51 Cryptography jobs in Canada
Cryptography Product Owner
Posted 7 days ago
Job Viewed
Job Description
A career as a cryptography product owner in the Cybersecurity team at National Bank means being a key person in the evolution of our cryptographic program. This position allows you to have a concrete impact on the organisation's security thanks to your expertise in product management, applied cryptography and the protection of sensitive data.
Your job
- Define and maintain the product vision in collaboration with stakeholders (SOC, delivery teams, AESI)
- Collect, analyse and prioritise cryptography-related needs in relation to other cybersecurity domains
- Write epics, maintain the product backlog and track deliverables for your Agile team
- Actively participate in Agile ceremonies such as planning, reviews and retrospectives
- Work with technical teams to ensure the feasibility and quality of the proposed solutions
- Track performance indicators (KPIs) and adjust the roadmap produced as needed
- Ensure compliance with security standards (ISO 27001, NIST, GDPR) in all proposed solutions
Your team
In Cybersecurity, you are part of a large multidisciplinary team and report to the Senior Cybersecurity Manager. Our team stands out for its passion for innovation, collaboration and proactive security mission. Our goal is to offer you maximum flexibility to promote your quality of life. This includes a hybrid work environment and a flexible and adaptable schedule.
The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, Language Training, Harvard Learning Centre and coaching and mentoring support are available to you at any time.
Prerequisites
- Related training in the sector and five years of relevant experience
- Experience delivering solutions as a Product Owner (PO)
- Ability to work in Agile mode: Scrum, Kanban, scaled Agile Framework (safe) and deliver without having all specifications
- In-depth knowledge of operational cryptography
- Solid understanding of cybersecurity, particularly data protection
- Ability to communicate information and ideas effectively
Cryptography Product Owner
Posted 7 days ago
Job Viewed
Job Description
A career as a cryptography product owner in the Cybersecurity team at National Bank means being a key person in the evolution of our cryptographic program. This position allows you to have a concrete impact on the organisation's security thanks to your expertise in product management, applied cryptography and the protection of sensitive data.
Your job
- Define and maintain the product vision in collaboration with stakeholders (SOC, delivery teams, AESI)
- Collect, analyse and prioritise cryptography-related needs in relation to other cybersecurity domains
- Write epics, maintain the product backlog and track deliverables for your Agile team
- Actively participate in Agile ceremonies such as planning, reviews and retrospectives
- Work with technical teams to ensure the feasibility and quality of the proposed solutions
- Track performance indicators (KPIs) and adjust the roadmap produced as needed
- Ensure compliance with security standards (ISO 27001, NIST, GDPR) in all proposed solutions
Your team
In Cybersecurity, you are part of a large multidisciplinary team and report to the Senior Cybersecurity Manager. Our team stands out for its passion for innovation, collaboration and proactive security mission. Our goal is to offer you maximum flexibility to promote your quality of life. This includes a hybrid work environment and a flexible and adaptable schedule.
The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, Language Training, Harvard Learning Centre and coaching and mentoring support are available to you at any time.
Prerequisites
- Related training in the sector and five years of relevant experience
- Experience delivering solutions as a Product Owner (PO)
- Ability to work in Agile mode: Scrum, Kanban, scaled Agile Framework (safe) and deliver without having all specifications
- In-depth knowledge of operational cryptography
- Solid understanding of cybersecurity, particularly data protection
- Ability to communicate information and ideas effectively
Cryptography Product Owner
Posted 7 days ago
Job Viewed
Job Description
A career as a cryptography product owner in the Cybersecurity team at National Bank means being a key person in the evolution of our cryptographic program. This position allows you to have a concrete impact on the organisation's security thanks to your expertise in product management, applied cryptography and the protection of sensitive data.
Your job
- Define and maintain the product vision in collaboration with stakeholders (SOC, delivery teams, AESI)
- Collect, analyse and prioritise cryptography-related needs in relation to other cybersecurity domains
- Write epics, maintain the product backlog and track deliverables for your Agile team
- Actively participate in Agile ceremonies such as planning, reviews and retrospectives
- Work with technical teams to ensure the feasibility and quality of the proposed solutions
- Track performance indicators (KPIs) and adjust the roadmap produced as needed
- Ensure compliance with security standards (ISO 27001, NIST, GDPR) in all proposed solutions
Your team
In Cybersecurity, you are part of a large multidisciplinary team and report to the Senior Cybersecurity Manager. Our team stands out for its passion for innovation, collaboration and proactive security mission. Our goal is to offer you maximum flexibility to promote your quality of life. This includes a hybrid work environment and a flexible and adaptable schedule.
