Work Location:Toronto, Ontario, Canada
Hours:37.5
Line of Business:Risk Management
Pay Details:$115,600 - $163,200 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:Job DescriptionSegment Risk Specialist - Technology and Cyber and Risk ManagementThe Segment Risk Specialist will partner with 2A Segments team, 2A TDRM enterprise and the First line of defense to oversee and challenge the execution of risk management activities and leading practices/technologies used to keep up with the constantly evolving technology and cyber threat landscape.
Reporting to the 2A ORM Segment AVP, Segment Risk Specialist Management, this role will have the following accountabilities:
• Senior specialist providing
advisory services to executives, business segment leaders, and governs requirements for own work.• Integrates knowledge of the enterprise function's or business segment's strategy in leading program design, policy formulation, or operating standards.
•
Anticipates emerging business trends and regulatory/risk issues to recommend large-scale products, technical, functional, or operations improvements.•
Serves as a source of expert advice to senior management and team colleagues• Advises on execution strategy and leads development/deployment of functional programs or initiatives within own field or across multiple specialties.
• Solves unique and ambiguous problems with broad impact.
• Execute 2nd line challenge activities required to support the ORM Framework, including but not limited to:
• Review and escalate Segment Technology and Cyber
RAS Measure limit & excesses and report Segment CRO and Senior Management
• Support 2A Segment in the Review and Challenge of the
PRCSA / RCSA;
• Technology and cyber scenario analysis;
• Challenge the design and operating effectiveness testing performed by the first line on the segment for Tech, Cyber,
• Key Risk Indicators
(KRI),- Adhere to enterprise frameworks or methodologies that relate to activities for our business area;
- Ensure respective programs/policies/practices are well managed, meets business needs, complies with internal and external requirements, and aligns with business priorities;
- Review and escalate Segment RAS Measure limit & excesses and report to Segment CRO and Senior Management
- Challenge the design and operating effectiveness testing performed by the first line on the segment for Tech, Cyber and Data; and;
• Segment
Deep Dives or Segment Target Reviews
• Other areas as appropriate to support technology and cyber in risk management.
• Effectively communicate risk management practices and methodologies and results of risk assessments to Executive and senior management in a supportive and collaborative manner and influence risk-based remediation.
• Quality writing and maintaining enforceable technology policies with "must" statements
• Be a positive team player to consistently maintain high levels of integrity, motivation, and morale.
Job Requirements - Bachelor's degree from a recognized university or equivalent experience.
- At least 10+ years of relevant experience within the Financial Services industry that includes 1st / 2nd line Technology & Control Function
- Experience in Operational Risk Management (2nd line ORM)
- Experience in operating in and engaging with technical SMEs across a range of topics including Incident Management, Change Management, Problem Management and technical Control Standards.
- A high level awareness of regulatory and Controls requirements: FFIEC, OCC 1042, OSFI B-10/B-13/E-21, GLBA 501(b), PCI, FFIEC, SOX, HIPAA, COBIT, ISO 27001/22301 and NIST standards.
- Aligning firm-wide control domains to frameworks (e.g., NIST → ITGC → RCSA mapping).
- Ability to work in ambiguity must be flexible to deal with changes in a fast paced and new environment, working closely with peers where subject matter expertise is required.
- Organizationally astute, with superior influencing, collaboration, and communication skills.
- Experience assessing risk and challenging the status quo and break silos.
- Strong analytical skills, including segment risk analysis, data analysis, and comparative analysis.
- In order to provide effective oversight and independent challenge the role requires the candidate to have a good understanding of the following areas:
- Risk management frameworks and methodologies;
- Cybersecurity frameworks, operations, processes, controls, and tools;
- Technology operations and processes;
- Infrastructure and application security domains;
- Change & Configuration Management;
- Technology Resilience (HA, DR, RTO/RPO, backup immutability);
- IT Asset Management & Lifecycle Governance;
- Logging, Monitoring, and Observability Tools;
- Trend & Root Cause Analysis;
- Continuous Control Monitoring (CCM) Logic;
- Cloud service provider management;
- Audit & Regulatory Engagement, preparing management responses and evidencing control coverage.
Education & Accreditation - This role requires successful completion of all three levels of TD Operational Risk Management certification. Certification is not a requirement to apply for this role. The successful candidate will have 12 months from the start date in the role to complete required certifications. The required courses are available internally through TD Operational Risk Management.
- Undergraduate degree in Computer Science/Computer Engineering/Risk Management is an asset.
- Accreditation such as CISSP, CISM, CISA, CDPSE, AAIA and CRISC and/or similar is preferred.
Language Requirement (Quebec only):Sans Objet