CIBC Logo

CIBC

Senior Manager, Cyber Risk, Regulatory Compliance

Reposted 17 Hours Ago
Be an Early Applicant
In-Office
Toronto, ON
Senior level
In-Office
Toronto, ON
Senior level
The Senior Manager, Cyber Risk will oversee compliance with cybersecurity regulations, manage risk reporting, and ensure effective remediation plans for identified risks, liaising with first line defenses and senior management.
The summary above was generated by AI

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What you'll be doing

The Senior Manager , Cyber Risk, Compliance & Reporting is an experienced professional responsible for fulfilling CIBC’s second line of defense mandate to support effective management of cyber security risk across the organization. The role works closely with the first Line of Defense (LoD) and applies technical expertise to assess cyber risks identified by the 1st LoD (e.g., through controls & Deficiency Management, regulatory risk assessments) and challenges risk mitigation/treatment plans. In addition, the role involves review and reporting of cybersecurity risks related to Enterprise Information security and control landscape, regulatory landscape, understanding the associated inherent and residual risk of various regulations such as (but not limited to) OSFI B-13, DORA, AMF, OSFI Technology and cyber security incident reporting , APRA, BILL C-26, CDCC, Bill C-27, HKMA and collaborating with relevant 1st LoD teams to advise on risk-based prioritization and drive remediation. The role also expects strong interpersonal, communication, and problem-solving skills to present conclusions to senior audiences, as well as keeping abreast with latest security threats and industry trends.

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. Details on your work arrangement (proportion of on-site and remote work) will be discussed at the time of your interview.

 

How you’ll succeed

  • Regulatory Compliance Monitor regulatory updates and implement changes to align with financial institution regulations (e.g., OSFI, SWIFT CSP).Ensure timely and accurate submission of regulatory filings (such as new and existing Regulatory Developments) related to cybersecurity and information risk.

  • Controls Review and Deficiency Management: Be able to challenge and review cybersecurity controls tied to regulatory developments and guidance to identify gaps, weaknesses, or areas for improvement. Collaborate with the 1st line to develop actionable remediation plans for deficiencies identified during audits or assessments in accordance with Regulatory Compliance Management. Ensure controls align with regulatory requirements, including OSFI B-13, DORA, GDPR, PIPEDA SWIFT CSP, NIST CSF 2.0, and ISO 27001.

  • Cybersecurity Regulatory Compliance Reporting: Develop and manage comprehensive reporting processes related to RCM activities, including dashboards and Risk Appetite Statements (RAS), KRIs metrics for executive leadership, audit committees, and regulatory bodies. Deliver meaningful insights into the organization's risk posture through KRIs, KPIs, and operational data. Prepare board-level reports detailing cyber risks, compliance statuses, and significant events affecting regulatory requirements.

  • Audit and Assessment Support: Support internal and external audits by ensuring accurate documentation of control environments, risk management practices, and compliance activities. Monitor remediation of audit findings, ensuring timely resolution and sustainable control implementation

  • RCM Policy Creation and Management: Develop, implement, and maintain information security related RCM policies, processes and procedures, ensuring alignment with enterprise RCM frameworks. Regularly review and update policies to reflect changes in the regulatory landscape, organizational priorities, and technological advancements. Collaborate with internal stakeholders to ensure the effective adoption of policies and promote a culture of compliance.

  • Cyber risk Review & Challenge: Act as a 2nd LOD and be able to effectively challenge and provide guidance on a wide array of cybersecurity controls and design requirements related to RCM activities, these may include areas such as Data security controls, Vulnerability & Threat Management, Identity & Access Management, Logging & Monitoring for various security attestations and cyber risk assessment and maturity scorecard programs.

  • Deep understanding of regulatory frameworks and requirements such as OSFI B-13, DORA SWIFT.

  • Critical thinking skills to evaluate the impact of identified security vulnerabilities and drive attack surface reduction.

  • Effective communications – Demonstrates clarity of thought in both written and verbal communications and develops and delivers strong and simplified reporting content and presentations.

  • Relationships – Builds and sustains strong internal relationships and is viewed as a valued partner that offers sound and pragmatic guidance, demonstrates a deep understanding of their environment and context and facilitates productive risk discussions and outcomes.

