TD risk specialist overseeing second-line technology, cyber, and data risk controls for a major Canadian bank. Advising executives and challenging operational risk practices.
Responsibilities
Partner with 2A Segments, 2A TDRM enterprise, and the First Line of Defense to oversee and challenge risk management activities and leading practices/technologies
Provide senior specialist advisory services to executives and business segment leaders
Lead program design, policy formulation, and operating standards aligned with enterprise or business segment strategy
Anticipate emerging business trends and regulatory/risk issues and recommend large-scale improvements
Serve as an expert advisor to senior management and potentially lead teams of related specialists/experts
Advise on execution strategy and lead development and deployment of functional programs or initiatives
Execute second-line challenge activities supporting the ORM Framework
Review and escalate Segment Technology & Cyber and Data RAS measure limits and excesses to the Segment CRO and senior management
Support review and challenge of PRCSA/RCSA
Review Technology & Cyber and Data scenario analysis
Challenge first-line design and operating effectiveness testing
Review Key Risk Indicators, Segment Deep Dives, and Segment Target Reviews
Communicate risk management practices, methodologies, and assessment results to executives and senior management
Influence risk-based remediation
Write and maintain enforceable technology policies using “must” statements
Maintain high levels of integrity, motivation, and morale as a positive team player
Requirements
Bachelor's degree from a recognized university or equivalent experience
At least 10+ years of relevant experience within the Financial Services industry in 1st/2nd line Technology & Control Function or Internal Audit
At least 5 years in Operational Risk Management (2nd line ORM)
Experience engaging with technical SMEs across Incident Management, Change Management, Problem Management, and technical Control Standards
Understanding of FFIEC, OCC 1042, OSFI B-10/B-13/E-21, GLBA 501(b), PCI, SOX, HIPAA, COBIT, ISO 27001/22301, and NIST standards
Experience aligning firm-wide control domains to frameworks, such as NIST → ITGC → RCSA mapping
Flexibility to work in ambiguity and adapt to changes in a fast-paced environment
Superior influencing, collaboration, and communication skills
Experience assessing risk, challenging the status quo, and breaking silos
Strong analytical skills, including segment risk analysis, data analysis, and comparative analysis
Understanding of risk management frameworks and methodologies
Understanding of cybersecurity frameworks, operations, processes, controls, and tools
Understanding of technology operations and processes
Understanding of Data Risk Management and Governance
Understanding of infrastructure and application security domains
Understanding of Change & Configuration Management
Understanding of Technology Resilience, including HA, DR, RTO/RPO, and backup immutability
Understanding of IT Asset Management & Lifecycle Governance
Understanding of logging, monitoring, and observability tools
Understanding of trend and root cause analysis
Understanding of Continuous Control Monitoring (CCM) Logic
Understanding of cloud service provider management
Understanding of audit and regulatory engagement, management responses, and evidencing control coverage
Successful completion of all three levels of TD Operational Risk Management certification within 12 months of starting the role; certification is not required to apply
Undergraduate degree in Computer Science, Computer Engineering, or Risk Management is an asset
CISSP, CISM, CISA, CDPSE, AAIA, CRISC, or similar accreditation is preferred
Benefits
Base salary
Variable compensation
Health and well-being benefits
Savings and retirement programs
Paid time off
Banking benefits and discounts
Career development
Reward and recognition programs
Regular development conversations, training programs, and a competitive benefits plan
Online learning platform
Mentoring programs
Training and onboarding sessions
Interview accommodations, including accessible meeting rooms and captioning for virtual interviews
Home and Auto Insurance Advisor selling digital personal insurance for PolicyMe. Managing inbound leads, closing policies, and improving customer - first sales processes.
Commercial Insurance Broker supporting Accounts, New Business, or Renewals for Zensurance’s digital - first commercial insurance platform. Advising clients, managing policies, growing revenue, and retaining accounts.
Investigation Advisor investigating health and dental claim fraud for iA Financial Group. Analyzing suspicious patterns, documenting findings, and improving fraud - detection tools.
Risk manager leading AML/KYC initiatives, regulatory change, and operational risk governance for American Express Canada. Advising stakeholders and reporting progress to senior leadership.
Personal Insurance Sales Advisor selling and retaining personal insurance policies for BrokerLink. Quoting business, developing client relationships, and supporting insurer documentation across Ontario offices.
AVP leading Sun Life’s insurance distribution strategy, advisor relationships and regional sales execution. Building leadership capability and sustainable life and health insurance growth.
Director managing enterprise underwriting and claims risk at Sun Life, a life insurer helping Clients achieve financial security. Redesigning mortality and morbidity risk programs globally.
Conseiller principal évaluant les risques environnementaux et sociaux des transactions d’EDC. Conseils sur l’atténuation, la conformité et les normes internationales pour soutenir les entreprises canadiennes à l’étranger.