TD Bank
Information Security Analyst II - Asset Assessment & Governance
Toronto, Ontario · On-site · Posted yesterday
Opens td.wd3.myworkdayjobs.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- On-site
- Source
- Workday (employer's hiring system)
Skills mentioned
React, Data Analysis
About the role
Work Location:
Toronto, Ontario, CanadaHours:
37.5Line of Business:
Technology SolutionsPay Details:
$69,700 - $98,400 CADTD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:
About This Role
You will be a core member of a high performing team of technology and risk professionals who utilize their subject matter expertise in technology and information and cyber security risk management to provide effective guidance on a broad range of cyber security policies, standards and controls in compliance with the Enterprise Risk and Control Framework. As part of the Global Technology & Solutions (GTS) Protect organization, the Centre of Excellence (COE) Assessment team, you will play a key role in ensuring required risk and control assessments are completed efficiently and with quality/care. The role also supports standards governance, assessment quality assurance, guidance maintenance, strategic partner engagement, and continuous improvement of the end-to-end assessment process.
Meaningful work is fueled by meaningful performance and career development conversations with your manager. Here's some of what you may be asked to perform:
Standards Governance & Advisory
- Represent GTS CoE Assessments in Standards working groups and stakeholder forums, perform preliminary analysis of proposed standard changes, and track related actions and follow-ups.
- Assess and challenge standard requirements for relevance to CGAs, support updates to CGA Guidance and related documentation, and help maintain traceability between standards, control requirements, guidance, and assessment requirements.
- Guide partners on a broad range of technology controls and information and cyber security programs, policies, and standards.
- Contribute to the definition, development, and oversight of a global security management strategy and framework.
- Contribute collaboratively to the review of internal processes and activities and assist in identifying potential opportunities for improvement.
- Support simplification and modernization of the CGA process through automation research, process mapping, documentation, assessor training, knowledge repositories, and identification of recurring assessment pain points.
- Adhere to, advise, oversee, monitor and enforce enterprise frameworks and methodologies that relate to technology controls and information security activities.
- Contributes to the ongoing evolution of the GTS CoE Assessment operating model and implementation of strategic process enhancements.
- Support stronger end-to-end assessment governance by improving process ownership, quality-control mechanisms, consistency of execution, and alignment between standards, guidance, and assessment practices.
- Strengthening relationships with Standards teams and stakeholders, provide proactive risk guidance, and act as a trusted advisor on control and assessment-related matters.
Assessment Execution & Risk Review
- Conduct: Technology Asset Risk Assessments (TARAs), Control Gap Assessments (CGAs), perform Quality Assurance reviews of risk assessments, and support assessment planning, coordination, documentation, evidence tracking, stakeholder follow-ups, and remediation activities.
- Conduct risk and control assessments and evaluate the appropriate control procedure.
- Interpret and communicate technology control and information security requirements arising from regulatory obligations, industry frameworks, internal policies and standards, and security best practices.
- Lead or contribute to the completion of risk and control design assessments for any assigned assets within the enterprise.
- Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology and security threats against TDBG’s business.
Reporting & Continuous Improvement
- Monitor assessment trends and emerging risk themes and help define and refine metrics that measure effectiveness and assessment quality, consistency, and efficiency.
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
- Contribute to the development of on-going technology risk reporting, monitoring key trends and providing assurance that metrics to regularly measure control effectiveness for own area are met.
What can you bring to GTS? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention.
- 2+ years of relevant experience in the area of IT risk and technology and/or information security and/or data analysis in a large organization.
- University degree and or Information Security Certification/Accreditation (an asset).
- Skills to identify, assess, and monitor technology risks including information security, cyber security, resilience, operations/change management quality, data quality/security, and IT compliance.
- Advanced knowledge of one or more technology controls or security domains, disciplines and practices.
- Knowledge of standards governance, control requirement interpretation, assessment Quality Assurance, and traceability between standards and assessment requirements.
- Strong critical thinking - ability to decompose complex issues into manageable pieces.
- Ability to articulate ideas, share experiences and skills.
- Sound knowledge of business, technology controls, security and risk issues.
- Firm commitment to staying informed/abreast of emerging cyber and information security issues, industry trends.
- Strength in prioritizing and managing your own workload to deliver quality results and meet timelines with limited guidance of management.
- Knowledge of industry standards and best practices in the areas of technology, information and cyber security, risk management and governance.
- High flexibility and are comfortable working in a fluid, changing environment.
- Strong communication, writing and presentation skills.
- Ability to multi-task and manage multiple team and client demands concurrently.
- Dedicated team player; comfortable with a dynamic work environment.
- Diligent and resourceful in research and information gathering.
- Must be proficient with technology tools including MS Office, databases and reporting tools.
- Ability to support process-improvement initiatives through research, analysis, process mapping, documentation, training materials, knowledge management, and identification of automation opportunities.
- Ability to navigate Co-Pilot for research, productivity and analysis.
Inclusiveness
At TD, we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. We are dedicated to building a workforce that reflects the diversity of our customers and communities in which we live and serve. If you require accommodation for the recruitment/interview process (including alternate formats of materials, or accessible meeting rooms or other accommodation), please let us know and we will work with you to meet your needs.
#li-tech
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we strive to make every interaction, product, and experience remarkably human and refreshingly simple for over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to foster deeper relationships, ensure disciplined execution, and build a simpler, faster banking experience. TD is deeply committed to being a leader in client experience, that is why we believe that all colleagues, no matter where they work, are client facing. Together, we are reimagining what banking can be for our clients, colleagues and communities.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information:
We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities.
If you’re passionate about helping clients and building deep, lasting relationships, TD offers diverse career paths where you can grow your expertise and make a meaningful impact.
We're committed to your success and foster a respectful workplace where diverse perspectives are valued, everyone has fair opportunities to grow, and you can unlock your full potential to achieve your career goals. Here at TD, we hire and develop the best.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.
Interview Process
We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
Language Requirement (Quebec only):
Sans ObjetJob ID wd-td-wd3-td-bank-careers-information-security-analyst-ii---asset-assessment---governance_r_1512605 · Original posting ↗
Similar jobs
Information Security Analyst II ( Social Engineer Threat Analyst)3dTD BankToronto, Ontario · On-site
Information Security Analyst (Detection Engineer)3dTD BankToronto, Ontario · On-site
Senior Information Security Analyst4dTD BankToronto, Ontario · On-site
Senior Information Security Analyst2wScotiabankToronto, Ontario
Senior Information Security Analyst (Vulnerability Governance)7wTD BankToronto, Ontario · Hybrid