Sr. Consultant, Operational Cyber Risk

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.<br><br>At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.<br><br>To learn more about CIBC, please visit CIBC.com<br><br><strong>What You’ll Be Doing<br><br></strong>As the Senior Consultant in the second line of defense risk management function, you will provide expert oversight and support for the identification, measurement, mitigation, monitoring, and reporting of cyber and technology risk across Capital Markets business units and other CIBC Functional Groups. You will collaborate closely with information security, technology, and risk partners to ensure a consistent, integrated approach to risk management.<br><br><em>At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.<br><br></em><strong>How You’ll Succeed<br><br></strong><ul><li>Risk Management & Portfolio Oversight Review operational practices, risk assessments, controls, deficiencies, metrics, and other relevant information to form an independent view of cyber risks and perform effective challenges. Apply a risk-based approach to assess and manage risks related to information/cyber security, ensuring alignment with operational risk management policies, the CIBC risk appetite, and specific risk tolerances. Conduct independent assessments of busi ness lines and initiatives, such as projects, risk and control self-assessments, and incidents, using established operational risk tools and processes. Leverage strong data and analytical skills to conduct detailed research, generate actionable risk insights, and document findings for distribution to various internal audiences. Prepare high-quality, impactful risk reporting and portfolio-level insights for senior leadership and governance committees.</li><li>Technical & Analytical Expertise Bring credibility and influence by leveraging your broad technology experience and deep expertise in areas such as cloud, network, cybersecurity, DevOps, APIs, big data, and IT service management to assess and challenge risks and controls across business lines. Support risk activities across the team, including risk reviews and project assessments, operating within a matrix team environment, and driving continuous improvement in risk management methodologies.</li><li>Advisory & Continuous Improvement Maintain a forward-looking, industry-informed view of the technology and cyber risk landscape, staying current with best practices, performance benchmarks, and emerging trends. Provide expert guidance on the management and mitigation of cyber risks and contribute to the continuous enhancement of operational risk management methodologies and practices.</li><li>Collaboration & Relationship Building Leverage effective communication and people skills to build and sustain trusted internal relationships, positioning yourself as a valued partner who provides sound risk guidance and demonstrates a deep understanding of both the business and technology environments. Collaborate closely with information security, technology, risk, and business partners to ensure a consistent and integrated approach to risk management.</li><li>Educational Support & Risk Culture Promote a culture of risk awareness and the importance of robust operational and cyber risk management practices. Ensure operational risk policies, processes, and continuous improvement initiatives are effectively communicated, and support the delivery of education and training to enhance risk awareness and capability across the organization.<br><br></li></ul><strong>Who You Are<br><br></strong><ul><li>You bring broad expertise in cyber and technology risk. You have demonstrated experience across IT service management, cybersecurity, and associated industry frameworks and regulations. You are adept at managing risk across multiple domains, including technology infrastructure, application delivery, data management, architecture, and cybersecurity.</li><li>You are a collaborative partner and effective communicator. You excel at building strong working relationships and collaborating with diverse stakeholders in a dynamic, fast-paced environment. You work seamlessly with technology, information security, and risk partners to drive integrated and consistent risk management.</li><li>You possess technical acumen and a continuous improvement mindset. You have technical experience in areas such as cloud, Agile/DevOps, APIs/microservices, automation, and big data technology. Industry-recognized certifications (e.g., CISA, ITIL, CISSP, Microsoft Certified: Cybersecurity Architect Expert) are considered valued assets. You actively contribute to the enhancement of risk management methodologies and are always seeking opportunities to innovate and improve.</li><li>You are data-driven and insightful. You enjoy investigating complex problems, leveraging strong analytical skills to extract insights from data, and translating findings into actionable recommendations for risk mitigation and reporting.</li><li>You are detail-oriented and a critical thinker. You have a keen eye for detail and apply strong critical thinking skills to inform your decision-making. You notice what others might overlook and ensure that risk assessments and reporting are thorough and accurate.</li><li>You embrace change and champion growth. You continuously evolve your thinking and approach, adapting to new challenges and emerging trends in the cyber and technology risk landscape to deliver your best work.</li><li>You live our values. You bring your authentic self to work and embody CIBC’s core values of trust, teamwork, and accountability in everything you do.<br><br></li></ul><strong>What CIBC Offers<br><br></strong>At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.<br><br><ul><li>We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.</li><li>Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.</li><li>We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.</li><li>Subject to plan and program terms and conditions<br><br></li></ul><strong>What You Need To Know<br><br></strong><ul><li>CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com</li><li>You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.</li><li>We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, French proficiency, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.<br><br></li></ul><strong>Job Location<br><br></strong>Toronto-81 Bay, 29th Floor<br><br><strong>Employment Type<br><br></strong>Regular<br><br><strong>Weekly Hours<br><br></strong>37.5<br><br><strong>Skills<br><br></strong>Analytical Thinking, Control Frameworks, Decision Making, Group Problem Solving, Operation Risk Management, Risk Analytics, Risk Assessments, Risk Governance<br><br>

Back to blog