Sr. Consultant, Data Security Operations
Toronto-81 Bay, 19th Floor, Canada
CIBC
Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered.We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you’ll be doing
As a Sr. Consultant, Data Security Operations, you will join CIBC's Cybersecurity, Third-Party and Resilience (CTPR) department and manage key data security processes and controls and will deliver improvements in how data security is managed and reported across CIBC. You will work and collaborate with data owners, data custodians, and other stakeholders and programs to ensure the direction is adhered to. You will ensure data security practices operate effectively and that data security exposures are resolved and remediated in an timely and efficient manner to mitigate risk. You will also execute data security operations services related to Data Discovery, Data Classification, and Data Protection.
At CIBC we enable the work environment most optimal for you to thrive in your role you’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.
How you’ll succeed
Data Security Operations - Operate within service levels and risk metrics to monitor effective implementation of data security key controls via the services. Provide consultation to projects regarding Data Security controls to advise on data exposures and participate in strategy and roadmap development for data security services.
Communication – Build and present documentation to executive management aimed at communicating benefits of proposed security programs, as well as on current potential risks along with recommendations. Provide awareness and training to application development teams of the benefits of web application layer protection services, data protection services, code scanning services, etc. Assess business needs against potential data security risks and provide your recommendations to enhance our information security risk exposure.
Advisory and Relationship Management - Working with the broader team, act as a trusted advisor to influence the application development, operational and infrastructure teams to build security into their design, development and scanning techniques, and to prioritize security vulnerabilities identified using a risk-based approach. Assist in the identification, assessment, reporting, and management of security risks identified in key applications with practical and achievable recommendations. Stay on top of the latest threat landscape and maintain relationships with peers from other banks.
Data Protection Services - Support the Digital Crown Jewels (DCJ) activities including DCJ assessment, onboarding, and reporting. Support technology peers in providing security services, specific to data identification, classification and protection. Measure the quality of the service and conduct threat update reviews, analysis of logs, trends and usage reports. Drive the improvement in the level of security protection for our enterprise data, specifically Digital Crown Jewels and critical assets.
Who you are
You can demonstrate experience in data security concepts in a senior level role. You have implemented data identification & protection methodologies to ensure secure design of applications and protection of confidential data. You have been a key contributor or have led data security initiatives (e.g., data discovery/classification, encryption/tokenization), data loss prevention) and have a working understanding of data governance and data privacy concepts. It’s an asset if you have current accreditation and good standing CISSP, CISA, or CISM designation.
You are passionate about industry application security, vulnerability management, and data security standards and best practices.
You develop strong relationships across various levels of an organization to bring about a positive result and communicate requirements effectively.
You understand that success is in the details. You notice things that others don't. Your critical thinking skills help to inform your decision making.
You embrace and champion change. You'll continuously evolve your thinking and the way you work in order to deliver your best.
You give meaning to data. You enjoy investigating complex problems, and making sense of information. You're confident in your ability to communicate detailed information in a meaningful way.
Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
Toronto-81 Bay, 19th FloorEmployment Type
RegularWeekly Hours
37.5Skills
Data Discovery, Data Protection, Data Security, Security Controls, Stakeholder Management* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Banking CISA CISM CISSP Encryption Governance Privacy Strategy Vulnerabilities Vulnerability management
Perks/benefits: Career development Competitive pay Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.