Group Risk Specialist – Information Security Risk Management

Posted:
8/20/2024, 5:00:00 PM

Location(s):
Toronto, Ontario, Canada ⋅ Ontario, Canada

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security

Work Location:

Canada

Hours:

37.5

Line of Business:

Risk Management

Pay Details:

We’re committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions, including pay details for this role.

Job Description:

Department Overview

The independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of operational risk across the enterprise.

ORM for Enterprise Technology (ORM ETech) provides independent oversight and challenge to operational risk management activities executed by the Technology organization and business groups across the enterprise. They partner with the first line of defense (CIO & CISO organizations) in identifying, reporting, and mitigating Technology and Cybersecurity risk issues and provide subject matter expertise in Cybersecurity risk management practices. The group executes 2A requirements in support of the 3 lines of defense framework. 

Job Description

The Information Security Risk Specialist will partner with the first line of defense and other second line of defense teams to oversee and challenge the execution of risk management activities and leading practices/technologies used to keep up with the constantly evolving cyber threat landscape. 
 
Reporting to the Senior Manager, Information Security Risk Management, this role will have the following accountabilities:

  • Act as liaison between Information Security Risk Management and other teams for the intake, tracking, and coordination of activities requiring cybersecurity subject matter expertise.
  • Support the oversight and independent challenge of Cybersecurity risk management activities for the Enterprise including Cybersecurity Strategy and Roadmap, Cybersecurity portfolio planning and execution, and maturity self-assessments aligned to the NIST Cybersecurity Framework (CSF).
  • Plan, implement and execute initiatives related to operational automation, activity planning, architecture of second line of defense operations, and periodic risk reporting.
  • Coordinate internal team efforts and resources to address requests from regulators, auditors, senior management, and other stakeholder groups.
  • Lead efforts to improve the second line of defense for cybersecurity practice in areas such as document management, processes/procedures, work planning, and formalization of methods and tooling.
  • Execute 2nd line challenge activities required to support the ORM Framework, including but not limited to:
    • Cybersecurity risks linked to strategic (sRCSA) and process RCSA (pRCSA) across Business Technology Solutions teams with a strong focus on the CISO organization;
    • Cybersecurity risk scenario analysis;
    • Internal and External cyber event analysis;
    • Key Risk Indicators, and;
    • Other areas as appropriate to support the technology areas in risk management.
  • Effectively communicate risk management practices and methodologies and results of risk assessments to Executive and senior management in a supportive and collaborative manner and influence risk-based remediation.
  • Be a positive team player to consistently maintain high levels of integrity, motivation, and morale.
  • Will be required to keep abreast of Technology and Cybersecurity emerging risks, the evolving Cyber threat landscape, best practices to address/mitigate Cybersecurity risks, and applicable Regulatory and Compliance requirements.
  • Position will deal with senior management in technology areas and technology risk professionals.
  • Conduct appropriate assessment of Technology for risk identification, assessment, reporting, and monitoring based on a risk-based methodology in areas such as:
    • Infrastructure and application vulnerability management;
    • Security configuration management;
    • Network and endpoint protections;
    • Technology and cybersecurity incidents;
    • Cybersecurity control/process adequacy, and
    • Technology risk assessments.


This role is looking for a highly seasoned professional with experience in Cybersecurity, technology, and/or risk management.

Job Requirements

  • Experience in the Cybersecurity, Technology Solutions, Risk Management, or Internal Audit field.
  • Good understanding of Business Analysis, application design and coding, with emphasis on Microsoft Power Apps and Power BI, JIRA, Confluence and SharePoint.
  • An understanding of regulatory and Controls requirements: PCI, FFIEC, SOX, HIPAA, ISO 2700x and NIST standards.
  • Ability to work in ambiguity, must be flexible to deal with changes in a fast paced and new environment, working closely with peers where subject matter expertise is required.
  • Organizationally astute, with superior influencing, collaboration, and communication skills.
  • Experience assessing risk and challenging the status quo.
  • Proven ability to foster a cohesive team and promote a positive, high performing work environment.
  • Expertise in working effectively in teams – requires a track record of knowledge across the organization.
  • Strong analytical skills, including segment risk analysis, data analysis, and comparative analysis.
  • In order to provide effective oversight and independent challenge the role requires the candidate to have a good understanding of the following areas:
    • Risk management frameworks and methodologies;
    • Cybersecurity frameworks, operations, processes, controls, and tools;
    • Technology operations and processes;
    • Infrastructure and application security domains;
    • Cloud service provider management, and;
    • Regulatory requirements.
  • Strong business and financial acumen.

Education & Accreditation 

  • This role requires successful completion of all three levels of TD Operational Risk Management certification.  Certification is not a requirement to apply for this role.  The successful candidate will have 12 months from the start date in the role to complete required certifications.  The required courses are available internally through TD Operational Risk Management. 
  • Undergraduate degree in Computer Science/Computer Engineering/Risk Management is an asset.
  • Accreditation such as CISSP, CISM, CRISC, CEH, OSCP, OSCE and/or similar is preferred.

Who We Are:

TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.

TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you’ve got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we’re here to support you towards your goals. As an organization, we keep growing – and so will you.

Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more

Additional Information:
We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.

Colleague Development
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.
 

Training & Onboarding
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.

Interview Process 
We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.


Accommodation
Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.

We look forward to hearing from you!

Language Requirement:

N/A.