Senior Social Engineering Threat Analyst
TD Bank
- Location
- Toronto, Ontario
- Work model
- On-Site
- Level
- Senior
- Salary
- $81.6k – $115.2k/yr
- Posted
- 1d ago
Skills
About this role
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs. As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description
Job Summary – Senior Social Engineering Threat Analyst (CP) The Senior Social Engineering Threat Analyst defines, develops, and implements Technology Controls and Information Security-related policies, programs, and capabilities focused on protecting TD customers, brand reputation, and digital channels from social engineering threats. This role provides specialized expertise and guidance in assessing cyber risks, identifying control gaps, and recommending security solutions to mitigate phishing, smishing, vishing, spoofing, impersonation, social media abuse, and other forms of customer-targeted fraud and social engineering activity. The role participates in projects of moderate to high complexity and delivers complex reporting, analysis, and assessments at the functional, business line, or enterprise level within their area of responsibility. The individual serves as a subject matter expert in customer protection operations and partners closely with Fraud, Cyber Security, Brand Protection, Telecommunications, Digital Channels, Legal, and external industry partners to reduce customer exposure and strengthen organizational resilience.
Key Responsibilities
Assess, investigate, and respond to customer-targeted social engineering threats, including phishing, smishing, vishing, impersonation, spoofing, and other digital fraud campaigns. Lead digital risk protection activities by identifying, analyzing, and disrupting malicious domains, phishing infrastructure, fraudulent websites, social media abuse, and brand impersonation targeting TD customers and assets. Monitor emerging threat activity, analyze threat actor tactics and trends, and provide actionable intelligence and risk-based recommendations to strengthen customer protection capabilities and security controls. Produce complex reporting, threat assessments, and strategic insights for leadership, stakeholders, and partner teams to support informed risk management and decision-making. Develop, maintain, and continuously improve operational processes, playbooks, controls, and automation solutions that enhance the effectiveness and scalability of customer protection operations. Collaborate with Cyber Security, Fraud, Digital, Telecommunications, Legal, Brand Protection, and external industry partners to coordinate investigations, mitigation efforts, and threat disruption activities. Participate in projects of moderate to high complexity involving technology controls, information security risk, customer protection strategy, and operational transformation initiatives. Qualifications / Education & Experience Bachelor's degree preferred but not required. Information Security, Cybersecurity, Fraud, Intelligence, or related certification/accreditation is considered an asset. Typically 5–7 years of relevant experience in cybersecurity operations, information security, digital risk protection, fraud investigations, threat intelligence, or technology risk. Experience investigating phishing, smishing, vishing, social media abuse, impersonation campaigns, or digital brand protection incidents required. Experience working across multiple