CIBC Logo

CIBC

Sr Consultant, Information Security(Pen Test)

Posted 7 Hours Ago
Be an Early Applicant
In-Office
Toronto, ON
Senior level
In-Office
Toronto, ON
Senior level
The Senior Information Security Consultant assesses penetration testing risks, communicates findings to stakeholders, and provides remediation guidance aligned with policies and standards.
The summary above was generated by AI

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What You’ll be Doing

As a Senior Information Security Consultant within CIBC’s Application Security & Risk team, you will assess, contextualize, and communicate the business risk of penetration testing findings. You will translate technical vulnerabilities into clear, prioritized risk treatments and remediation guidance, helping Lines of Business make informed decisions that align with CIBC’s risk appetite and policies

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote

How You’ll Succeed

  • Risk assessment and prioritization: Execute high-quality risk assessments of penetration testing findings; validate severity and exploitability in business context. Apply consistent risk ratings to prioritize remediation. Increase visibility into enterprise risk by identifying systemic control gaps and trends across applications, infrastructure, and cloud.
  • Actionable guidance and risk treatment: Translate findings into clear, prioritized remediation guidance tailored to the technology stack. Define risk treatment options with rationale aligned to policy and risk appetite.
  • Reporting and executive communication: Produce executive-ready risk reports and summaries that articulate risk and recommended actions. Present assessments and remediation progress to senior management and control partners (e.g., IT Risk, Audit, Architecture). Maintain consistent templates and writing standards to ensure clarity, comparability, and timely decisions.
  • Governance and consistency: Align assessments with internal policies and external standards (e.g., NIST, ISO 27001, OWASP, PCI DSS). Promote consistent rating practices and quality across portfolios.

Who You Are

  • You can demonstrate 5+ years of progressive experience in application security, penetration testing, or related fields. You have experience performing manual penetration testing of applications, infrastructure, and mobile apps; able to identify common web application vulnerabilities and recommend practical remediation. You have proven ability to conduct risk assessments for application-related security findings, translating technical issues into business risk and prioritized actions. You have solid understanding of penetration testing processes, procedures, and scoping requirements. It’s an asset if you have familiarity with the Financial Services industry and its regulatory/control considerations.
  • Your influence makes a difference. You know that relationships and networks are essential to success. You inspire outcomes by sharing your expertise. You have strong interpersonal and communication skills and ability to articulate application security issues to various stakeholders including developers, project managers and management.
  • You embrace and advocate for change. You continuously evolve your thinking and the way you work in order to deliver your best.
  • You know that details matter. You notice things that others don't. Your critical thinking skills help to inform your decision making.
  • You're passionate about people. You find meaning in relationships and surround yourself with a diverse network of partners. You connect with others through respect and authenticity.
  • You’re a certified professional. You have current accreditation and good standing in security certifications (e.g., CISSP, CRISC, etc.)
  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.

#LI-TA

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact [email protected]

  • CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).

  • We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 19th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Application Security, Penetration Testing, Risk Management, Secure Coding Practices, Web Application Vulnerabilities

Top Skills

Iso 27001
Nist
Owasp
Pci Dss
HQ

CIBC Toronto, Ontario, CAN Office

Square, 81 & 141 Bay, Toronto, Ontario, Canada

Similar Jobs

An Hour Ago
Hybrid
Toronto, ON, CAN
Mid level
Mid level
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Design and operate scalable backend services, collaborate on product requirements, ensure system quality, and advocate for best practices.
Top Skills: Java,Golang,Nosql,Memcache,Redis,Kubernetes,Google Cloud,Aws
3 Hours Ago
Remote or Hybrid
ON, CAN
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design and implement scalable Kubernetes platforms, optimize infrastructure reliability, mentor engineers, and evaluate open-source technologies.
Top Skills: Amazon Web ServicesArgoBashCiliumClusterapiFluxcdHelmKubernetesPythonRook
3 Hours Ago
Remote or Hybrid
ON, CAN
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Technical Writer II, you'll create product documentation, collaborating with teams to ensure clarity and comprehensibility for customers. You'll manage projects independently, develop product knowledge, and tailor content for users.
Top Skills: DitaGitOxygen Xml EditorXML

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account