Sr. Information Security Consultant, Threat Validation

Toronto-81 Bay, 19th Floor, Canada

CIBC

Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered.

View all jobs at CIBC

Apply now Apply later

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

This position can be primarily located in either Toronto (hybrid) or Ottawa (hybrid), Vancouver (hybrid) or Charlotte, NC (remote) depending on the successful candidate

What you’ll be doing

As a Sr. Consultant, Information Security, you will join a highly regarded Offensive Security team and build something incredible within Cyber Security, Third-Party and Resilience (CTPR). You will design, build  and operate an emerging Attack & Control Validation Program within the bank, publish the novel processes and findings for your select peers in information security, and help our partner lines of business achieve real security effectiveness. As a Sr. Consultant, Information Security, you will be working with our Offensive Security, Advanced Threat Detection, Detection Engineering and Exposure Management teams, and many other lines of business to validate and improve the effectiveness or our detections and controls through the execution of automated cyber attack scenarios.

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote

How you’ll succeed

  • Consulting –Your activities will be focused on designing and building a program from the ground up. Your ability to explain the importance and benefits of good security validation practices and consult with a wide variety of roles and lines of business across the bank will help accelerate our mandate to improve and mature our security posture. You will interact and experiment with a wide range of security technologies – both currently in use and in investigation at CIBC – to understand and describe how they can be used to detect and stop threats, and building the business case and benefits to onboard those tools and processes to maximum effectiveness.

  • Coordination – You will be responsible for coordinating the build activities with the different risk, technology and identity orgs within the bank.  When operational, you can effectively coordinating your validation scenarios with the our detection engineering, threat detection and our regional governance teams to provide assessments on the efficacy of new or proposed detections and controls, and respond to audit or regulatory requests.  In addition, you will provide valuable insight to our Exposure Management and reduction with validated attack paths and techniques that helps the bank prioritize it’s remediation plans for maximum effect.

  • Cyber Attack & Validation – You have experience building or operating a testing program and are familiar with cyber security testing techniques and software.  Familiarity with designing scenarios and tests to comprehensively validate a set of cyber controls and accurately reflect the risk of any gaps and help prioritize the improvements in the broader context of CIBC’s technology and security priorities.

Who you are

  • You can demonstrate experience in driving improvements and recommendation initiatives both within a security organization and across different lines of business. You have at least 3-4 years of overall Cyber Security and cyber controls experience. You bring 3+ years of product or program design/operation within a security operation or analysis function, and an understanding of how to leverage validation for enterprise defense. It’s an asset if you have familiarity with Advanced Persistent Threat (APT) activity and hold one of the following CISSP, CEH, OSCP, or OPST certifications.

  • You give meaning to data. You enjoy investigating the details of complex scenarios, and making sense of information. You're confident in your ability to communicate detailed information in an impactful way.

  • You act like an owner. You thrive when you're empowered to take the lead, go above and beyond, and deliver timely results.  You work well in a multi-discipline, matrix organization with stakeholders in multiple regions.

  • You embrace and champion change. You'll continuously evolve your thinking and the way you work in order to deliver your best.

  • You understand that success is in the details. You notice things that others don't. Your critical thinking skills help to inform your decision making and are able to convey why those details matter.

  • You look beyond the moment. You make decisions and take actions that will make a difference today and tomorrow. You proactively seek new opportunities to define what's possible.

  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.

**Prior to starting in this role, security checks, including a criminal record check must be successfully completed to the satisfaction of CIBC. An annual criminal record check may also be required.

#LI-TA

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 19th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Cybersecurity, Security Operations, Security Technologies, Security Testing, Threat Detection
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  2  0  0

Tags: APT Banking CEH CISSP Governance Offensive security OSCP Threat detection

Perks/benefits: Career development Competitive pay Startup environment Team events

Region: North America
Country: Canada

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.