It Security Analyst

Toronto, ON, Canada

Job Description

Story Behind the Need:

  • Business group: U.S. Information Security and Control
  • This is a security advisory team that provides various security services across the enterprise, including assessing systems and their security posture, aligning technology into the network environment, supporting secure by design initiatives, and providing guidance to business lines on best practices and adhering to the bank's security standards.
  • Project: Project GENIE
  • Assessing the presence of DLPC (Data Loss Prevention Controls) on subsidiary applications within the LATAM region.
  • The Bilingual (English-Spanish) Security Advisor contractor is required to conduct residual risk assessments for applications handling bulk sensitive data, as part of deliverable #2.
Candidate Value Proposition:
  • The successful candidate will have the opportunity to work for a global legacy Canadian bank with exposure to the LATAM region.
Typical Day in Role:
  • Reporting to the Senior Manager of Security Advisory (US Advisory), the Information Security Advisor provides guidance to business lines to ensure design, development and implementation of complex projects and initiatives are in accordance with the Bank's Information Security Standards and in compliance with industry regulations. In this role, you will be supporting various business lines while assisting them in making informed decisions to protect information assets deployed in various environments.
  • Provide strategic guidance and technical expertise to business lines, IT support functions, and IS&C Control functions to include security within early stages of the design of Banks technological solutions.
  • Providing the following functions to client's Initiatives:
o Conducting Threat Risk Assessments and performing security advisory work on specific applications and infrastructure associated with client's LATAM subsidiaries and other Initiatives ensuring that controls are adequate, meet Bank standards, and enable business objectives.
o Conducting Risk Management activities.
o Provide Quality Assurance on Threat Risk Assessments and Threat Modelling as required for Cloud initiatives. Provide strategic guidance and technical expertise on security solutions and recommend best practices.
o Collaborate with cross-functional teams to design and implement robust security architectures for various systems, applications, and networks.
o Evaluate existing security solutions and propose enhancements or new designs to address emerging threats and business requirements.
o Ensure alignment with industry best practices, compliance standards, and organizational security policies.
o Identify security weaknesses, vulnerabilities, and gaps in existing systems and recommend remediation strategies.
o Provide support on how to apply the Bank's portfolio of standards to the technology footprint of client's subsidiaries.
o Provide oversight over the specific line of business security posture, ensuring that all tools available to detect and remediate security risks have been applied.
o Conduct industry reviews and benchmarking exercises to ensure our controls are aligned with our peers, emerging threats, and available mitigation strategies.
o Working directly with technical leads from assigned Lines of Businesses supporting their initiatives from an Information Security perspective.
o Providing relationship management function primarily to LATAM subsidiaries from an Information Security perspective.
Candidate Requirements/Must Have Skills:
  • 5+ years of hands-on technical working experience in performing security assessments on various platforms, network infrastructure and complex applications.
  • 3+ years of Experience with Threat Risk Assessments of applications hosted on premise, cloud, hybrid cloud and SaaS.
  • 5+ years of experience in security solution architecture, software development, and/or hands-on experience with implementations to various environments, knowledge of application security controls, including compensating controls and cloud-based security solutions
  • Deep understanding of DLP tooling and controls including enhanced monitoring and authentication standards.
  • Bilingual in Spanish
Nice-To-Have Skills:
  • prior experience using ServiceNow platform
  • You have solid knowledge of cloud technologies and cloud security (GCP or Azure or AWS)
  • security engineering, security architecture, and/or security risk based certifications (CISSP, CISM, CCSP, CRISC)
  • Familiar with industry standards and frameworks e.g., NIST 800-53, ISO 27001, ISO27002, ISO 27017, ISO27018, PCI DSS, CIS.
Soft Skills Required:
  • You are a strong communicator and capable of creating clear documentation and communicating ideas to others
  • You possess advanced communication (verbal/written/presentation) skills in English.
Education:
  • Post-secondary education in Computer Science or in a related field.
Best VS. Average Candidate:
  • The ideal candidate would be familiar with frameworks listed under nice to haves and would have solid knowledge of cloud security.
Candidate Review & Selection:
  • 2 rounds:
o 1st round - HM - 30 mins - MS Teams Video (possible in-person interview)
o 2nd round - HM + Project Lead - MS Teams Video
Job Details
13763
Contract
6 months
Scarborough
82.00 CAD
Recruiter
Arshdeep Kaur
|

Skills Required

IT
Beware of fraud agents! do not pay money to get a job

MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Related Jobs

Job Detail

  • Job Id
    JD3161582
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Toronto, ON, Canada
  • Education
    Not mentioned