computer systems business analyst
Title posted on CareerBeacon -
Group Risk Specialist – Information Security Risk Management
Posted on
August 22, 2024
by
Employer details
TD Bank
Job details
Work Location:CanadaHours:37.5Line of Business:Risk ManagementPay Details:We're committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions, including pay details for this role.Job Description:Department OverviewThe independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of operational risk across the enterprise.ORM for Enterprise Technology (ORM ETech) provides independent oversight and challenge to operational risk management activities executed by the Technology organization and business groups across the enterprise. They partner with the first line of defense (CIO & CISO organizations) in identifying, reporting, and mitigating Technology and Cybersecurity risk issues and provide subject matter expertise in Cybersecurity risk management practices. The group executes 2A requirements in support of the 3 lines of defense framework. Job DescriptionThe Information Security Risk Specialist will partner with the first line of defense and other second line of defense teams to oversee and challenge the execution of risk management activities and leading practices/technologies used to keep up with the constantly evolving cyber threat landscape. Reporting to the Senior Manager, Information Security Risk Management, this role will have the following accountabilities:Act as liaison between Information Security Risk Management and other teams for the intake, tracking, and coordination of activities requiring cybersecurity subject matter expertise.Support the oversight and independent challenge of Cybersecurity risk management activities for the Enterprise including Cybersecurity Strategy and Roadmap, Cybersecurity portfolio planning and execution, and maturity self-assessments aligned to the NIST Cybersecurity Framework (CSF).Plan, implement and execute initiatives related to operational automation, activity planning, architecture of second line of defense operations, and periodic risk reporting.Coordinate internal team efforts and resources to address requests from regulators, auditors, senior management, and other stakeholder groups.Lead efforts to improve the second line of defense for cybersecurity practice in areas such as document management, processes/procedures, work planning, and formalization of methods and tooling.Execute 2nd line challenge activities required to support the ORM Framework, including but not limited to:Cybersecurity risks linked to strategic (sRCSA) and process RCSA (pRCSA) across Business Technology Solutions teams with a strong focus on the CISO organization;Cybersecurity risk scenario analysis;Internal and External cyber event analysis;Key Risk Indicators, and;Other areas as appropriate to support the technology areas in risk management.Effectively communicate risk management practices and methodologies and results of risk assessments to Executive and senior management in a supportive and collaborative manner and influence risk-based remediation.Be a positive team player to consistently maintain high levels of integrity, motivation, and morale.Will be required to keep abreast of Technology and Cybersecurity emerging risks, the evolving Cyber threat landscape, best practices to address/mitigate Cybersecurity risks, and applicable Regulatory and Compliance requirements.Position will deal with senior management in technology areas and technology risk professionals.Conduct appropriate assessment of Technology for risk identification, assessment, reporting, and monitoring based on a risk-based methodology in areas such as:Infrastructure and application vulnerability management;Security configuration management;Network and endpoint protections;Technology and cybersecurity incidents;Cybersecurity control/process adequacy, andTechnology risk asses
-
LocationToronto, ON
-
Workplace information
On site
-
SalaryNot available
-
Terms of employment
Full time
- Start date
Starts as soon as possible
- vacancies
1 vacancy
- Source
CareerBeacon
#2107031
Advertised until
2024-09-20
Important notice: This job posting has been provided by a partner site. Job Bank is not responsible for this content.
Report a problem with this job posting
Thank you for your help!
You will not receive a reply. For enquiries, please contact us.