Senior Information Security Specialist role providing technology risk support and management for TD's global financial services. Facilitating enterprise-wide information security programs and AI governance.
Responsibilities
Provide technology risk advice and consultation to business partners.
Facilitate communication and execution of enterprise-wide information security programs.
Develop enterprise awareness training for AI.
Conduct risk assessments on business applications, third parties, and infrastructure.
Validate that security and technology controls are implemented to support business requirements.
Lead development and implementation of technology controls and information security strategies, policies, and programs.
Oversee control and governance activities, identifying and assessing potential security risks, breaches, and exposures.
Act as a primary technical expert, working with technology partners and service/platform owners to integrate security components into enterprise architecture.
Consult on regulatory compliance requirements, reporting, and questions.
Requirements
University degree required
Information security certification or accreditation is an asset
10+ years of relevant experience.
Deep understanding of AI risk management frameworks (e.g., NIST AI Risk Management Framework, ISO/IEC 23894 , ISO42001, OWASP, MITRE)
Familiarity with financial services industry regulations and standards (e.g., FFIEC, GLBA, GDPR, PCI DSS, NYDFS Cybersecurity Regulation)
Experience implementing AI governance and ethical guidelines in financial institutions.
Ability to assess and mitigate risks associated with AI models, including bias, explainability, and robustness.
Knowledge of secure AI development lifecycle and best practices for model validation and monitoring.
Expertise integrating AI security controls into enterprise architecture and technology platforms.
Awareness of emerging AI threats, adversarial attacks, and evolving regulatory requirements.
Ability to communicate complex AI risk concepts to executive stakeholders and non-technical audiences.
Experience with incident response and remediation for AI-related security events.
Commitment to continuous learning and staying current with industry trends, frameworks, and best practices in AI and financial services.
IT Audit Senior managing client expectations and delivering detailed audit analyses and findings. Collaborating with management on IT audit engagements in a leading advisory firm.
Enterprise Security Architect specializing in Digital Workspace security at Novartis. Responsible for ensuring security standards and practices across IT functions and collaborating with various teams.
Cyber Security Engineer responsible for administering security tools and projects. Collaborating with stakeholders to ensure the overall Cyber Security of the firm.
Facility Security Officer responsible for developing and administering security programs for classified materials. Overseeing compliance with federal security regulations at the Rochester, NY site.
Security Support D managing security processes essential for classified operations. Focused on document control, compliance, and training within a regulated environment.
Intern supporting cybersecurity consulting with Guidehouse's federal clients. Engaging in hands - on projects and learning development opportunities within a structured internship program.
Security Engineering Manager leading network security engineering team at General Motors. Ensuring the reliability, performance, and security of global network infrastructure supporting automotive technologies.
VP, Information Security Officer managing cyber risk and advisory services at State Street. Collaborating with teams to protect digital assets and enhance security measures across the organization.
Senior Security Consultant enhancing AI security solutions at BAE Systems. Conducting security assessments and advising clients on AI risk management in national security projects.
IT Security Specialist focusing on cyber defense within a family - owned company. Responsibilities include managing firewalls, monitoring threats, and implementing security solutions.