TOR Cyber & Resilience Exercise Planner/Facilitator
TDAbout the role
Work Location:
Charlotte, North CarolinaHours:
40Pay Details:
$87,000 - $151,000 USDTD is committed to providing fair and equitable compensation opportunities to all colleagues. The included salary range for this role takes into account multiple factors that are considered in making compensation decisions. The base pay actually offered may vary based upon candidate's skills and experience, job-related knowledge, licensure and certifications, geographic location, and other specific business and organizational needs. As TD puts career development at the forefront of our colleague experience, it is not typical for an individual to be hired at or near the top of the range for their role.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Line of Business:
Technology SolutionsJob Description:
This role will work as part of the Technology Operational Resilience (TOR) team within Enterprise Protect. The function of TOR is to ensure TD is ready and able to effectively prepare, prevent, respond, and recover from any issues that would impede TD's ability to deliver services to its employees and customers.
Job Description:
Exercise planners are key components in the organization’s strategy to improve cyber preparedness and reduce risk. Cyber Exercise Planners contribute to the training and coordination between various cyber security and technology organizations and the Bank's lines of business. Exercise Planners design, develop, facilitate and evaluate cyber exercises, working with various technology and cyber security defense teams as well as Business Information Security Officers. Exercise planners work to formally assess the current level of resilience for applications hosted within TD and hosted/provided via third parties using a standardized methodology and framework and identify cyber risks, design threat scenarios, identify key stakeholders and participants, and execute the exercise against the planned scenarios. Exercises range from discussion-based to operations-based exercises, to include range-based exercises. Planners will be expected to work in a dynamic, fast-paced environment to design multiple exercises on a yearly plan. Planners will receive broad exposure across multiple organizational units and levels of leadership. Applicants should have a proven track record of being able to navigate successfully across organizational lines, a solid foundation of cyber security knowledge and demonstrated performance designing and executing a variety of exercise types.
This leader will work across various technology teams and areas to formally assess the current level of resilience for applications hosted within TD and hosted/provided via third parties using a standardized methodology and framework. This including gaining a deep understanding of how the application is used within TD to understand the level of resilience that is required, identifying dependencies down through the infrastructure layers, identifying the application's ability to absorb and recover from impacts, and identifying specific actions that can be taken to raise the current resilience level.
Team responsibilities include:
Work across technology, cyber and business areas to identify opportunities to increase the resilience of TD
Work with technology owners to identify operational resilience risks in system design, operations and/or architecture
Collaboratively develop options to reduce identified resilience gaps and measure progress
Leverage industry relationships to understand best practices in technical resilience
Identify gaps and opportunities within cyber and operational resilience that allow appropriate risk visibility and management
Drive identification and development of standards to increase TD's technology resilience
Design and implement approaches to identify, measure and improve resilience in key areas such as technology concentration risk, third party provider risk, cloud risk, etc.
Depth & Scope:
Participates on complex, comprehensive or large projects and initiatives
Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
Has advanced knowledge of organization, technology controls / security/ risk issues
Education & Experience:
Bachelor's degree preferred
Information security certification / accreditation an asset
7+ years of relevant experience
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s