Information Risk and Security Engineer

4 weeks ago


Old Toronto, Canada Scotiabank Full time
Title: Information Security Engineer (Cryptographic Operations)

Requisition ID: 211887

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Cryptographic Operations is a unit within Scotiabank’s Information Security & Control (IS&C) that provides services including HSM engineering, key and secret management, certificate management, etc. The team is purposefully formulated with the correct expertise to align with IT&S Strategic goals. Strong investments have been focused on automation and research into industry-leading cryptographic tools to meet Technology Enabler initiatives such as Improving Productivity and Modernizing to Win enabling the Bank to safely conduct business transactions in high-risk environments deployed over core business delivery channels that are global in scope.

Key Accountabilities for Information Security Engineer:

  1. Deliver Cryptographic HSM solutions and services across the enterprise by partnering with internal and external stakeholders.
  2. Provide second-line support of HSM and Key Management technologies, participating in the team’s 24/7 standby schedule.
  3. Actively review and action requirements for patching, maintaining supportable HW and SW versions, currency lifecycle management inclusive of obsolescence planning, service ownership, reporting and resolving of Audit findings.
  4. Responsible for creation and upkeep of all HSM inventories, documentation, knowledge base and checklist.
  5. Participate in HSM incident response investigations and escalations on HSM infrastructure, cross-functionally with other teams to deliver best in class service and operational effectiveness.
  6. Attend and participate onsite with audited key ceremonies at the Crypto Production Center located in Scarborough ON when required.
  7. Champion a customer-focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  8. Champion a high-performance environment, embracing Scotiabank’s values and contributing to an inclusive work environment.
  9. Participate in project activities for critical applications requiring managed cryptographic keys and integration with secure key storage solutions.
  10. Accountable for managing day 2 intake by reviewing, assessing, and delivering.

Qualifications:

Must Have:

  1. Strong knowledge in server administration (Linux and Windows).
  2. Related University degree or college diploma (computer science, engineering, and other related majors) and a minimum of three (3) years equivalent security industry-related experience.
  3. Ability to generate reports and tailor communication strategies for various levels of technical staff and executive management.
  4. Good communication and support skills for triaging and resolving technical issues.
  5. Demonstrable knowledge about cryptography and network security.

Nice to have:

  1. HSM experience with strong knowledge in implementation (installation, configuration, integration) and enterprise-grade application support.
  2. Expertise and experience with General and Payment grade HSM technology e.g. Thales Luna, Atalla, Futurex, nShield, & Marvell Liquid Security.
  3. Knowledge and experience with Service NOW and ITIL processes, incident response.
  4. IT standards, methodologies, key management regulations, and audit requirements.
  5. Proven security and risk awareness (i.e., CISSP or any other security designations would be an asset).
  6. Software development and scripting experience.

Location(s): Canada : Ontario : Toronto

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation during the recruitment and selection process, please let our Recruitment team know. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

#J-18808-Ljbffr

  • Old Toronto, Canada Delphi Resort Full time

    Information Security Engineer (Cryptographic Operations)Requisition ID: 211887Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Cryptographic Operations is a unit within Scotiabank’s Information Security & Control (IS&C) that provides services including HSM engineering, key and secret management,...


  • Old Toronto, Canada Scotiabank Full time

    Requisition ID: 211887Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Cryptographic Operations is a unit within Scotiabank's Information Security & Control (IS&C) that provides services including HSM engineering, key and secret management, certificate management, etc. The team has enterprise-wide...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job Responsibilities:Plan, coordinate, and direct all information security tasks within the area of responsibility to meet the global and local security goals.Support all security incidents of the location with alignment to the incident management process.Work with the Procurement and Legal departments to review and screen suppliers.Lead IT/security...


  • Old Toronto, Canada GeoComply Full time

    h3>Chief Information Security Officer (Toronto, ON)GeoComply provides geolocation compliance, fraud prevention, and cybersecurity solutions that detect location fraud and verify a customer’s true digital identity.Key Leadership ResponsibilitiesSet and execute the global cybersecurity vision, aligning security initiatives with GeoComply’s business...


  • Old Toronto, Canada Athennian Group Full time

    Athennian increases trust in business. Our products help legal, finance, and tax teams be transaction and audit-ready by organizing business entity and corporate structure information. Over 370,000 business entities in almost every country are managed on Athennian to automate workflows for ownership, company secretarial, governance, tax, and compliance.We...


  • Old Toronto, Canada Ezra Full time

    p>Job Role: IT Security, Risk and Compliance Manager - EZRA Location: Toronto, Canada – Hybrid (3 days per week in office) Who we are Ezra is the fastest-growing global virtual coaching company, supporting some of the world’s leading companies. p>The primary purpose of the role is to support the Head of IT Security Risk and Compliance to ensure the...


