Skip to content
← Back to job listings

Information Security Specialist (Security Posture Insights, Reporting and Remediation)

The Toronto-Dominion Bank (Canada) · Toronto, ON, Canada

IT - Network / Systems / DB AdminExternal listingfull-timeabout 1 hour ago

About The Role

TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.

As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.

Job Description

The Information Security Specialist – Security Posture Insights, Reporting and Remediation is responsible for turning infrastructure configuration and cyber technology compliance data into trusted insights, decision-ready reporting and measurable remediation outcomes. The role identifies material control gaps, assesses trends and root causes, prioritizes issues based on risk and business impact, and works with accountable technology owners to drive remediation within established timelines. As a key business and product partner for the ServiceNow Configuration Compliance Management module, the specialist defines reporting and workflow requirements, uses the platform to manage findings through closure, and develops dashboards, metrics and executive insights that improve accountability and risk decisions. The role also advances AI-enabled security insights and risk management by improving data quality, automating analysis and reporting, and enabling responsible use of predictive signals and remediation recommendations. The role reports to the Senior Manager, Security Compliance and Operations Management and works across infrastructure security governance, security engineering, technology operations, ServiceNow delivery, asset management, risk and audit teams.

​ ​ Role and Responsibilities ​

  • Analyze infrastructure configuration, asset, security tool and control data to identify material compliance gaps, recurring trends, emerging risks and systemic root causes across server, workstation, network, database, middleware, cloud and container environments.
  • Produce accurate, timely and decision-ready operational and executive reporting on security posture, including compliance performance, control coverage, configuration drift, issue aging, remediation progress, threshold breaches, exceptions and residual risk.
  • Develop and maintain dashboards, scorecards, KRIs, KPIs and management insights that clearly communicate what is non-compliant, why it matters, who is accountable, the required action and when remediation is due.
  • Use ServiceNow Configuration Compliance Management as the system of record for findings, ownership, remediation tasks, service-level commitments, exceptions, evidence, validation, escalation and closure.
  • Define and prioritize ServiceNow Configuration Compliance requirements for data ingestion, findings normalization, assignment logic, remediation workflows, notifications, escalations, dashboards, metrics and executive reporting.
  • Develop actionable insights from ServiceNow Configuration Compliance, CMDB, Splunk and security assessment tools by correlating compliance gaps with asset criticality, exposure, business context, control criticality and remediation history.
  • Establish risk-based prioritization and reporting models that direct remediation capacity to the gaps with the greatest potential business and security impact.
  • Work directly with accountable technology and remediation owners to establish corrective action plans, clarify deliverables and due dates, resolve blockers, monitor progress, validate remediation evidence and confirm sustainable closure.
  • Lead governance routines for outstanding gaps, including remediation reviews, aging analysis, challenge of recovery plans, dependency management and escalation of overdue or material issues to accountable leaders and risk partners.
  • Identify systemic or recurring gaps and recommend broader corrective actions, including process improvements, engineering fixes, configuration baselines, automation, ownership changes and preventative controls.
  • Validate reporting completeness and accuracy by reconciling authoritative asset inventories, source-tool results, ServiceNow records and remediation evidence; investigate data quality or control coverage gaps that could affect management decisions.
  • Partner with ServiceNow platform, data and engineering teams to improve Configuration Compliance integrations, analytics, workflow performance and reporting usability.
  • Drive the roadmap toward AI-enabled security insights and risk management, including anomaly detection, trend forecasting, root-cause analysis, predictive risk indicators, automated executive summaries and risk-based remediation recommendations.
  • Define data quality, validation, explainability, human oversight, access and governance requirements so AI-assisted insights and recommendations are trusted, traceable and appropriate for risk decisions.
  • Develop automation requirements that reduce manual analysis, improve reporting timeliness, accelerate issue assignment and escalation, and increase remediation velocity.
  • Maintain clear data definitions, reporting standards, control mappings, remediation procedures, RACIs, evidence requirements and decision records that support consistent operations and an auditable trail.
  • Provide concise, traceable evidence and reporting for senior management, second-line risk, audit and regulatory requests, clearly distinguishing current posture, open gaps, remediation commitments and residual risk.
  • Maintain a prioritized backlog and roadmap for insight generation, reporting modernization, ServiceNow Configuration Compliance improvements, remediation enablement and AI-assisted analytics.

