- Location
- 16 YORK ST:TORONTO, Canada
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Experience
- 5+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description
What is the opportunity?
RBC is seeking a Senior Security Principal Digital Platforms (Global Security) to be the embedded security accountability owner within our digital development. You will hold direct accountability for translating enterprise security policy, regulatory obligations, and threat intelligence into engineering-actionable requirements at the point of design and delivery, with authority to escalate and withhold release sign-off when necessary. The Senior Security Principal Digital Platforms will guide digital development teams on security strategy, adoption of secure design patterns, and ensure the organization delivers client-facing platforms that meet regulatory requirements and security standards.
What will you do?
- Sit embedded inside digital development teams' planning cadence as the named security risk owner, with accountability for platform risk registers, threat modeling outcomes, and incident retrospectives
- Shift security left by resolving threat modeling, secure design patterns, and control requirements at design review—not at pre-production gates—and own the exception process with time-boxed remediation commitments
- Protect our client trust surface by owning authentication/session integrity, fraud-security control alignment, API/partner integration security, and client data handling across retail, commercial, and wealth platforms
- Translate OSFI B-13, NYDFS Part 500, and PIPEDA/CPPA regulatory obligations into concrete engineering requirements and evidentiary artifacts produced during normal delivery
- Review AI-assisted and agentic client-facing capabilities against enterprise NHI and agentic trust architecture standards prior to client exposure
- Exercise escalation authority to withhold release sign-off pending remediation or documented risk acceptance at appropriate governance tiers
- Maintain a platform-level risk and control-maturity scorecard feeding enterprise board security reporting, translating technical findings into business-risk language for CRO/CIO/Legal audiences
- Influence and secure engineering commitment across teams outside your direct reporting line, driving security accountability into development velocity
What do you need to succeed?
Must-have
- 7–10+ years in cybersecurity with at least 5 years bridging security and software/product engineering
- Demonstrated ability to operate inside agile/product development environments—fluent in sprint planning, backlog grooming, and release activities
- Proven expertise in application and API security, secure SDLC, threat modeling methodologies (e.g., STRIDE), and cloud-native architecture patterns
- Direct experience with digital banking or regulated client-facing financial platforms, including payments, authentication, and fraud-adjacent controls
- Working knowledge of OSFI B-13, NYDFS 23 NYCRR Part 500, and PIPEDA/CPPA, with ability to translate regulatory requirements into engineering solutions independently
Nice-to-have
- Prior exposure to wealth management platforms, advisor identity risk, and high-net-worth data sensitivity
- Familiarity with open banking/API partner ecosystems, AI/agentic system security, or multi-jurisdictional regulatory experience (Canada/U.S.)
What’s in it for you?
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
- A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
- Leaders who support your development through coaching and managing opportunities
- Ability to make a difference and lasting impact
- Work in a dynamic, collaborative, progressive, and high-performing team
- Flexible work/life balance options
- Opportunities to do challenging work
- Opportunities to take on progressively greater accountabilities
- Access to a variety of job opportunities across business
#LI-post
#TECHPJ
Job Skills
Critical Thinking, Cyber Security Management, Decision Making, Detail-Oriented, Information Security Management, Information Technology Security, Interpersonal Relationship Management, IT Security Architecture, Performance Management (PM)Additional Job Details
Address:
City:
Country:
Work hours/week:
Employment Type:
Platform:
Job Type:
Pay Type:
Posted Date:
Application Deadline:
Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above
Our Employment Opportunities
At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.
Join our Talent Community
Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.
Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.
RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.