  • Old Toronto, Canada GeoComply Full time

    We are at the forefront of geolocation, cybersecurity, and anti-fraud innovation, developing and delivering cutting-edge technologies to help ensure regulatory compliance, combat bad online actors, alleviate user friction, and protect businesses from fraud.Achieving significant business and revenue growth over the past three years and dubbed a tech...


  • Old Toronto, Canada Natural Factors Full time

    We are at the forefront of geolocation, cybersecurity, and anti-fraud innovation, developing and delivering cutting-edge technologies to help ensure regulatory compliance, combat bad online actors, alleviate user friction, and protect businesses from fraud.Achieving significant business and revenue growth over the past three years and dubbed a tech...


  • Old Toronto, Canada Knightsbridge Solutions, L.L.C. Full time

    p>Job Role: IT Security, Risk and Compliance Manager - EZRALocation: Toronto, Canada – Hybrid (3 days per week in office)Who we areImagine what even the world’s finest organizations could achieve if all of their employees were coached to be their absolute best. We believe, through coaching, people get to know themselves, their goals, weaknesses, and...


  • Old Toronto, Canada Sun Life Financial Full time

    About UsSun Life Financial is a leading international financial services company dedicated to helping our clients achieve their financial goals. We pride ourselves on being a trusted partner, providing innovative solutions and exceptional service to individuals, families, and communities around the world.Salary and BenefitsWe offer a competitive salary of...


  • Toronto, Canada Manulife Full time

    This role offers the opportunity to lead our information security and risk management efforts as the Director of Information Security and Risk Management. By developing and implementing a comprehensive vulnerability management program, updating security policies, and driving security awareness initiatives, you will directly contribute to our mission of...


  • Old Toronto, Canada Manulife Insurance Malaysia Full time

    Director Strategy Information Security and Risk ManagementThis role offers an exceptional opportunity to lead and shape our information security and risk management strategies. Reporting to the Information Security and Risk Management Officer, you will collaborate with the Global Risk and Security team to align cybersecurity plans with organizational...


  • Old Toronto, Canada Scotiabank Full time

    Job OverviewA challenging opportunity has arisen for a seasoned information security professional to join Scotiabank as a Senior Audit Manager, Risk Management. This role requires a high level of expertise in leading and conducting risk-based audit assessments of medium to high complexity.About the RoleThe successful candidate will be responsible for...


  • Toronto, Canada Infotek Consulting Services Inc. Full time

    Infotek Consulting Services Inc. is seeking an experienced Information Security Risk Manager for a hybrid contract assignment based in Toronto.Salary Range: $80,000 - $120,000 per annumJob DescriptionThe US cybersecurity and IT risk team oversees and advises on cybersecurity and IT risk matters in the US, ensuring the bank's security controls are aligned...


  • Toronto, Canada Munich Re Full time

    The Information Security Risk Manager (ISRM), as part of the Enterprise Risk Management team is the second line of defense for Cyber Security covering Munich Re’s Life and Health North America (LHNA) entities. The ISRM supports the identification, prioritization, communication, and monitoring of cyber security risks in the Life and Health North America...

  • Group Risk Specialist

    4 months ago


    Toronto, Canada TD Bank Full time

    **Work Location**: Canada **Hours**: 37.5 **Line of Business**: Risk Management **Pay Details**: **Department Overview** **The independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of operational risk across the enterprise.** **The...


  • Old Toronto, Canada Canada Mortgage and Housing Corporation Full time

    Canada Mortgage and Housing Corporation (CMHC) is a leading organization in the field of housing finance. We are seeking a highly skilled Risk Management Specialist - IT Security to join our team.**Job Summary:**The successful candidate will be responsible for assessing and interpreting data to determine the level of risk and other indicators of risk,...


  • Old Toronto, Canada CNA Insurance Full time

    At CNA Insurance, we offer a comprehensive portfolio of property and casualty business insurance solutions that empower businesses to manage risks effectively and drive growth.Job Description:This role is an individual contributor responsible for leading numerous engineering workflows, providing customized security consultations to project teams, and serving...


  • Toronto, Ontario, Canada Randstad Full time

    Job OverviewWe are seeking an experienced Information Security Risk Specialist to join our team at Randstad. As a key member of our organization, you will play a vital role in ensuring the overall security and governance risk/control environment for critical production systems.


  • Old Toronto, Canada GeoComply Full time

    h3>Chief Information Security Officer (Toronto, ON)We’re GeoComply! We are at the forefront of geolocation, cybersecurity, and anti-fraud innovation, developing and delivering cutting-edge technologies to help ensure regulatory compliance, combat bad online actors, alleviate user friction, and protect businesses from fraud.Achieving significant business...