Director, Cloud Security

3 weeks ago


Candiac, Canada Scotiabank Full time

Requisition ID: 210242

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

The Director, Cloud Security will lead and oversee Cloud Security within Global Risk Management (GRM) globally ensuring business strategies, plans and initiatives are executed and delivered in compliance with governing regulations, internal policies, procedures with an understanding of industry frameworks/regulations/standards like CSA STAR, ISO, NIST, OWASP, OSFI etc in scope of cloud security.

Leads a second line of defense team to oversee and monitor cloud security, architecture and design with a focus on data risk management programs (i.e data protection). The role will partner closely with cross functional teams in the Bank including data risk management, security, devOps, infrastructure, network and technology teams to evolve foundational and transformational security and data risk management strategy for cloud across the enterprise.

Is this role right for you? In this role, you will:

  1. Lead and drive a customer focused culture throughout your team to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  2. Drive security and compliance of the Bank’s cloud environments, while also providing strategic guidance and implementation of a comprehensive second line of defense over key components in cloud, including security, data protection, and architecture (both technical and data).
  3. Partner with key stakeholders to oversee and monitor enterprise aligned cloud strategic framework as well as assess design and provide architectural advice on how to securely develop and build applications and supporting infrastructure.
  4. Develop programs to enable the identification of cloud cyber security and IT risks, by providing compliance and oversight in the form of frameworks, policies, tools, and techniques to support risk and compliance management.
  5. Challenge the creation of secure reference architectures, frameworks, policies and patterns for the security aspects of the SDLC including application, mobile, infrastructure, DevOps, cloud, and CI/CD pipelines.
  6. Govern cloud security practices at Scotiabank to enable cloud acceleration in a secure manner. Assess security controls, requirements, architecture and tooling to manage the security posture and secure workloads to support Bank’s cloud migration.
  7. Support a continuously evolving holistic cloud security strategy covering the various cloud deployment models – SaaS, PaaS and IaaS.
  8. Monitor and report on the effectiveness of security controls and make recommendations for improvement.
  9. Understand how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
  10. Create an environment in which your team pursues effective and efficient operations of their respective areas in accordance with Scotiabank’s Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  11. Build a high performance environment and implement a people strategy that attracts, retains, develops and motivates your team by fostering an inclusive work environment and using a coaching mindset and behaviours; communicating vision/values/business strategy; and managing succession and development planning for the team.

Do you have the skills that will enable you to succeed in this role? We’d love to work with you if you have experience with:

  1. University degree, preferably in Computer Engineering, Computer Science or related field, and a minimum of 10 years’ experience in increasingly senior Information Security roles in a complex, global organization.
  2. 3+ years of experience developing, implementing and maintaining security solutions in public cloud like GCP, Azure or AWS. Extensive understanding of cloud infrastructure and services.
  3. Experience leveraging CI/CD deployment methodologies and infrastructure as code (IaC).
  4. Financial services and, specifically, banking experience is mandatory.
  5. Experience in driving cross functional senior executive steering committees with a global presence.
  6. Experience in developing and managing multi-million business cases for strategic initiatives.
  7. Expertise in product/application security architecture, application security, cloud SaaS/PaaS/IaaS solutions.
  8. Understanding of application and product architectures, programming languages, web application stacks, and SDLC pipelines.
  9. Excellent written and verbal communication skills, with the ability to communicate security objectives and concepts to technology and business teams to technical and non-technical stakeholders.
  10. Ability to lead technical teams in a highly complex and matrixed organization. Ability to lead through influence, excellence and example is essential to success.
  11. Strong leadership and collaboration skills. Excellent oral and written communication, ability to present confidently to senior executives, attention to detail and strong planning and management ability.
  12. Deep and broad knowledge of enterprise, cloud, and security technologies is expected. Specific strong knowledge and experience with common hosting, storage, and networking technologies is required. Experience with Workload Protection and Posture Management products is an asset.
  13. Experience with and knowledge of formal project management methodologies is desired.
  14. English fluency required and Spanish preferred.

What's in it for you?

  1. The opportunity to join a forward-thinking and collaborative team, surrounded by innovative thinkers.
  2. A rewarding career path with diverse opportunities for professional development.
  3. Internal training to support your growth and enhance your skills.
  4. An inclusive working environment that encourages creativity, curiosity, and celebrates success
  5. Work in an Ecosystem; a bright, modern space where you’ll have access to group seating, offices, collaboration spaces, a cafeteria with different options daily, a bistro, and more.

Location(s): Canada : Ontario : Toronto

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

#J-18808-Ljbffr

  • Candiac, Quebec, Canada Scotiabank Full time

    **Job Summary**We are seeking a seasoned Cloud Security Director to lead our cloud security efforts globally. As a key member of our Global Risk Management team, you will be responsible for overseeing cloud security and ensuring compliance with regulatory requirements.**Key Responsibilities** Develop and implement cloud security strategies to protect our...


  • Candiac, Quebec, Canada Scotiabank Full time

    Job Description:The Cloud Security Director will lead the Cloud Security function within Global Risk Management (GRM) globally, ensuring business strategies, plans, and initiatives are executed and delivered in compliance with governing regulations, internal policies, and procedures with an understanding of industry frameworks/regulations/standards like CSA...


  • Candiac, Quebec, Canada Security Compass Full time

    Secure Your Future with UsSector: CybersecurityAbout the Role:We are seeking a seasoned Cloud Engineering Lead to spearhead the deployment and management of our flagship product SD Elements on Kubernetes for enterprise customers. As a key member of our Engineering Operations department, you will be responsible for designing, implementing, and maintaining...


