Senior Manager, Cyber Risk Assessments
Toronto-81 Bay, 29th Floor, Canada
CIBC
Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered.We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you'll be doing
The Senior Manager , Cyber Risk is an experienced professional responsible for fulfilling CIBC’s second line of defense mandate to support effective management of cyber security risk across the organization.
The role works closely with the first Line of Defense (LoD) and applies technical expertise to assess cyber risks identified by the 1st LoD (e.g., through red team, penetration tests) and challenges risk mitigation/treatment plans. In addition, the role involves assessment of application vulnerabilities, understanding the associated residual risk and collaborating with relevant 1st LoD teams to advise on risk-based prioritization and drive remediation.
The role also expects strong interpersonal, communication, and problem-solving skills to present conclusions to senior audiences, as well as keeping abreast with latest security threats and industry trends.
At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. Details on your work arrangement (proportion of on-site and remote work) will be discussed at the time of your interview.
How you’ll succeed
Risk Assessment - As a subject matter expert, the Senior Manager – Cyber Risk will be responsible for developing and operationalizing an assessment review process to enable consistent 2nd LoD review of application security related vulnerabilities and cyber risks identified by the 1st LoD.
An in-depth understanding and working knowledge of programming languages and application security fundamentals, (e.g., architectures, frameworks and standards) and secure coding practices.
Experience with implementing cyber security capabilities in relation to application security, penetration testing and/or red teaming programs within the organization.
Hands-on experience with managing application security scanning tools and technologies (e.g., SCA, SAST, DAST), with the ability to interpret scan results and determine associated risk.
Deep understanding of penetration testing, red team and threat modeling practices and experience in developing risk assessment review methodologies/processes to enable consistent evaluation of identified risks.
Critical thinking skills to evaluate the impact of identified security vulnerabilities and drive attack surface reduction.
Developer background with focus on security testing, as well as experience in performing penetration tests on applications is desirable.
Recognized cyber security certifications (e.g., CISSP, CEH, GIAC, OSCP) are preferred.
Effective communications – Demonstrates clarity of thought in both written and verbal communications and develops and delivers strong and simplified reporting content and presentations.
Advisory – Maintains an industry view of the broad cyber security landscape, understand best practice and performance benchmarks and monitor emerging cyber security trends. Provides guidance on the management of cyber risk when consulted, including risk mitigation strategies.
Relationships – Builds and sustains strong internal relationships and is viewed as a valued partner that offers sound and pragmatic guidance, demonstrates a deep understanding of their environment and context and facilitates productive risk discussions and outcomes.
Collaboration – TI&I Operational Risk is a highly matrixed team building upon cross functional strengths of all team members. The role leverages strong communication, interpersonal skills and teamwork to build and sustain strong internal relationships within Risk Management, Information Security, technology, business units and other enterprise functional groups.
Who you are
Strong knowledge of application development, application security and risk management, with in-depth understanding of application security best practices, testing and mitigation strategies.
Cooperative and innovative entrepreneurial team player with mature judgment, strong interpersonal skills and original approaches to problem resolution
Deals with ambiguity and is exceptionally adaptable and flexible
Thinking out of the box to make processes more efficient, focusing on bringing in automations and simplifications
You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.
Managing multiple activities with varying complexity in a sophisticated matrix environment organization while under time constraints
Maintaining productive and collaborative relationships with internal and external sources, colleagues and others to obtain, provide, verify and discuss information and best practices
Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential.
We work to recognize you in meaningful, personalized ways including a competitive compensation, a banking benefit*, wellbeing support and additional offers such as employee and family assistance programs and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
*Subject to program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit
We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Expected End Date
2025-02-12Job Location
Toronto-81 Bay, 29th FloorEmployment Type
RegularWeekly Hours
37.5Skills
Analytical Thinking, Application Security, Communication, Cybersecurity, DevOps, Emerging Technologies, Interpersonal Communication, Operation Risk Management, Penetration Testing, Prioritization, Red Teaming, Risk Assessments, Risk Management, Risk Management Programs, Secure Coding Practices, Security Testing, Teamwork, Technology Landscape* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Banking CEH CISSP DAST DevOps GIAC OSCP Pentesting Red team Risk assessment Risk management SAST Vulnerabilities
Perks/benefits: Career development Competitive pay Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.