Qualifications

  • University or post-graduate degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, Data Analytics or a related discipline is an asset.
  • Seven or more years of experience in cybersecurity, technology compliance, security posture management, infrastructure security, risk reporting, remediation management or security operations.
  • Demonstrated ability to transform complex security and technology data into actionable insights, concise executive reporting and clearly prioritized remediation actions.
  • Advanced analytical skills, including data correlation, trend and aging analysis, root-cause identification, risk prioritization, data reconciliation and interpretation of KRIs, KPIs and control effectiveness measures.
  • Hands-on experience developing dashboards, scorecards and operational or executive reports that communicate material gaps, ownership, due dates, progress, dependencies and residual risk.
  • Experience driving remediation with technology owners, including corrective action planning, milestone tracking, blocker resolution, evidence validation, challenge, escalation and closure.
  • Experience with ServiceNow Security Operations capabilities; experience using or defining requirements for the ServiceNow Configuration Compliance Management module, CMDB, findings workflows, remediation tasks, dashboards and integrations is strongly preferred.
  • Experience using security assessment and posture data from tools such as Qualys, CrowdStrike, Wiz, Azure Policy, Tenable, AppOmni , Splunk or comparable platforms.
  • Strong understanding of configuration compliance, control completeness and correctness, asset inventory, configuration drift, exception management, service-level commitments and risk-based remediation.
  • Ability to assess reporting accuracy and data quality across multiple sources and explain the limitations, assumptions and risks that could affect management decisions.
  • Working knowledge of AI and machine-learning use cases for security analytics, including anomaly detection, summarization, recommendations and predictive risk signals, with an understanding of explainability, validation, governance and human oversight.
  • Ability to communicate complex technical and risk information in concise business language for technology owners, senior leaders, risk partners, auditors and regulators.
  • Experience coordinating cross-functional delivery across security governance, security engineering, technology operations, asset management, data, platform teams and first- and second-line risk functions.
  • Strong organizational, prioritization and influencing skills, with the ability to establish accountability, manage competing remediation priorities and deliver outcomes with limited supervision.
  • Experience working within Agile delivery frameworks and using tools such as Jira is an asset.

Certifications

  • Completion of at least three of the following: GIAC (GCIA, GPEN, GWAPT, GCIH, GSEC and etc ), CCNP, CCNA, CISSP,CCSP , CISM, CISA

Who We Are

TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we strive to make every interaction, product, and experience remarkably human and refreshingly simple for over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to foster deeper relationships, ensure disciplined execution, and build a simpler, faster banking experience. TD is deeply committed to being a leader in client experience, that is why we believe that all colleagues, no matter where they work, are client facing. Together, we are reimagining what banking can be for our clients, colleagues and communities.

Our Total Rewards Package

Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more

Additional Information

We’re delighted that you’re considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we’re committed to providing the support our colleagues need to thrive both at work and at home.

Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.

Colleague Development

If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities.

If you’re passionate about helping clients and building deep, lasting relationships, TD offers diverse career paths where you can grow your expertise and make a meaningful impact.

We're committed to your success and foster a respectful workplace where diverse perspectives are valued, everyone has fair opportunities to grow, and you can unlock your full potential to achieve your career goals. Here at TD, we hire and develop the best.

Training & Onboarding

We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.

Interview Process

We’ll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.

Accommodation

Your accessibility is important to us. Please let us know if you’d like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.

We look forward to hearing from you!

Language Requirement (Quebec only)

Sans Objet

This is an external listing. JobSpring does not represent or verify the employer. Report this listing