Senior Information Security Analyst

Senior
CompanyTD Bank
LocationToronto, Ontario, Mississauga, Ontario
CategorySecurity
SenioritySenior
Workplace-
Posted2026-09-10
Estimated salaryCA$9K - CA$16K (a market estimate, not the employer's figure)
Viaworkday

Description

Work Location

Toronto, Ontario, Canada

Hours

37.5

Line of Business

Technology Solutions

Pay Details

$81,600 - $115,200 CAD

TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.

As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.

Job Description

Senior   Information Security Analyst   (L9)

Job Description

KEY ACCOUNTABILITIES

CUSTOMER

-
Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area

-
Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability   assessments   and any other relevant areas

-
Lead or contribute to completion of risk and control   assessments for an application portfolio   to   assess   design and operating effectiveness   of bank and third-party systems , articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable

-
Contribute to the definition, development, and oversight of a global security management strategy and framework

-
Ensure technology, processes, and governance are in place to   monitor , detect, prevent, and react to both current and emerging technology / security threats against TDBG’s business

-
Develop on-going Technology Risk reporting, monitoring key   trends   and defining metrics to regularly measure control effectiveness for own area

-
Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank’s overall Enterprise Architecture, and any control gaps are addressed.

-
Consult on Regulatory compliance requirements,   reporting   and questions

-
Provide support and consulting in preparation for Audits and in composing management responses and   appropriate remediation   activities

-
Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team

SHAREHOLDER

-
Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines

-
Contribute to the review of internal processes and activities and   assist   in   identifying   potential opportunities for improvement

-
Adhere to and   advise   on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security   activities

-
Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise

-
Remain informed of emerging issues, industry   trends   and/or relevant changes

-
Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service,   efficiency   and effectiveness

-
Actively   manage   relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements

-
Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank

-
Assess / identify key issues and escalate to   appropriate levels   and relevant stakeholders where   required

-
Maintain a culture of risk management and control, supported by effective processes and sound infrastructure   an   in alignment with risk appetite

-
Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to   identify   risk / provide guidance

-
May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level

EMPLOYEE / TEAM

-
Document internal processes and make periodic updates to existing documentation

-
Continuously enhance knowledge /   expertise   in own area

-
Keep current on emerging trends / developments and grow knowledge of   the business , analytical   tools   and techniques

-
Prioritize and manage own workload to deliver quality results and meet assigned timelines

-
Support a positive work environment that promotes service to the business, quality,   innovation   and teamwork and ensure   timely   communication of issues/ points of interest

-
Identify   and recommend opportunities to enhance productivity,   effectiveness   and operational efficiency

-
Establish effective relationships across multiple business and technology partners,   program   and project managers

-
Participate   in knowledge transfer within the team and business units

BREADTH & DEPTH

-
Advanced knowledge of one or more technology controls / security domains,   disciplines   and practices

-
Sound to advanced knowledge of organization, technology controls / security/ risk issues

-
May   participate   on projects of moderate to high complexity

-
Acts as a key resource and subject matter expert in at least one technology niche/ field and/or line of business

-
Generally   reports to Manager or Senior Manager

EXPERIENCE & EDUCATION

-
University degree

-
Information security certification / accreditation an asset

-
Familiarity with industry standard frameworks ( e.g.   NIST   CSF/800-53 , ISO   27001 , COBIT, CIS, PCI, GLBA, SOX /ITGC )

-
5-7years of relevant experience

-
Skills to   identify , assess, and   monitor   technology risks including information security, cyber security, resilience, operations/change management quality, data quality/security, and IT compliance.

-
Strong critical thinking - ability to decompose complex issues into manageable pieces.

-
Ability to articulate ideas, share   experiences   and skills.

-
Firm commitment to staying informed/abreast of emerging cyber and information security issues, industry trends.

-
Strength in prioritizing and managing your own workload to deliver quality results and meet timelines with limited guidance from management.

-
Knowledge of industry standards and best practices in the areas of technology, information and cyber security, risk   management   and governance.

-
High flexibility   and are   comfortable working in a fluid, changing environment.

-
Strong communication ,   written   and presentation skills.

-
Ability to multi-task and manage multiple team and client demands concurrently.

-
Dedicated team player; comfortable with a dynamic work environment.

-
Diligent and resourceful in research and information gathering.

-
Proficiency   with enterprise   collaboration and productivity   t ools , including   J ira, Confluence , SharePoint ,   and Microsoft   O ffice

-
Data analysis   experience , preferably using   Power BI   or Tableau

-
Familiarity with Python and generative AI is an asset

-
Familiarity with   GRC platforms   ( e.g.   Arc her,   ServiceNow   IRM )

Define,   develop   and/or implement Technology Controls / Information Security related policies, programs, tools and provide specialized   expertise   and guidance on assessing risks,   identifying   potential   gaps   and providing security solutions to mitigate risks and protect the Bank. May   participate   on   projects of moderate to high complexity and provide complex reporting, analysis, and assessmen