About The Position

RBC is seeking a Senior Security Principal Digital Platforms (Global Security) to be the embedded security accountability owner within our digital development. You will hold direct accountability for translating enterprise security policy, regulatory obligations, and threat intelligence into engineering-actionable requirements at the point of design and delivery, with authority to escalate and withhold release sign-off when necessary. The Senior Security Principal Digital Platforms will guide digital development teams on security strategy, adoption of secure design patterns, and ensure the organization delivers client-facing platforms that meet regulatory requirements and security standards.

Requirements

  • 7–10+ years in cybersecurity with at least 5 years bridging security and software/product engineering
  • Demonstrated ability to operate inside agile/product development environments—fluent in sprint planning, backlog grooming, and release activities
  • Proven expertise in application and API security, secure SDLC, threat modeling methodologies (e.g., STRIDE), and cloud-native architecture patterns
  • Direct experience with digital banking or regulated client-facing financial platforms, including payments, authentication, and fraud-adjacent controls
  • Working knowledge of OSFI B-13, NYDFS 23 NYCRR Part 500, and PIPEDA/CPPA, with ability to translate regulatory requirements into engineering solutions independently

Nice To Haves

  • Prior exposure to wealth management platforms, advisor identity risk, and high-net-worth data sensitivity
  • Familiarity with open banking/API partner ecosystems, AI/agentic system security, or multi-jurisdictional regulatory experience (Canada/U.S.)

Responsibilities

  • Sit embedded inside digital development teams' planning cadence as the named security risk owner, with accountability for platform risk registers, threat modeling outcomes, and incident retrospectives
  • Shift security left by resolving threat modeling, secure design patterns, and control requirements at design review—not at pre-production gates—and own the exception process with time-boxed remediation commitments
  • Protect our client trust surface by owning authentication/session integrity, fraud-security control alignment, API/partner integration security, and client data handling across retail, commercial, and wealth platforms
  • Translate OSFI B-13, NYDFS Part 500, and PIPEDA/CPPA regulatory obligations into concrete engineering requirements and evidentiary artifacts produced during normal delivery
  • Review AI-assisted and agentic client-facing capabilities against enterprise NHI and agentic trust architecture standards prior to client exposure
  • Exercise escalation authority to withhold release sign-off pending remediation or documented risk acceptance at appropriate governance tiers
  • Maintain a platform-level risk and control-maturity scorecard feeding enterprise board security reporting, translating technical findings into business-risk language for CRO/CIO/Legal audiences
  • Influence and secure engineering commitment across teams outside your direct reporting line, driving security accountability into development velocity

Benefits

  • bonuses
  • flexible benefits
  • competitive compensation
  • commissions
  • stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • Flexible work/life balance options
  • Opportunities to do challenging work
  • Opportunities to take on progressively greater accountabilities
  • Access to a variety of job opportunities across business
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service