Level

TD Bank

Information Security Specialist - Risk Management Transformation

TD Bank is hiring an Information Security Specialist - Risk Management Transformation in Toronto, Canada. Level rates it ; you can apply on Level.

AI in this role

Work Location:

Toronto, Ontario, Canada

Hours:

37.5

Line of Business:

Technology Solutions

Pay Details:

$96,900 - $136,800 CAD

TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.

As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.

Job Description:

Job Description:


This position reports to the Associate Vice President, Risk Management Tools and Transformation. The Information Security Specialist, Risk Management Transformation is a results-driven individual contributor within the Governance, Risk and Controls (GRC) team. The role provides specialized expertise and guidance to define, develop, implement, and improve technology and cybersecurity risk management processes, tools, and capabilities that support Global Security & Defense (GSD) and Global Technology Services (GTS) objectives.

The successful candidate will have demonstrated experience supporting modernization of technology and cybersecurity governance, risk, and control capabilities in a large, complex organization. The role contributes to initiatives involving risk assessment methodologies, automated and manual testing and assessments, the control lifecycle, issue management, governance, data and evidence management, and GRC platform capabilities and integrations. The specialist applies sound judgment, analysis, metrics, key risk indicators (KRIs), automation, and evidence-based approaches to identify gaps, recommend solutions, and improve risk-informed decision-making.

A strong product mindset, agile delivery experience, and commitment to improving risk and control solutions—including automated testing and assessment capabilities where appropriate—are required.


Key Accountabilities

  • Define, develop, implement, and improve GRC processes, tools, and capabilities within assigned areas of specialization, translating stakeholder needs and strategic priorities into practical requirements and deliverables.
  • Lead or contribute to improved design for risk and control assessments for applications, products, services, or processes; define and establish evidence collection methodologies through solid understanding of business requirements, data quality and reliability practices, and implementation of repeatable, and reliable services.
    • Contribute to the design, implementation, and continuous improvement of automated testing and assessment capabilities, including data sourcing, rules and logic, evidence capture, exception handling, validation, monitoring, and integration with broader GRC processes and platforms.
  • Provide consultation and advice to business and technology partners on tooling and technology, information security practices, GRC capabilities, with focus on use of automation and evidence-based assessment approaches within specialized area.
  • Maintains subject matter expertise on project risk and control assessments, including automated and manual testing where appropriate; understanding of required controls, and evaluation and automation of control procedures and management of supporting evidence
  • Identify and recommend opportunities to use AI and predictive analytics to reduce manual effort, save time, improve quality, and enable more consistent, evidence-based risk and control outcomes.
  • Provide analysis, reporting, metrics, and recommend KRIs that monitor trends, product and tooling effectiveness, service performance, assessment results, and delivery outcomes; evaluate data and evidence for completeness, accuracy, traceability, and decision usefulness; identify key issues and escalate as appropriate.
  • Gather, analyze, and translate business, security, regulatory, data, and operational needs into clear requirements, process designs, user stories, test scenarios, and implementation guidance for GRC technology teams.
    • Contribute to the design, implementation, and continuous improvement of automated testing and assessment capabilities, including data sourcing, rules and logic, evidence capture, exception handling, validation, monitoring, and integration with broader GRC processes and platforms.
    • Establish effective relationships across business, technology, risk, compliance, audit, product, and delivery partners; serve as a subject matter resource for assigned GRC processes and capabilities.
  • Stay informed on emerging information security, technology risk, regulatory, and industry trends; assess impacts and recommend opportunities to enhance effectiveness, productivity, automation, data quality, and operational efficiency.

Job Requirements

  • Advanced knowledge of one or more technology controls, information security, cybersecurity, or technology risk domains, disciplines, and practices.
  • Sound to advanced knowledge of organizational, technology control, security, and risk issues, including applicable policies, standards, and regulatory expectations.
  • Demonstrated ability to define and improve risk management processes, translate requirements into GRC capabilities, and apply data evaluation, evidence management, analytics, and automation to support effective oversight and decision-making.
  • Experience participating in projects or initiatives of moderate to high complexity at the functional, business-line, or enterprise level, independently managing assigned deliverables and timelines.
  • Ability to operate effectively in a fast-paced, ambiguous environment, exercise sound judgment, adapt to changing priorities, and escalate non-standard or high-risk matters.
  • Strong relationship-management and consulting skills, with the ability to collaborate across a large, matrixed organization, reconcile differing perspectives, and influence outcomes within defined authority.
  • Exceptional analytical, attention-to-detail, and organizational skills, with the ability to manage multiple priorities and deliver accurate, high-quality work under pressure.
  • Strong written, verbal, facilitation, and presentation skills, with the ability to communicate technical and risk concepts clearly to technical and non-technical stakeholders, including senior management.
  • Data- and fact-driven, with demonstrated ability to evaluate complex data sets and supporting evidence, assess quality and reliability, draw defensible conclusions, make practical recommendations, and monitor implementation outcomes.

