Director, Cyber Risk, Portfolio Management

Toronto-81 Bay, 31st Floor

CIBC

Bank on your terms with CIBC – whether it’s in person, over the phone or online, CIBC has you covered.

View company page

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What you’ll be doing

The Director, Cyber Risk, Portfolio Management will execute GORM operational risk program and practices related to Identification, Measurement, Mitigation and Monitoring & Reporting of operational risk, including technology, information security/cyber, data, business interruption, physical security and project risk, across TI&I business units and domains  such as technology infrastructure, application delivery, data management, architecture, and cybersecurity. In this capacity, the director will work closely with their information security, technology and risk partners across the company to manage cyber risk with a consistent and collaborative approach.

The role applies leadership skills and technical expertise to ensure that effective processes are in place to identify, manage, measure, monitor, and control cyber security risk. In addition, the role provides continuous improvement leadership with respect to operational risk management methodologies and practices. The role drives innovation across all areas of responsibility, applying expert interpersonal, communication, and problem-solving skills.

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. Details on your work arrangement (proportion of on-site and remote work) will be discussed at the time of your interview.

How you’ll succeed

  • Risk management: As a people leader, the Director, Cyber Risk, Portfolio Management reviews operational practices, risk assessments, controls, deficiencies, metrics, and other relevant information to form an independent view of information security/cyber risks and perform effective challenge. A risk-based approach is leveraged to understand and manage risk of technology-related activities to ensure alignment to operational risk management policies and framework and CIBC risk appetite. In alignment with GORM’s operational risk management program and practices, this includes independent assessment of business lines on activities such as projects (CIRAs), risk and controls self-assessments (RCSAs), Operational Incidents, RAS and KRI development and monitoring, etc. using operational risk tools and processes. The Director leverages strong data and analytical skills to perform detailed research to produce risk insights on current and emerging technologies for distribution to various internal audiences.  Impactful and insightful risk reporting is produced for presentation to senior leaders within CIBC.
  • Technical expertise – Brings instant credibility by skillfully leveraging strong breadth of information/cyber security experience and depth of knowledge in key technology, cyber and data domains, including strong knowledge of cyber security frameworks, standards, regulations (B13) and best practices such as NIST, ISO, COBIT, etc. Industry recognized technology certifications in their Subject Matter Expertise are preferred such as CISM, CISSP etc.
  • Effective communications – Demonstrates clarity of thought in both written and verbal communications and develops and delivers strong reporting content, presentations and assessment summaries on an ongoing basis for senior audiences and risk committees up to and including the Board.
  • Advisory – Maintains an industry view of the broad cyber security landscape, understand best practice and performance benchmarks and monitor emerging cyber security trends. Provides guidance on the management of information/cyber security risk when consulted, including risk mitigation strategies.
  • Relationships – Builds and sustains strong internal relationships and is viewed as a valued partner that offers sound and pragmatic guidance, demonstrates a deep understanding their environment and context and facilitates productive risk discussions and outcomes. Closely tracks status of key initiatives and programs to clearly understand, challenge and influence program objectives to ensure objectives are met and risk is reduced.
  • Collaboration – TI&I Operational Risk is a highly matrixed team building upon cross functional strengths of all team members.  The Director leverages strong communication, interpersonal skills and teamwork to build and sustain strong internal relationships within Risk Management, technology business units and other enterprise functional groups.

Who you are

  • Strong knowledge of the regulatory environment and risk management
  • Cooperative and innovative entrepreneurial team player with mature judgment, strong interpersonal skills and original approaches to problem resolution
  • Deals with ambiguity and is exceptionally adaptable and flexible
  • Thinking out of the box to make processes more efficient, focusing on bringing in automations and simplifications
  • You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.
  • Managing multiple activities with varying complexity in a sophisticated matrix environment organization while under time constraints
  • Strong leadership skills and focus on coaching and developing the team
  • Maintaining productive and collaborative relationships with internal and external sources, colleagues and others to obtain, provide, verify and discuss information and best practices
  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.

    What CIBC Offers

    At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

    • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

    • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

    • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

    *Subject to plan and program terms and conditions

    What you need to know

    • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com

    • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

    • We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

    Job Location

    Toronto-81 Bay, 31st Floor

    Employment Type

    Regular

    Weekly Hours

    37.5

    Skills

    Analytical Thinking, Analytical Thinking, Bank Regulations, Business Units, Client Security, Continuous Improvement Techniques, Cross-Functional Teamwork, Cyber Risks, Cybersecurity, Cybersecurity Risk Management, Emerging Risks, Group Problem Solving, Information Security, IT Policies, Leadership, Operational Risk Assessment, Operational Risk Management, Operational Risk Mitigation, Operational Risks, People Management, Project Risks, Regulatory Compliance, Regulatory Risk, Risk Analytics, Risk Management {+ 4 more}
    Apply now Apply later
    • Share this job via
    • or

    * Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

    Tags: Analytics Banking CISM CISSP COBIT Compliance Monitoring NIST Risk assessment Risk management

    Perks/benefits: Career development Competitive pay Flex hours Flex vacation Startup environment Team events

    Region: North America
    Country: Canada
    Job stats:  8  0  0

    More jobs like this

    Explore more InfoSec / Cybersecurity career opportunities

    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.