Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Responsibilities
Lead deployment, adoption and expansion of EUC governance technology solutions across business segments
Act as subject matter expert for EUC governance technology solutions, including platform capabilities, workflows, integrations, controls and business processes
Identify enhancements and new capabilities based on governance priorities, stakeholder feedback, operational insights and emerging needs
Develop and prioritize requirements and partner with Technology and external vendors on solution delivery, issue resolution and product evolution
Develop, maintain and manage product roadmaps aligned with EUC Governance strategy
Balance business needs, information security and control requirements, technology dependencies, risks and adoption objectives
Oversee EUC inventory and governance operations, including system interactions, inventory and data-quality processes, attestation controls, workflow management, reporting and continuous improvement
Support the Head of EUC Governance in executing enterprise strategy and priorities
Represent EUC Governance with business, Technology, Information Security, Risk and segment stakeholders
Lead identification, analysis, documentation, prioritization and validation of business, functional, information security and control requirements
Translate objectives into actionable requirements, user stories and acceptance criteria for Technology delivery
Partner throughout the PDLC across solution design, build, testing, release, deployment and enhancement
Apply product management and PDLC practices across Agile, Scaled Agile and Waterfall environments
Maintain product roadmaps and delivery artifacts using Jira, Confluence and Microsoft Project
Lead business validation, implementation readiness, issue management and post-deployment stabilization
Manage day-to-day product and delivery relationships with external technology vendors
Support development and evolution of program KPIs, KRIs and performance measures
Operationalize measurement and reporting, monitor trends and thresholds, and identify emerging risks and performance gaps
Facilitate reviews, assessments and assurance activities across the 1st, 2nd and 3rd Lines of Defense
Coordinate stakeholder engagement, documentation and evidence requirements, respond to inquiries and observations, and support remediation activities
Requirements
Strong experience in information security, technology risk, governance, product management or technology delivery within a large and complex organization
Financial services or other highly regulated industry experience is preferred
Strong understanding of technology risk and control concepts, including inventory management, risk assessment, control monitoring, data quality, attestation and ongoing governance
Knowledge of EUC risk and governance practices, including discovery and classification, is a strong asset
Experience with technology risk, governance, discovery, inventory, monitoring or risk-management platforms and their enterprise deployment and adoption
Knowledge of EUC governance solutions such as CIMCON, ClusterSeven/SAI360, Spark, Archer or comparable technologies is a strong asset
Experience translating information security, risk, control and business needs into technology requirements
Experience partnering with Technology teams throughout solution design, development, testing, implementation and ongoing enhancement
Strong knowledge of product management, PDLC and delivery methodologies, including Agile/Scaled Agile and Waterfall
Experience with Jira, Confluence, Microsoft Project, ServiceNow or comparable tools is preferred
Relevant post-secondary education in Information Security, Computer Science, Technology, Risk Management, Business or a related discipline, or equivalent relevant experience
Professional certifications such as CISSP, CISM, CRISC, PMP, PMI-ACP or equivalent are considered assets
Strong leadership, stakeholder management, analytical and communication capabilities
Must work on site
Benefits
Health and well-being benefits
Savings and retirement programs
Paid time off
Banking benefits and discounts
Career development
Reward and recognition programs
Regular development conversations
Training programs
Online learning platform
Mentoring programs
Training and onboarding sessions
Accessibility accommodations during the interview process
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.
Senior Associate designing cloud, application, and AI security solutions for PwC Canada’s consulting clients. Leading technical delivery pods and embedding DevSecOps across client environments.
Application Security Researcher building autonomous application - security capabilities for OX Security. Researching attack paths, AI models, and detection engines from prototype through production.
Managing Norfolk County’s cybersecurity, disaster recovery, incident response, and security projects. Supervising IT security staff and protecting municipal systems, services, and information.
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous - owned software testing and technology services across Canada.