The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, Language Training, Harvard Learning Centre and coaching and mentoring support are available to you at any time.
Prerequisites
- Related training in the sector and five years of relevant experience
- Experience delivering solutions as a Product Owner (PO)
- Ability to work in Agile mode: Scrum, Kanban, scaled Agile Framework (safe) and deliver without having all specifications
- In-depth knowledge of operational cryptography
- Solid understanding of cybersecurity, particularly data protection
- Ability to communicate information and ideas effectively
Cryptography Product Owner
Posted 4 days ago
Job Viewed
Job Description
A career as a cryptography product owner in the Cybersecurity team at National Bank means being a key person in the evolution of our cryptographic program. This position allows you to have a concrete impact on the organisation's security thanks to your expertise in product management, applied cryptography and the protection of sensitive data.
Your job
Define and maintain the product vision in collaboration with stakeholders (SOC, delivery teams, AESI)
Collect, analyse and prioritise cryptography-related needs in relation to other cybersecurity domains
Write epics, maintain the product backlog and track deliverables for your Agile team
Actively participate in Agile ceremonies such as planning, reviews and retrospectives
Work with technical teams to ensure the feasibility and quality of the proposed solutions
Track performance indicators (KPIs) and adjust the roadmap produced as needed
Ensure compliance with security standards (ISO 27001, NIST, GDPR) in all proposed solutions
Your team
In Cybersecurity, you are part of a large multidisciplinary team and report to the Senior Cybersecurity Manager. Our team stands out for its passion for innovation, collaboration and proactive security mission. Our goal is to offer you maximum flexibility to promote your quality of life. This includes a hybrid work environment and a flexible and adaptable schedule.
The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, Language Training, Harvard Learning Centre and coaching and mentoring support are available to you at any time.
Prerequisites
Related training in the sector and five years of relevant experience
Experience delivering solutions as a Product Owner (PO)
Ability to work in Agile mode: Scrum, Kanban, scaled Agile Framework (safe) and deliver without having all specifications
In-depth knowledge of operational cryptography
Solid understanding of cybersecurity, particularly data protection
Ability to communicate information and ideas effectively
Your benefits In addition to competitive compensation, upon hiring you’ll be eligible for a wide range of flexible benefits to help promote your wellbeing and that of your family. * Health and wellness program, including many options * Flexible group insurance * Generous pension plan * Employee Share Ownership Plan * Employee and Family Assistance Program * Preferential banking services * Opportunities to get involved in community initiatives * Telemedicine service * Virtual sleep clinic These are a few of the benefits available to you. We have an offer that keeps up with trends as well as your needs and those of your family. Our dynamic work environments and cutting-edge collaboration tools foster a positive employee experience. We actively listen to employees’ ideas. Whether through our surveys or programs, regular feedback and ongoing communication is encouraged. We're putting people first We're a bank on a human scale that stands out for its courage, entrepreneurial culture, and passion for people. Our mission is to have a positive impact on peoples' lives. Our core values of partnership, agility, and empowerment inspire us, and inclusivity is central to our commitments. We offer a barrier-free workplace that is accessible to all employees. We want our recruitment process to be fully accessible. If you require accommodation, feel free to let us know during your first conversations with us. We welcome all candidates! What can you bring to our team? Come live your ambitions with us!
Information Security Specialist
Posted 2 days ago
Job Viewed
Job Description
Barrie, Ontario, Canada
**Hours:**
37.5
**Line of Business:**
Technology Solutions
**Pay Details:**
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Job Description:**
We are seeking experienced ServiceNow ITOM (CMDB/Discovery) Analyst to join our team. The ideal candidate will be proficient in managing the Configuration Management Database (CMDB) within ServiceNow, with a strong background in ServiceNow Discovery and Service Mapping.
The successful candidate will be responsible for operating CMDB / Discovery within the ServiceNow platform, including identifying and remediating Discovery errors, ensuring the accuracy and integrity of the CMDB, addressing pain points and enhancing the health of CMDB as well as enforcing Enterprise Asset Management Governance process.
**KEY ACCOUNTABILITIES**
**CUSTOMER**
+ Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
+ Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
+ Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
+ Contribute to the definition, development, and oversight of a global security management strategy and framework
+ Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
+ Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
+ Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
+ Consult on Regulatory compliance requirements, reporting and questions
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
**SHAREHOLDER**
+ Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines
+ Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement
+ Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities
+ Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise
+ Remain informed of emerging issues, industry trends and/or relevant changes
+ Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness
+ Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements
+ Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank
+ Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required
+ Maintain a culture of risk management and control, supported by effective processes and sound infrastructure an in alignment with risk appetite
+ Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to identify risk / provide guidance
+ May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level
**EMPLOYEE / TEAM**
+ Maintain and manage the Configuration Management Database (CMDB) within ServiceNow and supported integrations with external data sources.
+ Ensure the ongoing inventory accuracy and integrity of CMDB data, implementing best practices and standards.
+ Regularly audit and reconcile CMDB data to maintain ongoing inventory accuracy and data quality.
+ Analyze and evaluate CMDB and discovery technologies across a broad spectrum of modern hardware and software IT assets
+ Perform day-to-day administration of the ServiceNow Discovery, including validating discovery results and troubleshooting discovery errors, discovery schedules, credentials, permissions and mid-servers
+ Identify opportunities for process improvement and automation within ServiceNow.
+ Provide input tothe CMDB and discovery product roadmaps, including cross-product and cross-organizational dependencies
+ Support key CMDB consumers such as IT service management processes,Enterprise Technology Currency management and SecOps and ensure alignment with business goals and regulatory requirements.
+ Support bi-annual ServiceNow Platform Upgrades
+ Stay up-to-date on ServiceNow releases and new capabilities, recommending enhancements that benefit the organization.
+ Continuously enhance knowledge / expertise in own area
+ Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
+ Prioritize and manage own workload to deliver quality results and meet assigned timelines
+ Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
+ Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
+ Establish effective relationships across multiple business and technology partners, program and project managers
+ Participate in knowledge transfer within the team and business units
**BREADTH & DEPTH**
+ Expert knowledge of IT security and risk disciplines and practices
+ Advanced knowledge of of organization, technology controls / security/ risk issues
+ May participate on complex, comprehensive or large projects and initiatives
+ Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
+ Generally reports to Senior Manager or above
**EXPERIENCE & EDUCATION**
+ Bachelor's Degree in Computer Science or Engineering or equivalent combination of education and experience.
+ Minimum 5 years of hands-on experience implementing, administering and optimizing ServiceNow ITOM (CMDB, Discovery, Service mapping).
+ Proven hands-on experience in optimizing discovery, tailoring patterns and development.
+ Proven hands-on experience monitoring, troubleshooting and remediating CMDB & Discovery related issues in large organizations including experience with any cloud service providers such as Azure, GCP or VMware.
+ Working knowledge of hybrid IT infrastructure, which combines on-premises, data center, and cloud-based operations including in-depth knowledge of networking.
+ Strong understanding of Networking principles, Server Administration concepts, Cloud Infrastructure and Middleware and Databases.
+ Knowledge of ServiceNow Common Services Data Model (CSDM) framework.
+ The following certifications would be considered as assets: Certified ServiceNow System Administrator (CSA), and Certified Implementation Specialist (CIS) in Discovery, Service Mapping, Vulnerability Response
+ Excellent analytical and problem-solving skills with the ability to troubleshoot complex technical issues;
+ Effective communication and interpersonal skills, with the ability to collaborate with stakeholders at all levels of the organization.
+ Demonstrated ability to work independently, prioritize tasks, and manage multiple issues and initiatives simultaneously.
+ Self-starter, positive attitude, and ability to problem-solve under minimal supervision
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more ( Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
**Language Requirement (Quebec only):**
Sans Objet
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Information Security Engineer
Posted 12 days ago
Job Viewed
Job Description
Insight Global is currently recruiting for an Information Security Engineer who will be responsible for ensuring the security, integrity, and availability of for the clients information assets. The candidate will contribute to the management and continuous improvement of multiple security programs. The position entails the development, implementation, and maintenance of security controls, through people, processes, and technology, across the organization.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: and Requirements
General
- Implement, maintain, and improve the security posture of the Microsoft 365.
- Maintain operational oversight of our security systems and administer secure configurations for both on-premise and cloud environments.
- Proactively manage system settings to counter evolving threats and safeguard enterprise systems and accounts.
- Actively monitor and assess new and emerging security threats. Recommend tactical and strategic initiatives that mitigate risks and keep our security posture ahead of the curve.
- Prepare and deliver periodic reports that highlight the current security posture of our Information Security Program.
- Ensure that all systems and processes comply with industry-recognized frameworks such as ISO 27001, NIST, CIS, and internal policies.
- Collaborate with IT Infrastructure, Operations, and other stakeholders to design and maintain secure, resilient enterprise-grade processes.
- Ensure that security requirements are integrated into IT services, balancing operational needs with risk management.
- Support regional internal and external audits related to IT security and compliance.
- Work with business services to ensure that security measures are effectively represented in client RFP responses and align with global standards.
- Contribute to the development, evaluation, and implementation of policies, standards, and procedures that meet both business and security requirements.
- Continuously refine technical processes to address the latest threats and compliance mandates.
Security Engineering
- Conduct technical architecture assessments to identify and mitigate risks.
- Translate business requirements into robust technical security controls.
- Develop, implement and maintain cloud security architectures, ensuring operational compliance (Azure expertise is a must).
- Leverage advanced Azure security features to architect and secure cloud deployments, ensuring compliance with best practices and regulatory standards.
- Author technical policies and develop SOPs to support secure architectural practices, with a focus on Azure and hybrid environments.
- Oversee patch deployment and secure configuration baselines for on-premise and cloud environments (Virtual Machines and Operating Systems).
- Ensure timely updates while minimizing downtime and risk.
- Perform regular audits (e.g., CIS, asset management, firewall rule review) to ensure compliance with internal policies and industry best practices.
- Conduct regular reviews and annual audits of firewall rules to ensure compliance with security policies, identify potential risks, and maintain optimal network protection.
- Provide recommendations to address audit findings and improve security controls.
- Develop and maintain secure configuration baselines for servers, endpoints, and network devices.
- Continuously monitor and remediate configuration drift.
- Manage and enhance privilege access controls, focusing on SecretServer or similar PAM solutions.
- Enforce least-privilege principles and monitor privileged accounts.
- Coordinate internal and external penetration testing efforts.
- Analyze results, prioritize remediation activities, and track corrective actions to closure.
Vulnerability Management Program
- Analyze threat and vulnerability feeds data for applicability to the environment and perform compensating controls analysis and validate efficacy of existing controls and provide recommendations.
- Perform security research, analysis, assessments and support with penetration testing and remediation actions.
- Conduct vulnerability assessments to evaluate attack vectors, identify vulnerabilities, and develop remediation plans.
- Work with IT stakeholders to guide and assist them during the remediation process.
- Monitor external security ratings and coordinate improvement efforts.
- Identify and address high-risk areas to strengthen overall security posture.
- Lead monthly vulnerability management meetings, assessments, and remediation coordination.
- Develop metrics and dashboards to track progress and highlight key risk areas.
Security Operations and Incident Management Program
- Assist the SOC team with daily operation of Information Security technologies.
- Assist with creating detailed runbooks and playbooks for incident response that integrate engineered solutions with operational procedures, ensuring quick and consistent responses to security events.
- Offer expert insights during and after incidents to identify root causes, recommend immediate fixes, and suggest long-term security improvements to prevent recurrence.
- Work closely with the security operations team to ensure that engineered systems meet operational needs, participate in incident drills, and provide training on new tools or technologies that enhance incident response capabilities.
- Handle spam/phishing requests, Mimecast URL exceptions, and data loss alerts.
- Act as an active participant within Incident Tabletop exercises
SKILLS & COMPETENCIES
- Strong written and oral communication skills.
- Strong stakeholder management skills and experience.
- Strong organizational skills with impeccable attention to detail.
- Strong situational analysis and decision-making skills, with experience balancing technical trade-offs.
- Demonstrates how to Act as One by being a team player across the Firm.
- Strong problem solving and analytical skills; can clearly explain and present problems and issues to others and contribute to their resolution.
- Ability to work under pressure and think clearly in challenging situations in a logical manner.
- Ability to be flexible in approach and be comfortable with a fluid organizational structure that requires both teamwork and self-sufficiency as necessary, with the ability to work under minimal supervision.
- Demonstrate initiative and the ability to be proactive, anticipating needs.
- Flexibility to accommodate working in multiple time zones.
EDUCATION, EXPERIENCE & CERTIFICATIONS
- Post-secondary education with a specialization in Information Technology and / or minimum of 6+ years of Information Technology experience in designing, developing, and maintaining IT cybersecurity solutions
- 6+ years of experience in an Information Security related role with at least 3 years of experience in cloud technologies, vulnerability and penetration testing.
- Advanced knowledge of Azure security features, architecture, and best practices for securing cloud deployments.
- Expertise in deploying patches and maintaining secure configuration baselines across on-premise and cloud environments.
- Proficient in coordinating and executing both internal and external vulnerability assessments and penetration tests.
- Experience in designing secure systems, conducting technical assessments, and translating business requirements into robust security controls.
- Knowledge in developing secure cloud security architectures.
- Competence in auditing systems against defined standards (e.g., CIS, NIST, ISO 27001) and preparing compliance reports.
- Familiarity with ITSM processes for ticket handling and incident response, including developing runbooks and incident playbooks.
- At least one relevant certification such as CISSP, CISM, or from GIAC/ISACA is required. null
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to
Information Security Officer
Posted 12 days ago
Job Viewed
Job Description
**Responsibilities:**
+ Perform security reviews on SaaS and PaaS products
+ Performing security assessment on Saas & Paas
+ Ability to engage in deep technical discussions with other Engineering groups, as well as ability to convey the same concepts and issues at an elevated level to senior leadership.
+ Ability to execute technical responsibilities, including, Design / Architecture reviews, Code / Configuration reviews and vulnerability assessment.
+ Develops security architecture, strategy, planning, and problem-solving solutions on an enterprise level.
+ Identify opportunities to automate and standardize information security controls and for the supported groups
+ Resolve any vulnerabilities or issues detected in an application or infrastructure
+ Analyze source code to mitigate identified weaknesses and vulnerabilities within the system
+ Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
+ Scan and analyze applications with automated tools, and perform manual testing if necessary
+ Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions
+ Direct the development and delivery of secure solutions by coordinating with business and technical contacts
+ Recommend security solutions according to Security Policy and Practices established by Citigroup.
+ Establish and maintain relationships with domain architects, project managers, and others within the technology development unit.
+ Maintains continuous awareness of business, technical, and infrastructure issues and acts as a sounding board or consultant to aid in the development of creative GCP security architecture solutions.
+ Interfaces with vendors to security assess their technology and to guide their product roadmap based on Citi's security requirements.
**Qualifications:**
+ 6-10 years of relevant experience as an ISO officer
+ Proficiency in application, architecture, information, and cyber security
+ Proficiency in one or more: GCP, AWS and Azure
+ Advanced proficiency with Microsoft Office tools and software
+ Consistently demonstrates clear and concise written and verbal communication
+ 5-10 years of experience in Application Security and/or Security Architecture
+ 5-10 years of experience Public & Private Cloud Security
**Education:**
+ Bachelor's degree/University degree in Information Security/Computer Science/Electrical, Mechanical Engineering /Information Technology or equivalent experience
+ Master's degree preferred
+ Professional certifications, such as CISSP and CSSLP, or willingness to obtain certification within 12-18 months of start date.
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required
**About Citi**
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We'll enable growth and progress together.
---
**Job Family Group:**
Technology
---
**Job Family:**
Information Security
---
**Time Type:**
Full time
---
**Most Relevant Skills**
Please see the requirements listed above.
---
**Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.
---
_Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._
_If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review_ _Accessibility at Citi ( _._
_View Citi's_ _EEO Policy Statement ( _and the_ _Know Your Rights ( _poster._
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
Be The First To Know
About the latest Cryptography Jobs in Canada !
Information security specialist
Posted 1 day ago
Job Viewed
Job Description
English
Education- Information technology
- Computer science
- Computer and information systems security/information assurance
Work must be completed both in person and remotely.
Work setting Credentials Certificates, licences, memberships, and courses Experience and specialization Type of service and repair Regulatory investigation Computer and technology knowledge Type of industry experience Area of specialization Additional information Transportation/travel information Benefits Health benefits Financial benefits Other benefits