Risk Specialist, Cyber Third Party & Supply Chain Risk (4413)
Posted 3 hours ago
Job Description
Work Location:
Toronto, Ontario, Canada
Hours:
37.5
Line of Business:
Risk Management
Pay Details:
96,900.00 - 136,800.00 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:
Technology Risk Specialist - Information Security Risk Management (ISRM)
Department Overview
The Operational Risk Management (ORM) function works in partnership with the business and technology teams across the Bank to strengthen operational risk management (ORM).
ORM for Enterprise Technology and Cyber & Information Security provides independent oversight and challenge to operational risk management activities. They partner with the first line of defense in identifying, reporting, and mitigating Technology and Cyber & Information Security risk issues and provide subject matter expertise. The group executes 2A requirements in support of 3 lines of defense framework.
Job Description
The ISRM Risk Specialist will partner with the first line of defense to oversee and challenge the execution of risk management activities and leading practices/technologies across Cyber & Information
Security domains, with a focus on cyber third party and supply chain risks.
ISRM promotes a strong risk culture by providing objective challenges, clear insight, and practical guidance across Information Security and Cyber domains. This includes oversight of third-party security risks, supplier-related technology dependencies, and emerging threats within complex supply-chain environments, while working collaboratively with technology, security, and business partners.
This position contributes to oversight activities, supports assessment review and challenge, and helps ensure analysis, evidence, and remediation plans meet expectations under the Technology & Information Security Risk Management Framework.
Reporting to the ISRM Senior Manager - Technology & Data Risk Management, this role will have the following accountabilities:
Job Requirements
Education & Accreditation
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
Language Requirement (Quebec only):
Sans Objet
Toronto, Ontario, Canada
Hours:
37.5
Line of Business:
Risk Management
Pay Details:
96,900.00 - 136,800.00 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:
Technology Risk Specialist - Information Security Risk Management (ISRM)
Department Overview
The Operational Risk Management (ORM) function works in partnership with the business and technology teams across the Bank to strengthen operational risk management (ORM).
ORM for Enterprise Technology and Cyber & Information Security provides independent oversight and challenge to operational risk management activities. They partner with the first line of defense in identifying, reporting, and mitigating Technology and Cyber & Information Security risk issues and provide subject matter expertise. The group executes 2A requirements in support of 3 lines of defense framework.
Job Description
The ISRM Risk Specialist will partner with the first line of defense to oversee and challenge the execution of risk management activities and leading practices/technologies across Cyber & Information
Security domains, with a focus on cyber third party and supply chain risks.
ISRM promotes a strong risk culture by providing objective challenges, clear insight, and practical guidance across Information Security and Cyber domains. This includes oversight of third-party security risks, supplier-related technology dependencies, and emerging threats within complex supply-chain environments, while working collaboratively with technology, security, and business partners.
This position contributes to oversight activities, supports assessment review and challenge, and helps ensure analysis, evidence, and remediation plans meet expectations under the Technology & Information Security Risk Management Framework.
Reporting to the ISRM Senior Manager - Technology & Data Risk Management, this role will have the following accountabilities:
- Provide execution support across Cyber and Information Security domains including cyber third party and supply chain risk.
- Contribute to the annual ISRM planning process with a focus on developing and evolving the maturity and effectiveness of ISRM challenge and oversight activities, including: the identification and forecast of top/emerging risks, alignment of ISRM activities with 1st and 3rd line of defense annual plans, and the development of the ISRM annual Oversight & Challenge plan.
- Support and deliver independent oversight and challenge activities for cyber third party and supply chain risk management practices executed by the 1LoD such as risk assessments for third party cyber controls, and to evaluate cyber weaknesses in the sourcing of acquired hardware, commercial off-the-shelf (COTS) software, open-source software (OSS), and components integrated into TD developed applications.
- Execute activities for ISRM domain challenge and assessment consistent with the responsibilities of the second line of defense as defined in the Technology Risk Management Framework.
- Support other members of the team during the ISRM challenge activities, providing subject matter expertise (SME) advice on domain and in executing risk and control assessments.
- Effectively communicate risk management practices and methodologies and results of risk assessments to stakeholders in a supportive and collaborative manner and influence risk-based decisions and remediation activities.
- Conduct appropriate independent challenge and assessments of Technology for risk identification, assessment, reporting and monitoring based on a risk-based methodology in areas such as:
- Third party risk assessments.
- Technology risk assessments.
- Cybersecurity/ Data breach incidents, and,
- Information Security operational processes.
- Be a positive team player to consistently maintain high levels of integrity, motivation and morale.
- Will be required to keep abreast of Technology and Cybersecurity emerging risks, the evolving Cyber threat landscape especially in regard to TTPs on supply chains, best practices for technology risk management, and applicable Regulatory and Compliance requirements.
- Position will deal with stakeholders and specialists in Technology & Cybersecurity areas and risk professionals across the enterprise.
- This is a seasoned Cybersecurity risk professional with 5+ years of experience in Information Security and Protection, cybersecurity technology, and risk management.
Job Requirements
- Ability to work in ambiguity must be flexible to deal with changes in a fast paced and new environment, working closely with peers where Third-Party Risk Management and cybersecurity risk assessments, and Information Security subject matter expertise are required.
- Organizationally astute, with superior influencing, collaboration and communication skills. Ability to digest and summarize complex technical scenarios and to communicate those effectively to business leaders.
- Experience assessing risk and constructively challenging the status quo.
- In order to provide effective oversight and independent challenge the role requires the incumbent to have a good understanding of the following areas:
- Risk management frameworks and methodologies.
- Information Security & Cybersecurity frameworks, Privacy, operations, processes, controls and tools.
- Technology operations and processes.
- Third party risk management.
- Regulatory requirements.
- Experience in Cybersecurity, Risk Management, Technology vendor management and Supply chain, Technology Solutions or Internal Audit field.
- Deep understanding of Regulatory and Controls requirements: Privacy legislation, GDPR, PCI, FFIEC, SOX, HIPAA, ISO 2700x, and NIST. Standards.
- Strong analytical skills, including segment risk analysis, and comparative analysis. Ability to identify root causes on risk exposures and to correlate multiple risk exposures to assess aggregated risks and enterprise compensating controls.
- Proven ability to promote a positive, high performing work environment. Expertise in working effectively in teams - requires a track record of knowledge across the organization.
- Strong business and financial acumen.
Education & Accreditation
- This role requires successful completion of all three levels of TD Operational Risk Management certification. Certification is not a requirement to apply for this role. The successful candidate will have 12 months from the start date in the role of completing the required certifications. The required courses are available internally through TD Operational Risk Management.
- Undergraduate degree in Computer Science/ Computer Engineering/ Risk Management is an asset.
- Accreditation such as CISSP, CISM, CRISC, CISA and/or similar is preferred.
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
Language Requirement (Quebec only):
Sans Objet
About TD
Industry
Banking & FinanceCompany Size
10,000+ employees
Application closing date is 2026-03-29
Current Openings
-
Full Time
-
Full Time
-
Full Time
-
Full Time
-
Full Time
-
Full Time
-
Supply Chain Planner
Canfor
Full Time
-
Full Time
-
Lead, Digital Risk and Compliance (Contract)
Teck Resources
Part Time
-
Full Time