  • Collaboration – TI&I Operational Risk is a highly matrixed team building upon cross functional strengths of all team members. The role leverages strong communication, interpersonal skills and teamwork to build and sustain strong internal relationships within Risk Management, Information Security, technology, business units and other enterprise functional groups.

  • Communicate Effectively – You demonstrate clarity of thought in both written and verbal communications. You will facilitate productive risk discussions and outcomes and will develop and deliver strong reporting content, presentations and assessment summaries on an ongoing basis for senior audiences and risk committees.

  • Proactive oversight and assessment – You will review operational practices, risk assessments, controls, deficiencies and other relevant information to form an independent view of operational risks. You will identify material and emerging risks through proactive risk reviews and monitoring of Key Risk Indicators and External Events. You will effectively communicate areas or concern to ensure appropriate risk mitigation actions are taken.

  • Facilitate Innovation – Support change and the maintenance of effective Operational Risk programs that allows CIBC to fulfill its purpose-driven mission. This will include new ideas that supports CIBC’s goal of an effective, efficient and radically simple Operational Risk and Control program

Who you are

  • Years of Experience The candidate is expected to have at least 8-10 years of experience working within the Cybersecurity and Information risk space with a wide array of experience working on/with different regulatory bodies and their cybersecurity requirements to manage risks related to Information security.

  • It is an asset to have direct Compliance/ Regulatory Compliance Management experience within the Canadian Banking industry

  • Strong knowledge of Cybersecurity regulatory frameworks and risk management, with in-depth understanding of cybersecurity best practices, testing and mitigation strategies.

  • Cooperative and innovative entrepreneurial team player with mature judgment, strong interpersonal skills and original approaches to problem resolution

  • Deals with ambiguity and is exceptionally adaptable and flexible

  • Thinking out of the box to make processes more efficient, focusing on bringing in automations and simplifications

  • You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.

  • Managing multiple activities with varying complexity in a sophisticated matrix environment organization while under time constraints

  • Maintaining productive and collaborative relationships with internal and external sources, colleagues and others to obtain, provide, verify and discuss information and best practices

  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability

#LI-TA

 

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact [email protected]

  • CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).

  • We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 29th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Analytical Thinking, Collaboration, Communication, Critical Thinking, Cybersecurity Controls, Cyber Security Governance, Cybersecurity Policy, Cybersecurity Risk Assessment, Cybersecurity Risk Management, Cyber Security Standards, Emerging Risks, Enterprise Information Security, Group Problem Solving, Information Security, NIST Cybersecurity Framework (CSF), Regulatory Compliance Management, Regulatory Compliance Reporting, Regulatory Frameworks, Regulatory Requirements, Regulatory Risk, Risk Reporting, Technical Knowledge

Top Skills

Gdpr
Iso 27001
Nist Csf
Pipeda
Swift Csp
HQ

CIBC Toronto, Ontario, CAN Office

Square, 81 & 141 Bay, Toronto, Ontario, Canada

Similar Jobs

An Hour Ago
Hybrid
Toronto, ON, CAN
Junior
Junior
Cloud • Insurance • Professional Services • Analytics • Cybersecurity
The Associate Underwriter provides underwriting support for Canada policies, manages new and renewal business, ensures compliance, and engages with internal teams for queries.
Top Skills: Microsoft Office Suite
An Hour Ago
In-Office or Remote
Toronto, ON, CAN
Mid level
Mid level
Artificial Intelligence • Cloud • Fintech • Professional Services • Software • Analytics • Financial Services
The Account Executive will seek new business opportunities, collaborate with sales teams, address customer objections, and develop sales strategies to drive customer acquisition.
Top Skills: Software As A Service (Saas)
An Hour Ago
Easy Apply
Hybrid
Mississauga, ON, CAN
Easy Apply
Senior level
Senior level
Artificial Intelligence • Information Technology • Mobile • Payments • Software • App development • Utilities
The Senior Security Architect will design and oversee security solutions, perform architecture reviews, partner with teams for vulnerability resolution, and develop security strategies to mitigate risks.
Top Skills: AWSCloud SecurityContainerized ArchitecturesIamNetwork SecurityTerraformThreat ModelingWiz

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account