues
- Experience participating on complex, comprehensive or large projects and initiatives
- University degree
#LI-TECH