- Company Name
- TD
- Job Title
- Spécialiste, Sécurité de l'information
- Job Description
-
**Job Title**
Information Security Specialist
**Role Summary**
Provide expert consultation on technology controls, security programs, policies, and incident response. Develop and oversee a global security strategy, ensure compliance with regulatory requirements, and guide stakeholders on emerging technology and AI enablement.
**Expectations**
- Deliver high‑quality security consulting within agreed timelines.
- Serve as a trusted advisor to business and technology partners, embedding risk‑aware culture.
- Maintain up‑to‑date knowledge of industry trends, threats, and regulatory changes.
**Key Responsibilities**
- Advise partners on technology controls, security policies, standards, and incident handling.
- Conduct risk assessments, define required controls, and evaluate current control effectiveness.
- Contribute to the design, implementation, and continuous improvement of a global security framework.
- Ensure technology, processes, and governance detect, prevent, and respond to current and emerging threats.
- Integrate security components into the Enterprise Architecture and remediate control gaps.
- Enable and govern AI and cloud adoption in alignment with enterprise capability.
- Champion emerging technology and compliance requirements across the organization.
- Consult on regulatory compliance, reporting, and audit preparation, providing remediation guidance.
- Participate in computer‑security incident response, representing the security function and aligning business priorities.
- Enforce enterprise security frameworks, policies, and procedures; advise on and monitor adherence.
- Promote a risk‑managed culture, influencing behaviors to reduce exposure.
- Remain informed on emerging security trends and assess potential impacts.
- Develop and manage standards, procedures, and solutions that mitigate risk and enhance service availability.
- Build and maintain relationships with technology, business, and control functions to ensure alignment.
- Assess key risks, escalating appropriately, and support business initiatives as a subject‑matter expert.
- Contribute to complex reporting, analysis, and enterprise‑level assessments.
**Required Skills**
- Deep knowledge of IT, cloud, AI, security, and risk management practices.
- Expertise in risk assessment, vulnerability scanning, and control implementation.
- Strong understanding of regulatory frameworks (PCI‑DSS, SOX, GLBA, GDPR, CCPA, etc.).
- Experience with security frameworks (ISO 27001, NIST, CIS, COBIT, etc.).
- Incident response planning and execution.
- Project consulting and stakeholder engagement.
- Excellent communication, negotiation, and presentation skills.
- Ability to translate technical concepts to non‑technical audiences.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
- Minimum 5 years of professional experience in information security, risk management, or technology controls.
- Professional certifications such as CISSP, CISM, CCSP, ISO 27001 Lead Implementer, or CEH preferred.
All information is provided in English and is ATS‑friendly.