Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

Td Bank Senior Information Security Specialist GCP Architecture 
Canada, Ontario, Toronto 
671859750

17.04.2025
Toronto, Ontario, CanadaTechnology Solutions

$108,800 - $163,200 CAD


About This Role:

We are seeking a highly skilled and experienced Senior Information Security Specialist to join our Public Cloud Security Governance team, focusing primarily on Google Cloud Platform (GCP) security architecture. Reporting to the AVP, you will be a key contributor and advocate in shaping and implementing robust security controls and practices for TD’s public cloud environment. You'll provide specialized expertise and guidance on assessing risks, identifying potential gaps, and developing innovative security solutions to protect our critical assets within GCP and across other major cloud platforms. This role requires a proactive individual with a deep understanding of cloud-native security principles and the ability to influence technical direction at both a tactical and strategic level. You will be instrumental in developing and maintaining technology controls and information security related policies, programs, and tools, ensuring alignment with industry best practices and regulatory requirements.

Key Responsibilities:

  • GCP Security Architecture & Hardening: Develop, maintain, and enforce information security hardening standards and procedures specifically tailored for GCP environments (Compute Engine, Kubernetes Engine, Cloud Storage, etc.), aligning with industry best practices (CIS Benchmarks, NIST), regulatory requirements , and TD’s internal policies.
  • Cloud Security Engineering: Design and implement secure cloud architectures, incorporating security controls throughout the development lifecycle – frominfrastructure-as-codeto application deployment. Experience with Infrastructure as Code tools like Terraform or CloudFormation is essential.
  • DevSecOps Integration: Champion and integrate DevSecOps principles into our CI/CD pipelines, automating security testing (SAST, DAST, IAST), vulnerability scanning, and configuration management. Experience with container security technologies (e.g., Aqua Security, Wiz, Chainguard) is a strong asset.
  • Compliance & Governance as Code: Lead the implementation of compliance and governance controls using code-based approaches to ensure consistent enforcement across our cloud environments.
  • Security Tooling & Automation: Understand, evaluate, and provide technical insights on security tools and technologies within the GCP ecosystem (e.g., Cloud Security Command Center, Chronicle). Be the orchestrator between governance andoperations/engineeringto streamline security operations and improve efficiency.
  • Collaboration & Influence: Collaborate closely with engineering, DevOps, and architecture teams to translate business requirements into secure technical solutions. Provide guidance and mentorship on cloud security best practices. You will influence compliance and governance as code operations for infrastructure security, ensuring alignment across multiple teams.
  • Documentation & Communication: Create clear, concise documentation for various audiences, including technical teams, business stakeholders, and leadership. You will analyze new information, consolidate content into user-centric documents for various personas, embracing an agile working environment with complex, fast-paced projects.
  • Guidance & Mentorship: Guide partners on a broad range of specific Technology Controls and Information Security programs, policies, standards, and incidents. You’ll also contribute to the review of internal processes and activities, identifying opportunities for improvement.
  • Risk Management & Culture: Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology and security threats against TDBG’s business. You will influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
  • Emerging Technologies: Stay abreast of emerging security threats, vulnerabilities, and technologies within the public cloud space (including Azure and AWS) and proactively incorporate mitigating controls into our hardening standards.

Job Requirements:

What can you bring to TD? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention. It helps if you have:

  • University Degree in Computer Science, Information Security, or a related field.
  • Information Security Certification / Accreditation (e.g., CISSP, CCSP, GCP Professional Cloud Security Engineer) –
    highly preferred
    .
  • 8+ years of relevant experience in information security with a significant focus on public cloud environments.
  • Deep expertise and hands-on experience securing Google Cloud Platform (GCP) including IAM, VPCs, Kubernetes Engine (GKE), Cloud Storage, BigQuery, and related services.
  • Experience securing workloads across multiple cloud platforms – AWS and Azure experience is a significant asset.
  • Strong understanding of DevSecOps principles and practices, with experience integrating security into CI/CD pipelines.
  • Proficiency in scripting languages (e.g., Python, Bash) for automation purposes.
  • Experience with Infrastructure as Code tools (e.g., Terraform, CloudFormation).
  • Solid knowledge of common security frameworks and standards (e.g., NIST CSF, CIS Controls, ISO 27001).
  • Demonstrated ability to lead complex projects and initiatives, influencing technical direction and driving adoption of secure practices.
  • Excellent written and verbal communication skills with the ability to articulate technical concepts to both technical and non-technical audiences.



Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.

If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.


We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.


Sans Objet