Information Security Analyst governing End-User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
Responsibilities
Define, develop, and implement Technology Controls and Information Security policies, programs, standards, processes, and tools
Provide expertise on assessing risks, identifying control gaps, and developing risk-mitigation solutions
Support the Bank’s End-User Computing governance program, including asset classification, attestation, risk and control assessments, thematic remediation, high-risk mitigation, standards enhancement, stakeholder guidance, governance reporting, learning content, and intake management
Advise business, technology, and control partners on EUC governance and information-security requirements
Serve as an EUC risk and technology subject matter expert
Conduct or support inherent risk and control-gap assessments and guide remediation strategies
Coordinate intake, review, prioritization, and assignment of EUC-related requests
Develop and maintain EUC governance content, procedures, learning materials, and knowledge resources
Lead or support stakeholder engagement sessions, office hours, and knowledge-sharing activities
Maintain the EUC Book of Record through classification, attestation campaigns, monitoring, data-quality reviews, and assessment of asset changes and risk indicators
Support thematic analysis, corrective-action tracking, high-risk asset mitigation, and management reporting
Develop EUC risk reporting and monitor KPIs and KRIs
Perform or support quality assurance and quality control reviews
Support internal audits, regulatory examinations, compliance reviews, and remediation tracking
Monitor emerging technology, security, regulatory, and industry developments
Identify and escalate key risks and issues
Participate in business-specific, cross-functional, and enterprise initiatives
Contribute to knowledge transfer, documentation, training, and learning activities
Influence stakeholder behaviour to reduce risk and promote technology risk management
Requirements
University degree or equivalent relevant education and professional experience
Experience in information security, technology risk, governance, risk assessment, control assessment, or a related discipline
Experience conducting risk assessments, analyzing control gaps, documenting risk impacts, and supporting remediation activities
Strong stakeholder consultation, analytical, written communication, and presentation skills
Ability to interpret technology-control, information-security, governance, and regulatory requirements and translate them into practical guidance
Ability to manage multiple priorities independently and deliver accurate, high-quality results within established timelines
Ideally, 5 or more years of work experience with 2 years of experience in End User Computing Risk Assessment, preferably in the financial industry
Preferred: experience within financial services or another highly regulated industry
Preferred: experience supporting End-User Computing governance, asset governance, asset classification, attestation, or related technology-risk programs
Preferred: experience using ServiceNow or a comparable governance, risk, and compliance platform
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
Lead AI risk analyst securing CBC/Radio - Canada’s public - service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.