Information Security Analyst
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Work Location: Mississauga, Ontario, Canada Hours: 37.5 Line of Business: Technology Solutions Pay Details: $81,600 - $115,200 CAD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs. As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description: Job Description Summary
Define, develop, and implement Technology Controls and Information Security-related policies, programs, standards, processes, and tools. Provide specialized expertise and guidance on assessing risks, identifying control gaps, and developing appropriate solutions to mitigate risk and protect the Bank. The role provides subject matter expertise for the Bank’s End-User Computing governance program, including asset classification, attestation, risk and control assessments, thematic remediation, high-risk mitigation, standards enhancement, stakeholder guidance, governance reporting, learning content, and intake management. The role may participate in projects of moderate to high complexity and provide complex reporting, analysis, and assessments at the functional, business-line, or enterprise level.
Job Description KEY ACCOUNTABILITIES
- Provide consultation and advice to business, technology, and control partners on End-User Computing governance, information security requirements, policies, standards, processes, and controls.
- Serve as an EUC risk and technology subject matter expert, helping stakeholders understand asset classification, registration, attestation, risk assessment, control, and remediation requirements.
- Conduct or support Inherent Risk Assessments and Control Gap Assessments, document identified risks and control gaps, and provide practical guidance on remediation strategies.
- Coordinate the intake, review, prioritization, and assignment of EUC-related requests, ensuring stakeholders receive timely and consistent guidance.
- Develop and maintain EUC governance content, guidance, procedures, learning materials, and knowledge resources through approved collaboration platforms.
- Lead or support stakeholder engagement sessions, office hours, and knowledge-sharing activities to promote understanding and consistent application of EUC requirements.
- Establish effective relationships across business, technology, program, project, and control functions to support risk-based decision-making and timely issue resolution.
- Maintain the integrity and quality of the EUC Book of Record through asset classification, attestation campaigns, ongoing monitoring, data-quality reviews, and assessment of asset changes and risk indicators.
- Lead or contribute to risk and control design assessments, clearly documenting the impact of control gaps on the business and the Bank and supporting the development of risk-mitigation and remediation plans.
- Support thematic analysis and remediation activities by identifying common risk patterns, determining affected populations, tracking corrective actions, and escalating material issues where required.
- Support mitigation of Functionally High-Risk EUC assets and EUC assets subject to Payment Card Industry requirements, including risk identification, control-gap analysis, action tracking, stakeholder engagement, and management reporting.
- Contribute to the definition, review, enhancement, and implementation of EUC security standards, controls, procedures, and supporting governance processes.
- Develop ongoing EUC risk reporting and monitor Key Performance Indicators and Key Risk Indicators to measure program performance, risk exposure, remediation progress, and control effectiveness.
- Perform or support quality assurance and quality control reviews to promote the accuracy, completeness, and consistency of EUC classifications, assessments, control determinations, and reporting.
- Provide support and consultation for internal audits, regulatory examinations, compliance reviews, and management responses, including the coordination and tracking of remediation activities.
- Consult on regulatory and compliance requirements, reporting, and information requests related to EUC governance.
- Monitor emerging technology, security, regulatory, and industry developments and assess their potential impact on the Bank’s EUC governance and control environment.
- Identify key risks a