Toronto, Ontario, CanadaTechnology Solutions
$91,200 - $136,800 CAD
Job Description:
- The Information Security Manager main function is to be the product owner for the Security Compliance
- Management Pod and is accountable for ensuring the planning, execution and improvement and security
- compliance operations processes. These processes include cover cloud security, infrastructure security and
- cyber technology compliance. The role reports to the Senior Manager, Security Compliance and Operations
- Management (SCOM) and works within the larger Crypto, Cloud and Infrastructure Security (CICS), team.
Roles and Responsibilities
- · Manage team of Information Security Analysts and Business Systems Analysts to complete security
- compliance management and operations processes.
- · Responsible for working with Information Security Specialists to ensure their assigned domains (Cloud,
- Infrastructure, Cyber Technology) are aligned with over POD operations and strategy. Act as a liaison
- for each domain to the Senior Manager, Security Compliance and Operations management.
- · Accountable for the execution of the daily, weekly, and monthly Security compliance operations
- processes, including monitoring, triage, notification, issue tracking and escalation of non-compliance
- issues.
- · Accountable for creating and maintaining processes documents that include RACIs, processes flows
- and descriptions of tasks performed.
- · Responsible for receiving escalations and engaging technology teams responsible for addressing non-
- compliance using multiple communication methods such as ServiceNow tickets, emails, instant
- messaging, or phone call.
- · Accountable for tracking responses from technology teams and producing timely updates on status of
- remedation efforts. Escalate tickets breaching SLA to technology owners and leadership.
- · Accountable for ensuring there is operational reporting on a weekly and monthly basis that includes
- KRIs, KPIs and commentary on trends. Develop new reporting methods, dashboards and reports.
- · Accountable for developing requirements for automation and implement improvements to improve
- operational efficiency.
- · Responsible for developing KPIs for team operations and developing plans to ensure they are met.
- · Responsible for providing senior managers, and senior executives with updates on security compliance
- management processes, and tailoring updates dependent on the audience. This reporting includes key
- metrics successes, risks, and roadblocks within the program.
- · Responsible for ensuring pod is adhering to TD's and CICS' agile framework. Lead Program Increment
- planning, maintaining work backlog and quarterly plan in JIRA. Manage pod capacity and workload.
- · Develop security compliance operations strategy and target state operating models · Support direct reports career development plans and adhere to TD's share commitments as a people manager. Maintain and improve team culture.
Qualifications
- A University or post-Graduate degree in Information Technology, Computer Science, Computer Engineering, or a related discipline is an asset. ·
- Min 7+ years' experience in working in Cyber Security / Information Risk Management, preferably in an operations role (Compliance Management, SOC, Vulnerability Management, Security Tools Operations, DevSecOps).
- Excellent written and oral communication skills. Ability to convey detailed technical information into summarized business language. ·
- Excellent people management skills. · Ability to coordinate a team work to ensure an adequate workload to team members depending on their skills, knowledge and performance. ·
- Expert knowledge of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, cloud, application and networking environments. ·
- Experience and knowledge of cloud security in one or more cloud platforms (AWS, GCP, Azure) ·
- Experience and knowledge of endpoint and network security technologies and controls (Endpoint Threat Detection, DDOS, WAF etc.) ·
- Organizational and self-directing skills – ability to initiate, coordinate and prioritize responsibilities and follow through on tasks to completion. ·
- An approach to work that includes initiative, sound judgment, diplomacy and Discretion. ·
- Advanced problem Solving / Analytical Thinking Skills. · Ability to work independently on a variety of assignments with minimal supervision. ·
- Ability to work without supervision with senior managers, supervisors, VIPs and Users. ·
- Ability to perform analysis and reporting on information from multiple data sources using data mining technique for the purpose of documenting analysis results, produce report and present to technical and executive stakeholders. ·
- Demonstrate expertise in Enterprise IT operations, incident management, change management, Access/Identity Management, Security Operations, vulnerability and compliance management, ticketing system, incident ticket life cycle and SLA terms ·
- Experience working within Agile framework and using JIRA. · Experience with ServiceNow and Splunk. Certifications: ·
- Completion of at least three of the following: GIAC (GCIA, GPEN, GWAPT, GCIH, GSEC and etc), CCNP, CCNA, CISSP,CCSP, CISM, CIS
- #LI-Tech
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.
Sans Objet