Information Security Advisor
4 weeks ago
Get AI-powered advice on this job and more exclusive features. Requisition ID : Tangerine is Canada’s leading direct bank. We offer flexible and accessible banking options, innovative products, and award-winning Client service. The reason why Tangerine employees come to work each day is to help Canadians live better lives. We focus on making a difference in our communities, and that includes our own internal community. It’s important to us that our employees feel empowered and enthusiastic about belonging to our Orange culture. Team Scotiabank’s Security Advisory Services team is responsible for providing advisory services to Tangerine Bank and its business lines, subsidiaries and affiliates enabling the achievement of the Bank's Information Security as it continues to move to the Public Cloud. Role Reporting to the Senior Manager of Security Advisory (Tangerine), the Information Security Advisor provides guidance to business lines to ensure design, development and implementation of complex projects and initiatives are in accordance with the Bank's Information Security Standards and in compliance with industry regulations. In this role, you will be supporting various business lines while assisting them in making informed decisions to protect information assets deployed in Public Cloud environments. Responsibilities You have a strong experience leading complex projects providing security advise to ensure information security risk are mitigated. You thrive in solutioning for multiple security domains (Application Security, Data Protection, Cloud Security Engineering, Identity and Access Management, Cloud Security Architecture, Network Security, Risk Management, etc.) and knowledgeable of Zero Trust Architecture principles. You have experience in solutioning security architecture, creating and reviewing security patterns, and advising on security risks. You are proficient in reviewing architecture and solution design documentation and can identify and assess potential risks. You excel in reviewing Technical Design and Security Design documents and creating assessment documents (Threat Risk Assessment) and evaluating risks. You are passionate about new technologies and enjoy the challenges of implementing security controls to protect them. Working on different types of projects (from large complex to simple) is a part of your DNA. You love to collaborate with various business lines, IT support functions and IS&C Control functions. Skills Post-secondary education in Computer Science or in a related field. You have at least 5 years of hands‑on technical working experience in performing security assessments on cloud platforms, CI/CD deployment pipelines, network infrastructure and complex applications. Experience with Risk Assessments of applications migrated into the Cloud Environments. You have at least 5 years experience in security solution architecture, software development, and/or hands‑on experience with implementations of cloud environments, security controls and cloud‑based solutions. You are a strong communicator and capable of creating clear documentation and communicating ideas to others. You have solid knowledge of cloud technologies and cloud security (GCP or Azure or AWS, Kubernetes and IAM, CI/CD pipelines, Terraforms, infrastructure as code). Experience with GCP and Kubernetes is a strong asset. Experience with tools used in securing cloud deployments such as CNAPP, CSPM, CWPP, etc. You have cloud security engineering or cloud solution architecture certifications from Google, Microsoft or AWS. You have used industry leading productivity tools to produce quantitative/qualitative reports, data flow diagrams & visual presentations. Certifications (CISSP, CISM, CCSP, CRISC) are nice to have. Familiar with industry standards and frameworks e.g., NIST 800-53, ISO 27001, ISO27002, ISO27017, ISO27018, PCI DSS, CIS. You possess advanced communication (verbal/written/presentation) skills in English. Knowledge of Spanish is an asset. Key Job Accountabilities Provide strategic guidance and technical expertise to business lines, IT support functions, and IS&C Control functions to include security within early stages of the design of Bank's technological solutions. Conducting Threat Risk Assessments and performing security advisory work on specific applications and infrastructure associated with Scotiabank's Cloud and other Initiatives ensuring that controls are adequate, meet Bank standards, and enable business objectives. Conducting Risk Management activities. Provide Quality Assurance on Threat Risk Assessments and Threat Modelling as required for Cloud initiatives. Provide strategic guidance and technical expertise on security solutions and recommend best practices. Conduct comprehensive security assessments on large high-profile initiatives implemented in GCP and Azure. Collaborate with cross-functional teams to design and implement robust security architectures for various systems, applications, and networks. Evaluate existing security solutions and propose enhancements or new designs to address emerging threats and business requirements. Ensure alignment with industry best practices, compliance standards, and organizational security policies. Identify security weaknesses, vulnerabilities, and gaps in existing systems and recommend remediation strategies. Provide support on how to apply the Bank's portfolio of standards to the technology footprint of Scotiabank's Cloud offering. Provide oversight over the specific line of business security posture, ensuring that all tools available to detect and remediate security risks have been applied. Conduct industry reviews and benchmarking exercises to ensure our controls are aligned with our peers, emerging threats, and available mitigation strategies. Working directly with technical leads from assigned Lines of Businesses supporting their initiatives from an Information Security perspective. Providing relationship management function primarily to the Tangerine and Enterprise Cloud team from an Information Security perspective. What's in it for you? Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias‑free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employees to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans. Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements. Upskilling through online courses, cross‑functional development opportunities, and tuition assistance. Competitive Rewards program including bonus, flexible vacation, personal, sick days and benefits will start on day one. Community Engagement - no matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs such as hackathons, contests, Humans of Digital and much more Location(s): Canada : Ontario : Toronto At Tangerine we value the unique skills and experiences each individual brings to the team, and are committed to creating and maintaining an inclusive and accessible environment. If you require accommodation during the recruitment and selection process, please let our Recruitment team know. Seniority level Mid‑Senior level Employment type Full‑time Job function Information Technology Industries Banking #J-18808-Ljbffr
-
Information Security Advisor
2 weeks ago
Toronto, Canada People Corporation Full timeWe are hiring an Information Security Advisor to join our team in Toronto or Winnipeg. In this role, you will be a key player in protecting the organization’s critical information assets and ensuring compliance with industry standards and regulations. You will leverage a unique blend of technical expertise and strategic business insight to identify,...
-
Information Security Advisor
4 weeks ago
Toronto, Canada People Corporation Full timeWe are hiring an Information Security Advisor to join our team in Toronto or Winnipeg. In this role, you will be a key player in protecting the organization’s critical information assets and ensuring compliance with industry standards and regulations. You will leverage a unique blend of technical expertise and strategic business insight to identify,...
-
Information Security Advisor
2 weeks ago
Toronto, Canada Scotiabank Full timeRequisition ID: 203260 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. **KEY ACCOUNTABILITIES** - Focus on implementing right security controls for the bank and ensure all the threat risk assessments are well documented, tracked, and managed. - Educate team members on security awareness and industry best...
-
Information Security Advisor
16 hours ago
Toronto, Ontario, Canada Elevance Health Full timeAnticipated End Date: Position Title:Information Security Advisor - Identity Access ManagementJob Description:Information Security Advisor - Identity Access ManagementLocation: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance....
-
Advisor, Information Security
6 hours ago
Toronto, Ontario, Canada CIBC Full timeWe're building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what's right for our clients.At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and...
-
Information Security Advisor
1 week ago
Toronto, Canada Tangerine Bank Full timeThe Team Scotiabank’s Security Advisory Services team is responsible for providing advisory services to Tangerine Bank and its business lines, subsidiaries and affiliates enabling the achievement of the Bank's Information Security as it continues to move to the Public Cloud. The Role Reporting to the Senior Manager of Security Advisory (Tangerine), the...
-
Information Security Advisor
1 week ago
Toronto, Canada Tangerine Bank Full timeThe Team Scotiabank’s Security Advisory Services team is responsible for providing advisory services to Tangerine Bank and its business lines, subsidiaries and affiliates enabling the achievement of the Bank's Information Security as it continues to move to the Public Cloud. The Role Reporting to the Senior Manager of Security Advisory (Tangerine), the...
-
Information Security Advisor
7 days ago
Toronto, Canada Tangerine Bank Full timeThe Team Scotiabank’s Security Advisory Services team is responsible for providing advisory services to Tangerine Bank and its business lines, subsidiaries and affiliates enabling the achievement of the Bank's Information Security as it continues to move to the Public Cloud. The Role Reporting to the Senior Manager of Security Advisory (Tangerine), the...
-
Information Security Awareness Advisor
7 days ago
Toronto, Canada OLG Full timeRange: 78,400.00 - 117,600.00 CAD Job Description: Information Security Awareness Advisor GAME ON - OLG needs you We’ve said GAME ON, and we mean it - OLG is rapidly transforming its organization to better serve Ontarians by delivering great gaming experiences through our digital, retail lottery, and land-based gaming channels. Over the course of...
-
Information Security Advisor
7 days ago
Toronto, Canada Accelerate Her Future® Full timeRequisition ID: 241600Tangerine is Canada’s leading direct bank. We offer flexible and accessible banking options, innovative products, and award‑winning client service. The reason why Tangerine employees come to work each day is to help Canadians live better lives. We focus on making a difference in our communities, and that includes our own internal...