Information Security Specialist Full-time Job
Jul 8th, 2024 at 14:20 IT & Telecoms Toronto 95 views Reference: 7779Job Details
We are looking for a dedicated and proactive individual to join us and lead our Infrastructure Vulnerability Management program. You will oversee the development, enhancement and document of Vulnerability Management tools and processes. We will look to you to help create the external attack surface asset mapping strategy to protect TD's critical assets. In addition, you will act as a liaison between the security team and business partners to facilitate communication and collaboration and drive a culture of proactive vulnerability management.
Meaningful work is fueled by meaningful performance and career development conversations with your manager. Here's some of what you may be asked to perform:
Responsibilities
- Manage vulnerabilities across asset domains, including infrastructure, applications, Cloud, and COTS.
- Develop the external attack surface asset mapping strategy to guardrail critical assets.
- Collaborate with stakeholders to ensure seamless data flow and accurate reporting.
- Manage complex concurrent vulnerability management initiatives in an efficient manner.
- Partner with the Infrastructure Vulnerability Management teams and other stakeholders to develop the future VM state across the bank.
- Provide the consulting services for automated patching solution, exception process, patching SLA, and patching governance.
- Strategize and formulate the automated processes for technology asset owners to onboard assets to VM program, self-served reporting, and expedited patching validation.
- Partner with Engineering team for tooling Proof of Concept support and implement recommended tools for Infrastructure Vulnerability Management program.
- Strategize and formulate the unified risk scoring methodology across both infrastructure and applications realm.
- Establish and maintain the security metrics and reporting mechanisms to monitor and communicate the status and progress of vulnerability management initiatives.
- Foster strong working relationships across various business units, ensuring alignment and support for vulnerability management efforts.
- Provide guidance and support to business units in understanding and addressing vulnerabilities.
- Educate and influence employees at all levels to prioritize security and participate in vulnerability mitigation.
- Identify opportunities for process improvements and implement solutions to enhance the effectiveness of the vulnerability management program.
Qualifications
- 4-6 years of relevant experience within any of the following areas: Infrastructure Vulnerability Management, Cloud or Application Security.
- Completion of a University Degree or equivalent program in Computer Science, Management Information Systems, or similar field
- Experience driving priorities for patching team and hosting areas patching (VMWare, Firmware, etc.)
- Experience with ServiceNow reporting product.
- Hands-on experience with JIRA, Confluence and Tableau.
- Advanced knowledge of scripting language, such as python.
- Ability to influence and negotiate with others using soft skills in a matrixed environment.
- Demonstrated ability to participate in and lead complex, comprehensive or large projects and initiatives.
- Ability to apply agile methodology & accurate logic and common sense in making decisions.
- Ability to quickly analyze large amounts of information and formulate action plans based on that analysis.
- Excellent written and oral communications skills and ability to articulate and present information to all levels of management and staff.
Certifications
- Possess one or more of security certifications, such as CISSP, CCSP, or CRISC