The Information Security Specialist defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools
Provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank
Participates on projects of moderate to high complexity
Provides complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area
Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
Requirements
Bachelor's degree preferred
Information security certification / accreditation an asset
7+ years of relevant experience
Expert knowledge of IT security and risk disciplines and practices
Familiarity with EDR, SIEM, and cloud security controls from an attacker’s perspective
Experience developing custom tooling in languages such as C#, Python, and PowerShell
Knowledge of red team infrastructure, domain management, and OPSEC best practices
Strong knowledge of Windows Active Directory environments, identity abuse, and enterprise authentication flows
Proven experience with common red team tooling (e.g., C2 frameworks, phishing platforms, custom payloads)
Solid understanding of network protocols, operating systems, and endpoint security controls
Relevant certifications (e.g., CRTO, OSCP, GXPN, Red Team Ops–focused certs)
Tech Stack
Cloud
Python
Benefits
health and well-being benefits
savings and retirement programs
paid time off (including Vacation PTO, Flex PTO, and Holiday PTO)