cover image
TD

Information Security Specialist - Cyber Security Incident Response

On site

Toronto, Canada

Full Time

03-02-2026

Share this job:

Skills

Leadership Incident Response Risk Management Monitoring Operating Systems Organization react

Job Specifications

Lieu De Travail :

Toronto, Ontario, Canada

Horaire :

37.5

Secteur D’activité :

Solutions technologiques

Détails De La Rémunération :

$96,900 - $136,800 CAD

La TD a à cœur d’offrir une rémunération juste et équitable à tous les collègues. Les occasions de croissance et le perfectionnement des compétences sont des caractéristiques essentielles de l’expérience collègue à la TD. Nos politiques et pratiques en matière de rémunération ont été conçues pour permettre aux collègues de progresser dans l’échelle salariale au fil du temps, à mesure qu’ils s’améliorent dans leurs fonctions. Le salaire de base offert peut varier en fonction des compétences et de l’expérience du candidat, de ses connaissances professionnelles, de son emplacement géographique et d’autres besoins particuliers du secteur et de l’entreprise.

En tant que candidat, nous vous encourageons à poser des questions sur la rémunération et à avoir une conversation franche avec votre recruteur, qui pourra vous fournir des détails plus précis sur ce poste.

Description Du Poste :

As an Information Security Specialist, you will play a critical role in detecting, investigating, and responding to cyber threats targeting TD.
You will work within the Cyber Security Incident Response Team (CSIRT), leading in complex. Investigations, developing detection and hunting techniques, and strengthening our incident response capabilities.
This role requires an experienced security professional with deep technical expertise in incident handling and analysis, malware investigation and containment, and cyber kill chain. You will be responsible for identifying and mitigating cyberthreats, collaborating with stakeholders across Protect Platform, ITS, and business teams to reduce risk and enhance our security posture.

The personnel in this role will work as part of a cyber security operations team responsible for carrying out 24x7 security monitoring operations. Operations are carried out on a rotating shift schedule than involves occasional on-call and/or weekend support.

Here Are The Essential Job Functions Of This Position:

Guide partners on a broad range of technology throughout incidents
Lead Cybersecurity Incidents and Cybersecurity events
Lead or contribute to containment and recovery plans for Cybersecurity Incidents
Contribute to the definition, development, and oversight of a global security management strategy and framework
Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology and security threats against TD businesses and network domains
Develop on-going operational enhancements for Cybersecurity including alerting, monitoring, and detection across multiple security domains
Adhere to internal policies and procedures, technology control standards, and applicable regulatory guidelines
Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement
Adhere to, advise, oversee, monitor and enforce enterprise frameworks and methodologies that relate to technology controls / information security activities
Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise

Job Requirements

Here are the minimum requirements for this position:
University degree or equivalent hands-on work experience
7+ years of hands-on relevant experience
Expert knowledge of Information Technology (IT) security and Incident Management practices across multiple cybersecurity domains.
Candidate must possess strong hands-on experience with traditional incidents response detection tools such as SIEM, EDR, XDR, Firewall, WAF, email proxies, NIDS, and equivalent
Candidate should possess advanced hands-on experience in all modern Operating Systems (Window/NIX/Cloud/Mobile)
Should have advanced scripting skills, can read data structures and software binary code
Advanced knowledge of Enterprise, technology controls, cybersecurity, and cyber risk issues
Strong communications, leadership and people building skills within Information Technology and/or Cybersecurity
A demonstrated ability to participate in complex, comprehensive and large projects
Has the ability to serve as a leading expert in technology controls and information security for project teams, the business, organization, and external vendors
Must be eligible for employment under regulatory standards applicable to the position

Preferred Qualifications For This Role:

Extensive experience as an Incident commander or manager working on complex information security and cybercrime-related incidents, requiring coordination with internal and external enterprise teams, as well as third parties and vendors, partners
Extensive experience working cybersecurity events and incidents related to network layer 7/application and internet facing attacks
Extensive experience briefing Senior Executives related to cybercrimes, information security inc

About the Company

The Toronto-Dominion Bank & its subsidiaries are collectively known as TD Bank Group (TD). TD is the sixth largest bank in North America by assets & serves approx. 28 million customers in a number of locations in key financial centres around the globe. With over 95,000 employees, TD ranks among the world's leading online financial firms, with more than 17 million active online and mobile customers. Delivering legendary customer experiences is who we are & is part of our goal to be the Better Bank. Visit our Careers page to l... Know more