Location Address: Hybrid – Scarborough and Downtown Toronto – rotation between both – 2x/week (Tuesdays/Thursdays) – need candidates in GTA who can go to both locations
Contract Duration: 1 year
Possibility of extension & conversion to FTE
Number of Positions: 1
Schedule Hours: 9am-5pm Monday-Friday; standard 37.5 hrs/week
Reason: Additional Workload
Typical Day in Role:
• Develop and execute a framework for risk and audit issues management, including the creation Participate in initiatives and projects driven by various business lines. Guide project and delivery managers to design and establish sound information security practices, facilitating key artifacts such as security design documents, threat/risk assessments and data classifications with the owner to ensure that risk is identified and effectively managed.
• Provide first line subject matter expert advice on pervasive Bank's information security standards, policies and processes, information security world class standards and major regulations in the industry.
• Liaise with internal and external security teams, local and international, and participate in reviews that pertain to compliance with Bank and Regulatory IT security controls and guidelines.
• Work with our business line partners to assess risk and avoid deviations to Bank standards; where possible, identifying secure solutions. When unavoidable, escalate deviations or risk acceptance requests through appropriate channels.
Candidate Requirements/Must-Have skills:
1. 10+ years of working experience as an IT Security Analyst / Security Advisor
2. 5+ years’ recent hands-on experience with cloud security controls and experience in deployments and cloud architecture security (GCP and Azure preferred)
3. 5+ years’ hands-on experience with security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and networking environments
4. 5+ years’ combined experience with security technologies such as: Identify & Access Management, PKI, Intrusion Prevention, vulnerability assessments (any are OK please list which)
5. 5+ years’ experience with regulatory guidelines related to the financial industry like OSFI.
Nice-To-Have Skills:
1. Experience with/knowledge of financial services’ Security Governance Framework (policies and standards) is a strong asset.
2. Experience with Agile, Lean, Rapid Labs and other accelerated project frameworks would be an asset.
3. Security Certifications: CISSP, CCSP, GSEC, CISA, CISM, etc.
4. Experience in Canadian banking
Soft Skills:
• Must have advanced verbal and written communication skills in English, especially report writing ability.
• Proven ability to meet deadlines for multiple assignments and adapt quickly to changing priorities.
Education:
• College or university degree in Computer Sciences, Information Systems/Security or technical equivalent.
• Security Certifications: CISSP, CCSP, GSEC, CISA, CISM, etc. nice to have
Candidate Review & Selection
• 1st round MS Teams interview – Hiring manager + 2 team members (30 minutes)
• 2nd round MS Teams interview – Hiring manager + Global head (30 minutes)
• Candidate should be prepared to discuss their working experience/projects and how it relates to the job requirements. Assess both technical and soft skills.