Segment Risk Specialist – Technology, Cyber and Data Risk Management

Posted 2 weeks ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • TD risk specialist overseeing second-line technology, cyber, and data risk controls for a major Canadian bank. Advising executives and challenging operational risk practices.

Responsibilities

  • Partner with 2A Segments, 2A TDRM enterprise, and the First Line of Defense to oversee and challenge risk management activities and leading practices/technologies
  • Provide senior specialist advisory services to executives and business segment leaders
  • Lead program design, policy formulation, and operating standards aligned with enterprise or business segment strategy
  • Anticipate emerging business trends and regulatory/risk issues and recommend large-scale improvements
  • Serve as an expert advisor to senior management and potentially lead teams of related specialists/experts
  • Advise on execution strategy and lead development and deployment of functional programs or initiatives
  • Execute second-line challenge activities supporting the ORM Framework
  • Review and escalate Segment Technology & Cyber and Data RAS measure limits and excesses to the Segment CRO and senior management
  • Support review and challenge of PRCSA/RCSA
  • Review Technology & Cyber and Data scenario analysis
  • Challenge first-line design and operating effectiveness testing
  • Review Key Risk Indicators, Segment Deep Dives, and Segment Target Reviews
  • Communicate risk management practices, methodologies, and assessment results to executives and senior management
  • Influence risk-based remediation
  • Write and maintain enforceable technology policies using “must” statements
  • Maintain high levels of integrity, motivation, and morale as a positive team player

Requirements

  • Bachelor's degree from a recognized university or equivalent experience
  • At least 10+ years of relevant experience within the Financial Services industry in 1st/2nd line Technology & Control Function or Internal Audit
  • At least 5 years in Operational Risk Management (2nd line ORM)
  • Experience engaging with technical SMEs across Incident Management, Change Management, Problem Management, and technical Control Standards
  • Understanding of FFIEC, OCC 1042, OSFI B-10/B-13/E-21, GLBA 501(b), PCI, SOX, HIPAA, COBIT, ISO 27001/22301, and NIST standards
  • Experience aligning firm-wide control domains to frameworks, such as NIST → ITGC → RCSA mapping
  • Flexibility to work in ambiguity and adapt to changes in a fast-paced environment
  • Superior influencing, collaboration, and communication skills
  • Experience assessing risk, challenging the status quo, and breaking silos
  • Strong analytical skills, including segment risk analysis, data analysis, and comparative analysis
  • Understanding of risk management frameworks and methodologies
  • Understanding of cybersecurity frameworks, operations, processes, controls, and tools
  • Understanding of technology operations and processes
  • Understanding of Data Risk Management and Governance
  • Understanding of infrastructure and application security domains
  • Understanding of Change & Configuration Management
  • Understanding of Technology Resilience, including HA, DR, RTO/RPO, and backup immutability
  • Understanding of IT Asset Management & Lifecycle Governance
  • Understanding of logging, monitoring, and observability tools
  • Understanding of trend and root cause analysis
  • Understanding of Continuous Control Monitoring (CCM) Logic
  • Understanding of cloud service provider management
  • Understanding of audit and regulatory engagement, management responses, and evidencing control coverage
  • Successful completion of all three levels of TD Operational Risk Management certification within 12 months of starting the role; certification is not required to apply
  • Undergraduate degree in Computer Science, Computer Engineering, or Risk Management is an asset
  • CISSP, CISM, CISA, CDPSE, AAIA, CRISC, or similar accreditation is preferred

Benefits

  • Base salary
  • Variable compensation
  • Health and well-being benefits
  • Savings and retirement programs
  • Paid time off
  • Banking benefits and discounts
  • Career development
  • Reward and recognition programs
  • Regular development conversations, training programs, and a competitive benefits plan
  • Online learning platform
  • Mentoring programs
  • Training and onboarding sessions
  • Interview accommodations, including accessible meeting rooms and captioning for virtual interviews

Job title

Job type

Full Time

Experience level

SeniorLead

Salary

CA$115,600 - CA$163,200 per year

Degree requirement

Bachelor's Degree

Tech skills

CloudCyber Security

Location requirements

HybridTorontoCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.