×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Principal Digital Platforms; Global Security

Job in Toronto, Ontario, C6A, Canada
Listing for: RBC
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 190000 CAD Yearly CAD 140000.00 190000.00 YEAR
Job Description & How to Apply Below
Position: Senior Security Principal Digital Platforms (Global Security)

What is the opportunity?

RBC is seeking a Senior Security Principal Digital Platforms (Global Security) to be the embedded security accountability owner within our digital development. You will hold direct accountability for translating enterprise security policy, regulatory obligations, and threat intelligence into engineering-actionable requirements at the point of design and delivery, with authority to elevate and withhold release sign-off when necessary. The Senior Security Principal Digital Platforms will guide digital development teams on security strategy, adoption of secure design patterns, and ensure the organization delivers client-facing platforms that meet regulatory requirements and security standards.

Job Description

RBC is seeking a Senior Security Principal Digital Platforms (Global Security) to be the embedded security accountability owner within our digital development. You will hold direct accountability for translating enterprise security policy, regulatory obligations, and threat intelligence into engineering-actionable requirements at the point of design and delivery, with authority to elevate and withhold release sign-off when necessary. The Senior Security Principal Digital Platforms will guide digital development teams on security strategy, adoption of secure design patterns, and ensure the organization delivers client-facing platforms that meet regulatory requirements and security standards.

What

will you do?
  • Sit embedded inside digital development teams' planning cadence as the named security risk owner, with accountability for platform risk registers, threat modeling outcomes, and incident retrospectives
  • Shift security left by resolving threat modeling, secure design patterns, and control requirements at design review - not at pre-production gates, and own the exception process with time-boxed remediation commitments
  • Protect our client trust surface by owning authentication/session integrity, fraud-security control alignment, API/partner integration security, and client data handling across retail, commercial, and wealth platforms
  • Translate OSFI B-13, NYDFS Part 500, and PIPEDA/CPPA regulatory obligations into concrete engineering requirements and evidentiary artifacts produced during normal delivery
  • Review AI-assisted and agentic client-facing capabilities against enterprise NHI and agentic trust architecture standards prior to client exposure
  • Exercise escalation authority to withhold release sign-off pending remediation or documented risk acceptance at appropriate governance tiers
  • Maintain a platform-level risk and control-maturity scorecard feeding enterprise board security reporting, translating technical findings into business-risk language for CRO/CIO/Legal audiences
  • Influence and secure engineering commitment across teams outside your direct reporting line, driving security accountability into development velocity
What do you need to succeed? Must-have
  • 7-10+ years in cybersecurity with at least 5 years bridging security and software/product engineering
  • Demonstrated ability to operate inside agile/product development environments—fluent in sprint planning, backlog grooming, and release activities
  • Proven expertise in application and API security, secure SDLC, threat modeling methodologies (e.g., STRIDE), and cloud-native architecture patterns
  • Direct experience with digital banking or regulated client-facing financial platforms, including payments, authentication, and fraud-adjacent controls
  • Working knowledge of OSFI B-13, NYDFS 23 NYCRR Part 500, and PIPEDA/CPPA, with ability to translate regulatory requirements into engineering solutions independently
Nice-to-have
  • Prior exposure to wealth management platforms, advisor identity risk, and high-net-worth data sensitivity
  • Familiarity with open banking/API partner ecosystems, AI/agentic system security, or multi-jurisdictional regulatory experience (Canada/U.S.)
What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to…

Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary