TD Bank Sr InfoSec Specialist - Application Security Program Lead in Wilmington, Delaware
Auto req ID 213392BR
Job Title Sr InfoSec Specialist - Application Security Program Lead
Job Status Full Time
Country United States
Location Wilmington - Market Street
Business line TD Bank AMCB
Job Category - Primary Technology Solutions
Job Category(s) Technology Solutions
TD Description About TD Bank, America's Most Convenient Bank®
TD Bank, America's Most Convenient Bank, is one of the 10 largest banks in the U.S., providing more than 8 million customers with a full range of retail, small business and commercial banking products and services at approximately 1,300 convenient locations throughout the Northeast, Mid-Atlantic, Metro D.C., the Carolinas and Florida. In addition, TD Bank and its subsidiaries offer customized private banking and wealth management services through TD Wealth®, and vehicle financing and dealer commercial services through TD Auto Finance. TD Bank is headquartered in Cherry Hill, N.J. To learn more, visit www.tdbank.com. at http://www.tdbank.com/ Find TD Bank on Facebook at www.facebook.com/TDBank and on Twitter at www.twitter.com/TDBank_US .
TD Bank, America's Most Convenient Bank, is a member of TD Bank Group and a subsidiary of The Toronto-Dominion Bank of Toronto, Canada, a top 10 financial services company in North America. The Toronto-Dominion Bank trades on the New York and Toronto stock exchanges under the ticker symbol "TD". To learn more, visit www.td.com at http://www.td.com/ .
Building a World-Class Technology Team at TD
We can't afford to be boring. Neither can you. The scale and scope of what TD does may surprise you. The rapid pace of change makes it a business imperative for us to be smart and open-minded in the way we think about technology. TD's technology and business teams become more intertwined as new opportunities present themselves. This new era in banking does not equal boring. Not at TD, anyway.
TD Information Security covers the development and management of security strategies, policies and programs to assess, prioritize, and mitigate business risk with technology controls. Priorities include: mitigating and managing cyber security threats, ensuring systems availability, aligning with global regulatory risk and compliance requirements, managing systems and network complexity, and partnering with businesses for better technology delivery by providing advice on technology controls.
There's room to grow in all of it.
About This Role
We are looking for someone to lead and provide sound counsel on development and implementation of significant enterprise-wide Technology Controls and Information Security strategies, policies, programs and tools. As part of this, you'll oversee control and governance activities and identify and assess potential security risks, vulnerabilities that impact highly complex, high-risk businesses or transformational strategic initiatives. You'll have significant exposure to executives and functional stakeholders enterprise-wide if you prove to be the winning candidate.
Meaningful work is fueled by meaningful performance and career development conversations with your manager. Here are the essential job functions of this position:
Provide technical leadership on a range of specific Technology Controls and Information Security programs, policies, standards and incidents.
Lead risk assessment, required controls definition, control procedure appropriateness, vulnerability assessments and any other relevant areas.
Conduct comprehensive risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and enterprise-wide, risk mitigation and remediation plans, remediation strategy document or provide information security solutions to address risks.
Contribute to the definition, development, and oversight of a global security management strategy and framework.
Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging security threats against TDBG’s business.
Provide guidance and/or lead on the development of on-going technology risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area.
Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area.
Act as primary practice / technical expert and proactively work with technology partners and stakeholders and service/platform owners to ensure all technology security components are integrated into the bank’s overall Enterprise Architecture, and any control gaps are addressed.
Proactively review internal processes and activities and identify opportunities for improvement.
Adhere to, advise on, oversee, monitor, enforce enterprise frameworks and methodologies related to technology controls and information security activities.
Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.
Remain informed of emerging issues, industry trends and/or relevant changes.
Other duties as assigned
• Driving Requirements:
• Travel Requirements:
What can you bring to TD? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention. Here are the minimum requirements for this position:
Information Security Certification / Accreditation an asset.
10+ years of relevant experience and are equipped to provide technical leadership to a larger team portfolio.
Comfortable operating as a technical expert with deep knowledge of IT security and risk disciplines and can foresee issues and identify emerging industry trends.
Advanced and highly-specialized knowledge of the business, technology controls / security/ risk issues.
Experience working on high-profile, complex and/or high-risk technology projects with significant impact to the organization.
Ability to demonstrate technical leadership to a larger team portfolio.
Must be eligible for employment under regulatory standards applicable to the position.
Here are the preferred qualifications for this role:
Experience building Application Security program strategy, standards and compliance functions
Working knowledge of application security assessment tools and techniques (SAST, DAST, SCA, Pen Testing)
Ability to analyze security issue data for prevention and remediation strategies
Understanding of Open Source Software technical risk and license risk
Experience with secure development training techniques
Exposure to incident response and/or threat intelligence, a plus
At TD, we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. We are dedicated to building a workforce that reflects the diversity of our customers and communities in which we live in and serve, and creating an environment where every employee has the opportunity to reach her/his potential.
If you are a candidate with a disability and need an accommodation to complete the application process, email the TD Bank US Workplace Accommodations Program at USWAPTDO@td.com . Include your full name, best way to reach you, and the accommodation needed to assist you with the application process.
EOE/Minorities/Females/Veterans/Individuals with Disabilities/Sexual Orientation/Gender Identity.
**Province/State (Primary) Delaware
City (Primary) Wilmington