CIBC

Sr. Director, Information Security

Toronto, ON Full time

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What you'll be doing 

The Senior Director, Information Security will be responsible for the operational aspects of risk identification within the organization. This role will play a crucial part in redefining assessment processes and optimizing the distribution of advisors across various lines of business and areas of expertise.

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. 

How You’ll Succeed

  • Risk Management: Redefine and enhance the methodologies for risk assessments, ensuring alignment with best practices and organizational objectives. Collaborate with Risk Advisors to establish effective processes for Threat Risk Assessments (TRAs), deviations, triages, penetration tests, and source code reviews. Oversee portfolio hygiene activities to maintain the integrity and effectiveness of risk management practices. Manage the Security Risk Management (SRM) functions, ensuring comprehensive oversight and reporting. Lead the Security Services Assessment (SSA) and Information Security Assessment (ISA) processes to identify and mitigate risks. Ensure compliance with SOC 2 requirements and manage the Center of Excellence (COE) for SOC 2. Provide expert consultation on contracts to ensure risk considerations are integrated into agreements. Lead coordination of application security testing and associated findings, action plan development and tracking. Monitor, assess and evaluate information security risk for third-party engagements. Consult on appropriate information security contract language for third parties. Attending risk, regulatory, or Technology leadership forums.
  • Cross functional relationships: Required to develop and maintain relationships with Technology leadership fostering relationships between Information Security functions and Technology management teams. Will be required to foster relationships with middle to senior management, and senior executives across a range of functions including Compliance, Internal Audit, Risk Management and Technology. Regular interaction with the Executive Committees where they are established. May be a member of a range of Technology committee’s and forums, representing Information Security. Fostering collaborative and supportive relationships that promote effective Information Security risk management and key information security initiatives. Interfacing and negotiating effectively with a wide range of audiences, including senior executives and senior management.
  • Leadership and Team Management: Providing clear, consistent leadership, advice and representation on all aspects of Information Security to leaders across the Enterprise, regions and subsidiaries. Demonstrating effective management, communication, and negotiation skills to drive complex initiatives towards completion including those with a cross functional dimension. Active participation in evaluating implementation of information security controls and requirements on Technology projects, providing challenge, insight and associated approvals. Working closely with Cyber Aggregation & Solution team to identify common themes and root causes for recurring information security challenges. Coordinate with and support Business and Tech Advisory teams on aspects of project threat risk assessments.

Who you are 

  • You can demonstrate 10+ years of experience in enterprise information security function including 5 years in a leadership role. Extensive experience in managing discrete cross-border work efforts, either directly as a people manager or through cross-functional leadership. You have advanced knowledge of applicable laws and regulations as they relate to Information Security and the effective management of Information Security Risks. You demonstrable experience in implementing strategic plans and managing an information security program. You have extensive experience in risk management, with a proven track record of leading teams and managing complex assessments.
  • You have a degree/diploma in Information or Technology Management or Risk Management or equivalent work experience.
  • You’re a certified professional. You have current accreditation and good standing like CISSP, CISM, CISA, at a prior financial institution of similar scope and scale
  • Your influence makes a difference. You know that relationships and networks are essential to success. You inspire outcomes by sharing your expertise.
  • You're motivated by collective success. You know that teamwork can transform a good idea into a great one. You know that an inclusive team that enjoys working together can bring a vision to life. 
  • You embrace and advocate for change. You continuously evolve your thinking and the way you work in order to deliver your best. Ability to apply and assess the impact of change management principles to initiatives of variable sizes and degrees of complexities on business financials and performance.
  • You are a caring and accountable leader. You have experience developing and implementing strategic team goals. You have experience coaching employees and inspiring successful team performance.
  • You're passionate about people. You find meaning in relationships and surround yourself with a diverse network of partners. You connect with others through respect and authenticity.
  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability. 

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com

  • CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).

  • We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 19th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Information Security, Information Technology (IT), Leadership, Security Policies, Security Strategy, Stakeholder Management