  • Candiac, Quebec, Canada Scotiabank Full time

    The Director, Cloud Security will lead and oversee Cloud Security within Global Risk Management globally ensuring business strategies, plans and initiatives are executed and delivered in compliance with governing regulations, internal policies, procedures with an understanding of industry frameworks/regulations/standards like CSA STAR, ISO, NIST, OWASP, OSFI...


  • Candiac, Quebec, Canada Sun Life Full time

    Job SummaryAre you an experienced security professional seeking a challenging role in cloud security? We have an exciting opportunity for a Cloud Security Professional to join our team at Sun Life. As a key member of our security platform team, you will be responsible for planning, deploying, and managing a diverse range of security technologies to protect...


  • Candiac, Quebec, Canada Jungle Scout Full time

    About the RoleWe are seeking a highly skilled Cloud Security Engineer to join our fast-paced Engineering team at Jungle Scout. As a Cloud Security Engineer, you will play a critical role in designing, implementing, and maintaining secure and efficient AWS environments.Key ResponsibilitiesDesign and implement multi-account AWS environments that promote...


  • Candiac, Canada Jungle Scout Full time

    Jungle ScoutThe leading all-in-one platform for selling on Amazon, with the mission of providing data & insights to help entrepreneurs and brands grow their businesses.At Jungle Scout, we are on a mission to build the best Amazon competitive intelligence tools for Amazon sellers and brands.The RoleDo you enjoy solving complex challenges related to cloud...


  • Candiac, Quebec, Canada Jungle Scout Full time

    Job Title: Cloud Security EngineerAbout the Role:We are seeking a skilled Cloud Security Engineer to join our Engineering team at Jungle Scout. As a Cloud Security Engineer, you will be responsible for designing, implementing, and maintaining secure AWS environments for our customers.Key Responsibilities:Design and implement secure AWS environments,...


  • Candiac, Canada Jungle Scout Full time

    Jungle ScoutThe leading all-in-one platform for selling on Amazon, with the mission of providing data & insights to help entrepreneurs and brands grow their businesses.At Jungle Scout, we are on a mission to build the best Amazon competitive intelligence tools for Amazon sellers and brands.The RoleDo you enjoy solving complex challenges related to cloud...


  • Candiac, Quebec, Canada CIBC Full time

    Job DescriptionWe are seeking a skilled Cloud Security Expert to join our Technology Risk Management team at CIBC.About the Role:Lead and contribute to the development and execution of the annual Audit Plan for Technology risk, focusing on cloud security.Provide consultation to other Internal Audit teams and train, guide, and mentor auditors in areas of...


  • Candiac, Quebec, Canada Jungle Scout Full time

    Unlock Your Potential in Cloud SecurityJungle Scout is a leading all-in-one platform for selling on Amazon, with the mission of providing data insights to help entrepreneurs and brands grow their businesses.We are committed to building the best Amazon competitive intelligence tools for Amazon sellers and brands.The RoleWe are seeking an experienced Cloud...


  • Candiac, Canada Manulife Full time

    Director Strategy Information Security and Risk ManagementManulife is a leading financial services group. We provide financial advice, insurance, as well as wealth and asset management solutions for individuals, groups and institutions.This role offers an exceptional opportunity to lead and shape our information security and risk management strategies as the...


  • Candiac, Canada Manulife Full time

    Director, Information Security and Risk ManagementManulife is a leading financial services group. We provide financial advice, insurance, as well as wealth and asset management solutions for individuals, groups and institutions.This role offers the opportunity to lead our information security and risk management efforts as the Director of Information...


  • Candiac, Quebec, Canada Manulife Full time

    Director, Information Security and Risk ManagementWe are a leading financial services group providing comprehensive solutions for individuals, groups, and institutions.This role offers the opportunity to lead our information security and risk management efforts as the Director of Information Security and Risk Management. By developing and implementing a...


  • Candiac, Canada Manulife Full time

    h3>Director, Information Security and Risk ManagementManulife is a leading financial services group. We provide financial advice, insurance, as well as wealth and asset management solutions for individuals, groups and institutions.This role offers the opportunity to lead our information security and risk management efforts as the Director of Information...


  • Candiac, Quebec, Canada KUBRA Full time

    About the RoleWe are seeking an experienced Senior Security Architect to join our Information Security team at KUBRA. As a key member of the team, you will be responsible for providing technical guidance and consultation in designing, optimizing, and maintaining a secure computing environment. This will involve ensuring that security standards are met,...


  • Candiac, Canada KUBRA Full time

    KUBRAWe provide customer experience solutions to help companies engage with their customers through multiple channels. Discover our suite of services today.KUBRA is looking for a Senior Security Architect to join our Information Security team! As a Senior Security Architect, you will be responsible for providing technical guidance and consultation in...


  • Candiac, Quebec, Canada Security Compass Full time

    Transformative Solutions with Security CompassWe at Security Compass are pioneers in creating a secure digital landscape where technology and trust coexist harmoniously. Our mission is to empower organizations to build robust cybersecurity solutions without hindering business growth.This is where you come in – as a Senior DevOps Software Engineer, you will...


  • Candiac, Quebec, Canada SAP Full time

    SAP is seeking a skilled Product Security Specialist to join our team. The ideal candidate will have a strong background in software security and the ability to work collaboratively with cross-functional teams to identify and address security risks.Key Responsibilities:Collaborate with security experts and engineering teams to integrate security practices...


  • Candiac, Canada Scotiabank Full time

    p>The Director, Cloud Security will lead and oversee Cloud Security within Global Risk Management (GRM) globally ensuring business strategies, plans and initiatives are executed and delivered in compliance with governing regulations, internal policies, procedures with an understanding of industry frameworks/regulations/standards like CSA STAR, ISO, NIST,...