Information Security Specialist - I&E Shared Standards Center of Excellence
Listed on 2026-03-14
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Overview
Work Location: Toronto, Ontario, Canada
Hours: 37.5
Line of Business: Technology Solutions
Pay Details: $96,900 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job DescriptionMembers of the VRO-Shared Centre of Excellence team are responsible for leading I&E involvement in risk partner assessments and supporting I&E teams with the execution of activities closely tied to TD's Patching Standards and the Technology Risk Management, Governance and Oversight Framework.
The Information Security Specialist, VRO-Shared Centre of Excellence, supports definition, development and/or implementation of I&E-related Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank. May participate on projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business line or enterprise level for the VRO.
The role is expected to focus largely on regulatory, audit, and enterprise-impacting activities.
ACCOUNTABILITIES
CUSTOMER
- Lead on Regulatory and Internal Audit compliance requirements, reporting and questions for the VRO
- Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
- Provide support and consultation in preparation for Operational Risk Management assessments and in composing management responses and appropriate remediation activities
- Provide support and consultation in composing management responses and appropriate remediation activities for First Line control exceptions and Self-Declared findings
- Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for I&E-VRO
- Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
- Lead or contribute to completion of risk and control design assessments for VRO activities, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
- Contribute to the definition, development, and oversight of a global security management strategy and framework
- Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
- Support development and maintenance of on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
- Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
SHAREHOLDER
- Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines
- Lead the review of internal processes and activities and assist in identifying potential opportunities for improvement
- Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities - With a specific focus on I&E Patching Standards and teams
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise
- Remain informed of emerging issues, industry trends and/or relevant changes
- Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness
- Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements
- Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank
- Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required
- Maintain a culture of risk management and control, supported by…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: