Senior Information Security Analyst securing TD’s technology controls, cyber risk, and regulatory compliance. Assessing vulnerabilities, supporting audits, and guiding enterprise security remediation.
Responsibilities
Provide consultation and advice on technology controls and information security programs, policies, standards, and incidents
Conduct project consulting on risk assessments, control requirements, control procedures, vulnerability assessments, and related areas
Lead or contribute to risk and control assessments for application portfolios
Document control gaps, business and enterprise impact, risk mitigation, and remediation plans
Contribute to global security management strategy and framework development and oversight
Ensure technology, processes, and governance monitor, detect, prevent, and respond to security threats
Develop technology risk reporting, monitor trends, and define control-effectiveness metrics
Work with technology partners, stakeholders, and service/platform owners to integrate security components into enterprise architecture
Consult on regulatory compliance requirements, reporting, and questions
Support audits, management responses, and remediation activities
Participate in computer security incident response
Define, develop, implement, and manage technology controls/information security policies, programs, tools, and solutions
Review internal processes, identify improvement opportunities, and advise on enterprise frameworks and methodologies
Manage relationships across technology, business, corporate, and control functions
Participate as a subject matter expert in business-specific, cross-functional, and enterprise initiatives
Prepare complex reporting, analysis, and assessments
Document and update internal processes
Manage workload, deliver quality results, and meet timelines
Establish relationships with business and technology partners, program managers, and project managers
Participate in knowledge transfer within teams and business units
Requirements
University degree
5–7 years of relevant experience
Advanced knowledge of one or more technology controls/security domains, disciplines, and practices
Familiarity with industry-standard frameworks, including NIST CSF/800-53, ISO 27001, COBIT, CIS, PCI, GLBA, and SOX/ITGC
Ability to identify, assess, and monitor technology risks, including information security, cybersecurity, resilience, operations/change management quality, data quality/security, and IT compliance
Knowledge of technology, information and cybersecurity, risk management, and governance standards and best practices
Strong critical thinking and ability to decompose complex issues
Strong written, communication, and presentation skills
Ability to prioritize workload and meet timelines with limited guidance
Ability to multitask and manage multiple team and client demands
Proficiency with Jira, Confluence, SharePoint, and Microsoft Office
Data analysis experience, preferably using Power BI or Tableau
Familiarity with GRC platforms such as Archer and ServiceNow IRM
Information security certification/accreditation is an asset
Familiarity with Python and generative AI is an asset
Benefits
Base salary and variable compensation
Health and well-being benefits
Savings and retirement programs
Paid time off
Banking benefits and discounts
Career development
Reward and recognition programs
Regular career, development, and performance conversations
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
Lead AI risk analyst securing CBC/Radio - Canada’s public - service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.
IT security analyst protecting Desjardins hardware, software, data, and access controls. Analyzing vulnerabilities, risks, and security processes while developing recommendations and action plans.
Analyste cybersécurité administrant et optimisant les plateformes protégeant les services essentiels de la Ville de Montréal. Déploiement de solutions, gestion des incidents et automatisation opérationnelle.
Analyste SOC détectant les menaces et répondant aux incidents pour I - TRACING, pure - player indépendant de la cybersécurité. Exploitation SIEM, analyse de vulnérabilités et suivi de remédiation.