Information Security Analyst assessing technology assets, controls, and cyber risks for TD, a major North American bank. Supporting governance, quality assurance, reporting, and continuous assessment improvement.
Responsibilities
Represent GTS CoE Assessments in standards working groups and stakeholder forums
Analyze proposed standards changes and track related actions and follow-ups
Assess and challenge standard requirements for relevance to CGAs
Support updates to CGA guidance and related documentation
Maintain traceability between standards, control requirements, guidance, and assessment requirements
Guide partners on technology controls and information and cyber security programs, policies, and standards
Contribute to global security management strategy and framework development
Review internal processes and identify improvement opportunities
Support CGA process simplification and modernization through automation research, process mapping, documentation, assessor training, knowledge repositories, and pain-point identification
Adhere to, advise on, oversee, monitor, and enforce enterprise technology control and information security frameworks and methodologies
Conduct Technology Asset Risk Assessments, Control Gap Assessments, and quality assurance reviews
Support assessment planning, coordination, documentation, evidence tracking, stakeholder follow-ups, and remediation
Conduct risk and control assessments and evaluate control procedures
Interpret and communicate regulatory, industry, internal policy, and security best-practice requirements
Lead or contribute to risk and control design assessments for assigned enterprise assets
Ensure technology, processes, and governance address current and emerging technology and security threats
Monitor assessment trends and emerging risk themes
Define and refine metrics for assessment effectiveness, quality, consistency, and efficiency
Contribute to technology risk reporting and monitor control-effectiveness trends
Influence behavior to reduce risk and strengthen enterprise technology risk management culture
Strengthen relationships with standards teams and stakeholders and provide proactive risk guidance
Requirements
2+ years of relevant experience in IT risk, technology and/or information security and/or data analysis in a large organization
University degree and/or Information Security Certification/Accreditation is an asset
Ability to identify, assess, and monitor technology risks
Advanced knowledge of one or more technology controls or security domains, disciplines and practices
Knowledge of standards governance, control requirement interpretation, assessment quality assurance, and traceability
Knowledge of business, technology controls, security, and risk issues
Knowledge of industry standards and best practices in technology, information and cyber security, risk management, and governance
Strong critical thinking and ability to decompose complex issues
Strong communication, writing, and presentation skills
Ability to prioritize and manage workload with limited guidance
Ability to multitask and manage multiple team and client demands
Proficiency with MS Office, databases, and reporting tools
Ability to support process-improvement initiatives through research, analysis, process mapping, documentation, training materials, knowledge management, and automation opportunities
Ability to navigate Co-Pilot for research, productivity, and analysis
Flexibility in a changing environment
Must be able to work under applicable provincial employment regulations in Canada
Benefits
Health and well-being benefits
Savings and retirement programs
Paid time off
Banking benefits and discounts
Career development
Reward and recognition programs
Regular career, development, and performance conversations with manager
Online learning platform
Mentoring programs
Training and onboarding sessions
Accessibility accommodations during recruitment and interviews
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.