Experience and Education


  • University degree or equivalent relevant professional experience.
  • 7+ years of relevant experience in technology risk, information security, cybersecurity, technology controls, GRC, or a related discipline within a large, complex organization.
  • Information security certification or accreditation such as CISSP, CISM, CISA, or CRISC is an asset.

Colleague and Team Accountabilities


  • Contribute to a positive, inclusive, and high-performing environment that supports colleague growth, well-being, innovation, teamwork, and service to the business.
  • Align individual contributions and deliverables to business priorities, the TD Shared Commitments, and applicable risk appetite, policies, and standards.
  • Work collaboratively within a diverse team that values different perspectives, creativity, curiosity, mutual respect, and timely execution.
  • Promote an inclusive environment where colleagues and partners are valued, respected, heard, and able to contribute effectively.
  • Share knowledge, information, skills, and specialized expertise with colleagues and partners; provide guidance and support within the role’s area of expertise.
  • Seek, provide, and act on constructive feedback; pursue continuous learning and maintain current knowledge of relevant security, risk, regulatory, and technology developments.
  • Identify and recommend opportunities to improve team productivity, effectiveness, quality, and operational efficiency.
  • Maintain a strong culture of risk management and control, ensure timely communication and escalation of issues, and protect the interests of the organization.
  • Support change by demonstrating resilience and flexibility, constructively challenging current practices, and helping partners adopt improved processes and capabilities.
  • Contribute specialized expertise to business-specific, cross-functional, and enterprise initiatives and deliver assigned outcomes with limited guidance.
  • Prioritize and manage own workload to meet commitments, maintain quality, and achieve results aligned with team and business objectives.



Inclusiveness

Our Commitment to Diversity, Equity, and Inclusion


At TD, we’re committed to fostering an environment where all colleagues are encouraged to bring their authentic selves to work, experience equitable opportunities, and feel respected and supported. We’re dedicated to building an inclusive workforce that reflects the diversity of the customers and the communities in which we live and serve.

How We're Helping Make an Impact in Communities
TD has a long-standing commitment to help drive progress towards a more inclusive and sustainable future. That’s why we launched the TD Ready Commitment in 2018, now a multi-year North American initiative. Under the TD Ready Commitment, we are targeting a total of $1 billion by 2030 in community giving across four key, interconnected drivers of change: Financial Security, Vibrant Planet, Connected Communities, and Better Health. It’s our goal to help support change, nurture progress, and contribute to making the world a better, more inclusive place for our customers, colleagues, and communities.

Accommodation
Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.

We look forward to hearing from you!


#li-tech

Who We Are:

TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we strive to make every interaction, product, and experience remarkably human and refreshingly simple for over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to foster deeper relationships, ensure disciplined execution, and build a simpler, faster banking experience. TD is deeply committed to being a leader in client experience, that is why we believe that all colleagues, no matter where they work, are client facing. Together, we are reimagining what banking can be for our clients, colleagues and communities.

Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more

Additional Information:
We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.

Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.


Colleague Development

If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities.

If you’re passionate about helping clients and building deep, lasting relationships, TD offers diverse career paths where you can grow your expertise and make a meaningful impact.  

We're committed to your success and foster a respectful workplace where diverse perspectives are valued, everyone has fair opportunities to grow, and you can unlock your full potential to achieve your career goals. Here at TD, we hire and develop the best.

Training & Onboarding
We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.

Interview Process 
We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.


Accommodation
Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.

We look forward to hearing from you!

Language Requirement (Quebec only):

Sans Objet

How we rate this

Information Security Specialist - Risk Management Transformation at TD Bank rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Get new cybersecurity jobs by email

One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at TD Bank

More cybersecurity jobs

Related searches

Same AI level

Jobs by city