Group Risk Specialist – Technology and Cybersecurity Risk Management; TCRM
Job Description & How to Apply Below
Work Location Toronto, Ontario, Canada
Hours 37.5
Line Of Business Risk Management
Pay Details 96,900. CAD
Department Overview The Second Line of Defense (2
LoD) independent Operational Risk Management (ORM) Technology and Cyber Security Risk Management (TCRM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of technology and cybersecurity risks across the enterprise. 2
LoD TCRM provides independent oversight and challenge to operational risk management activities executed by the Technology organization and business groups across the enterprise. They partner with the First Line of Defense (CIO & CISO organizations) in identifying, reporting, and mitigating Technology and Cybersecurity risk issues and provide subject matter expertise in Cybersecurity risk management practices. The group executes 2A requirements in support of the 3 lines of defense framework.
Job Description Support the oversight and independent challenge of Technology and Cybersecurity risk management activities for the Enterprise such as Cyber Scenario analysis, End User Computing, Business management Technology, Third Party and Cyber Supply Chain Risk Management, Digital Crown Jewels, Process Risk and Control-Assessment (pRCSA), Controls testing, Technology Risk Assessments.
Address requests from regulators, auditors, senior management, and other stakeholder groups.
Execute 2nd line challenge activities required to support the ORM Framework, including but not limited to:
Technology and Cybersecurity risks linked to and process RCSA (pRCSA) across Business Technology Solutions teams with a strong focus on the CISO organization;
Cybersecurity risk scenario analysis;
Internal and External cyber event analysis;
Key Risk Indicators, and;
Other areas as appropriate to support the technology areas in risk management.
Effectively communicate risk management practices and methodologies and results of risk assessments to Executive and senior management in a supportive and collaborative manner and influence risk-based remediation.
Be a positive team player to consistently maintain high levels of integrity, motivation, and morale.
Will be required to keep abreast of Technology and Cybersecurity emerging risks, the evolving Cyber threat landscape, best practices to address/mitigate Cybersecurity risks, and applicable Regulatory and Compliance requirements.
Position will deal with senior management in technology areas and technology risk professionals.
Conduct appropriate assessment of Technology for risk identification, assessment, reporting, and monitoring based on a risk-based methodology in areas such as:
Cybersecurity control/process adequacy,
Technology risk assessments,
Controls Testing and related processes,
Third Party and Cyber Supply Chain Risk Management,
End User Computing,
Business Managed Technology,
PCI Compliance
Job Requirements Experience in the Cybersecurity, and/or Technology Risk Management, or Internal Audit field.
An understanding of regulatory and Controls requirements: PCI, FFIEC, SOX, HIPAA, ISO 2700x and NIST standards.
Ability to work in ambiguity must be flexible to deal with changes in a fast paced and new environment, working closely with peers where subject matter expertise is required.
Organizationally astute, with superior influencing, collaboration, and communication skills.
Experience assessing risk and challenging the status quo.
Proven ability to foster a cohesive team and promote a positive, high performing work environment.
Expertise in working effectively in teams – requires a track record of knowledge across the organization.
Strong analytical skills, including segment risk analysis, data analysis, and comparative analysis.
In order to provide effective oversight and independent challenge the role requires the candidate to have a good understanding of the following areas:
Risk management frameworks and methodologies;
Cybersecurity frameworks, operations, processes, controls, and tools;
Technology operations and processes;
Infrastructure and application security domains;
Cloud service provider management, and;
Regulatory requirements.
Strong business and financial acumen.
Education & Accreditation This role requires successful completion of all three levels of TD Operational Risk Management certification. Certification is not a requirement to apply for this role. The successful candidate will have 12 months from the start date in the role to complete required certifications. The required courses are available internally through TD Operational Risk Management.
Undergraduate degree in Computer Science/Computer Engineering/Risk Management is an asset.
Accreditation such as CISSP, CCSP, CISA, CISM, CRISC, and/or similar is preferred.
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×