Toronto, ON, Canada
23 hours ago
Senior Manager, Cyber Risk, Compliance & Reporting

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What you'll be doing

The Senior Manager , Cyber Risk, Compliance & Reporting is an experienced professional responsible for fulfilling CIBC’s second line of defense mandate to support effective management of cyber security risk & delivery of comprehensive cybersecurity risk reporting across the organization. 

The role works closely with the First Line of Defense (1LoD) to gather, analyze, and report on cyber risks identified through controls, deficiency management, regulatory risk assessments and challenge risk mitigation/treatment plans. The role requires a deep understanding of risk reporting practices, regulatory requirements, and risk management practices, with a primary focus on creating actionable insights through data-driven reporting. The successful candidate will collaborate with cross-functional teams to collect, analyze, and present key metrics, ensuring alignment with CIBC’s risk appetite as well as regulatory expectations. In addition, the role involves review and reporting of cybersecurity risks related to regulatory landscape, understanding the associated inherent and residual risk of various regulations such as (but not limited to) OSFI B-13, DORA, GDPR and collaborating with relevant 1st LoD teams to advise on risk-based prioritization and drive remediation.

The role also expects strong interpersonal, communication, and problem-solving skills to present conclusions to senior audiences, as well as keeping abreast with latest security threats and industry trends.

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. Details on your work arrangement (proportion of on-site and remote work) will be discussed at the time of your interview.

How you’ll succeed

Cybersecurity Reporting

Develop and manage comprehensive reporting processes, including dashboards, Risk Appetite Statements (RAS), Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs).

Draft well-structured and insightful cyber risk statements, emerging risk outlooks and risk appetite commentary.

Deliver meaningful insights into the organization’s cybersecurity risk posture through data analysis and visualization.

Prepare board-level and executive reports detailing cyber risks, compliance statuses, and significant events affecting regulatory requirements.

Create and maintain reporting templates and processes to ensure consistency, accuracy, and efficiency in delivering insights to stakeholders.

Collaborate with internal teams to gather data on cybersecurity controls, incidents, and remediation efforts, ensuring timely and accurate reporting.

Monitor and report on trends in cyber threats, vulnerabilities, and regulatory developments, providing actionable recommendations to senior leadership.

Ensure reporting aligns with industry standards and regulatory requirements, including OSFI B-13, DORA, GDPR, PIPEDA, SWIFT CSP, and NIST CSF.

Information Security Risk Policy and Control Reporting

Develop and maintain reporting on the effectiveness of cybersecurity risk policy and control mapping, ensuring alignment with global standards such as NIST CSF 2.0, ISO 27001.

Regularly review and update reporting processes to reflect changes in the regulatory landscape, organizational priorities, and technological advancements.

Cyber risk Review & Challenge: Act as a 2nd LOD and be able to effectively challenge and provide guidance on a wide array of cybersecurity controls and design requirements such as Data security controls, Vulnerability & Threat Management, Identity & Access Management, Logging & Monitoring for various security attestations and cyber risk assessment and maturity scorecard programs.

Regulatory Compliance Monitor regulatory updates and implement changes to align with financial institution regulations (e.g., OSFI, SWIFT CSP).Ensure timely and accurate submission of regulatory filings (such as new and existing Regulatory Developments) related to cybersecurity and information risk.

Audit and Assessment Support: Support internal and external audits by ensuring accurate documentation of control environments, risk management practices, and compliance activities. Monitor remediation of audit findings, ensuring timely resolution and sustainable control implementation

Policy Creation and Management: Develop, implement, and maintain information security and risk policies (ISRP, AUP), ensuring alignment with global standards such as NIST, ISO 27001, and COBIT and various Industry recognized frameworks. Regularly review and update policies to reflect changes in the regulatory landscape, organizational priorities, and technological advancements. Collaborate with internal stakeholders to ensure the effective adoption of policies and promote a culture of compliance.

Data-Driven Reporting: Demonstrate expertise in collecting, analyzing, and presenting cybersecurity data to provide actionable insights for decision-making.

Regulatory Awareness: Stay informed of regulatory requirements and ensure reporting processes align with expectations from bodies such as OSFI, DORA, GDPR, and SWIFT CSP.

Innovation: Continuously improve reporting processes by leveraging automation, data visualization tools, and best practices.

Critical thinking skills to evaluate the impact of identified security vulnerabilities and drive attack surface reduction.

Effective communications – Demonstrates clarity of thought in both written and verbal communications and develops and delivers strong and simplified reporting content and presentations.

Relationships – Builds and sustains strong internal relationships and is viewed as a valued partner that offers sound and pragmatic guidance, demonstrates a deep understanding of their environment and context and facilitates productive risk discussions and outcomes.

Collaboration – TI&I Operational Risk is a highly matrixed team building upon cross functional strengths of all team members. The role leverages strong communication, interpersonal skills and teamwork to build and sustain strong internal relationships within Risk Management, Information Security, technology, business units and other enterprise functional groups.

Who you are

Years of Experience At least 10-12 years of experience in cybersecurity and information risk, with expertise in cyber risk reporting and regulatory compliance.

It is an asset to have direct Cyber risk Insights and reporting experience within the financial industry.

Strong knowledge of Cybersecurity risk reporting practices as well as cyber regulatory risk reporting.

Cooperative and innovative entrepreneurial team player with mature judgment, strong interpersonal skills and original approaches to problem resolution

Deals with ambiguity and is exceptionally adaptable and flexible

Thinking out of the box to make processes more efficient, focusing on bringing in automations and simplifications

You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.

Managing multiple activities with varying complexity in a sophisticated matrix environment organization while under time constraints

Maintaining productive and collaborative relationships with internal and external sources, colleagues and others to obtain, provide, verify and discuss information and best practices

Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com

You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 29th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Analytical Thinking, Cyber Risk Data, Cybersecurity Controls, Cyber Security Governance, Cybersecurity Policy, Cybersecurity Risk Management, Cyber Security Standards, Group Problem Solving, Information Security, Metrics Reporting, NIST Cybersecurity Framework (CSF), Regulatory Risk, Risk Monitoring, Risk Reporting, Technical Knowledge
Por favor confirme su dirección de correo electrónico: Send Email