Audit Director, Cybersecurity
Toronto-81 Bay, 34th Floor
CIBC
Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered.We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you’ll be doing
As a key member of the Internal Audit department, the Audit Director, Cybersecurity leads the development and implementation of the strategy for testing controls related to cybersecurity. This includes areas related to the protection of data held internally or at third parties. The Director will work collaboratively with auditors to determine approaches for reviewing controls related to cybersecurity. In select audits with a high degree of risk or complexity related to cybersecurity, the Director will test for controls related to cybersecurity risk. You will maintain an awareness of emerging risks and regulatory requirements related to cybersecurity in all jurisdictions where CIBC conducts business. You will develop and maintain a perspective on the strength of controls related to cybersecurity and will periodically provide insights and opinions on these for reporting to senior management and the Audit Committee. The role exercises a high degree of independent judgement to keep stakeholders informed regarding identified and existing internal control weaknesses and recommended solutions. The role drives innovation across areas of responsibility, applying expert interpersonal, communication, and problem-solving skills.
At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.
How you’ll succeed
Get Engaged and Build Relationships – Get to know about the audits in execution and how cybersecurity risk affects the different business units of CIBC. Build relationships with the entire Internal Audit department and become the focal point for cybersecurity risk.
Coach and Collaborate – Work in partnership with other auditors to provide insights, guidance and judgement on testing of cybersecurity risk. Help others develop their understanding of cybersecurity risk so they can better recognize and test cybersecurity risk.
Reflect and Strategize – As cybersecurity risk evolves and requirements change, stay informed on corresponding control requirement changes. Be forward-looking and ensure the audit coverage of cybersecurity risk evolves with the regulatory and threat landscape.
Who you are
You have 8+ years of Cybersecurity and/or Audit experience and can demonstrate having a broad and deep knowledge and understanding of NIST controls and Information Security and Cybersecurity risks associated with technology infrastructure, networks, system access and security, cloud technology, regulatory requirements. You will also have knowledge of auditing practices, procedures and principles that enable you to analyze business processes, assess risks, and select the most suitable audit approach. You must have proven ability to write comprehensive and concise reports that have been utilized by senior leadership.
You’re a certified professional. You have a current accreditation in at least one or more of the following (or equivalent): CISA – Certified Information Systems Auditor; CISSP – Certified Information Systems Security Professional; In-depth knowledge of COBIT and working knowledge of ITIL, ISO and NIST frameworks.
You love to learn. You're passionate about growing your knowledge, and you know that there is no limit to what you can achieve.
You understand that success is in the details. You notice things that others don't. Your critical thinking skills help to inform your decision making.
You give meaning to data. You enjoy investigating complex problems, and making sense of information. You're confident in your ability to communicate detailed information in an impactful way
You're driven by collective success. You know that collaboration can transform a good idea into a great one. You understand the power of an inclusive team that enjoys working together to bring a shared vision to life.
Values matter to you. You bring your real self to work and you live our values – trust, teamwork and accountability.
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
Toronto-81 Bay, 34th FloorEmployment Type
RegularWeekly Hours
37.5Skills
Audit Management, Internal Controls, Leadership, Operating Effectiveness, People Management, Risk Based Auditing, Risk Management and Mitigation, Strategic Objectives* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Banking CISA CISSP Cloud COBIT ITIL NIST NIST Frameworks Risk management Strategy
Perks/benefits: Career development Competitive pay Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.