Cybersecurity Risk Assessment & Mitigation: Conduct security and threat risk assessments, identify and monitor cybersecurity risks, maintain risk registers, and recommend risk mitigation strategies.
Cybersecurity Maturity & Continuous Improvement: Assess cybersecurity capabilities against recognized frameworks and industry best practices and recommend improvements to strengthen the organization's security posture
Governance, Policies & Standards: Develop, implement, and maintain cybersecurity policies, standards, governance frameworks, and data classification requirements to support business and regulatory objectives.
Compliance & Control Assurance: Assess security controls, manage compliance and exceptions, identify control gaps, and coordinate remediation activities to ensure adherence to regulatory, legal, and organizational requirements.
Audit & Regulatory Coordination: Support internal and external audits, assessments, and regulatory reviews, ensuring timely responses, evidence collection, and resolution of findings.
Third-Party & Vendor Risk Management: Conduct vendor risk assessments and due diligence, review procurement and contract documentation for security and privacy requirements, monitor third-party risks throughout the vendor lifecycle, maintain vendor risk inventories, and communicate risk findings and recommendations to stakeholders.
Cybersecurity Program & GRC Management: Support cybersecurity programs, projects, and initiatives, and administer and enhance governance, risk, and compliance (GRC) tools, processes, and reporting capabilities.
Reporting & Stakeholder Engagement: Develop reports, metrics, and presentations; communicate cybersecurity risks and recommendations; and collaborate with technical and business stakeholders to support informed decision-making.
Security Resilience & Incident Preparedness: Support the development, testing, and continuous improvement of cybersecurity incident response, business continuity, and disaster recovery plans and procedures.
Security Awareness & Data Protection: Promote cybersecurity awareness and secure practices across the organization, and support the enhancement of data protection capabilities, including Data Loss Prevention (DLP).
Cybersecurity Expertise & Continuous Improvement: Monitor emerging threats, technologies, and industry best practices, and serve as a subject matter expert on cybersecurity risk, governance, and compliance.
Promote a respectful work and service environment that supports diversity, inclusion, and is free from harassment and discrimination. Provide leadership in the development and implementation of inclusive and accessible policies, programs and/or services for employees and customers in accordance with TTC’s commitments and obligations under the Ontario Human Rights Code (OHRC) and Related Orders, the Accessibility for Ontarians with Disabilities Act (AODA), and TTC’s policies.
Participate in the TTC Ambassador Program.