Back to jobs
CIBC US

Sr. Consultant, Information Security - Open Banking

Toronto, ONPosted Yesterday
FULL_TIMEhybrid

Job Description

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What you'll be doing

You’ll be joining CIBC’s Cyber and Third Party Risk Team. You’ll be on the front lines of building the future of information security at CIBC. As a Sr. Consultant, Information Security, you’ll assess projects for security risks and present recommendations that allow the business to make informed conclusions. You’ll provide insight and support to assemble policies and procedures that safeguard our clients, enhance risk management, and enable our success. 

At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote. 

How you'll succeed

  • Build and Maintain Relationships - You will partner with business lines, technology teams, and ecosystem participants to provide guidance and support on cybersecurity risks and current trends within Open Banking and financial data ecosystems. Leveraging your relationship-building skills, you will proactively identify risks associated with data sharing, API integrations, authentication, and consent flows, presenting practical and achievable recommendations. Your passion for information security and risk advisory services will help you establish trust and credibility as a strategic advisor across the organization.

  • Consulting - You will review and interpret requirements documentation, architecture diagrams, and solution designs to determine the feasibility and security risk of projects within the Open Banking ecosystem. By conducting comprehensive threat modeling using methodologies such as STRIDE, MITRE ATT&CK, and attack trees, you will provide actionable security recommendations and advisory support to stakeholders, ensuring alignment with CIBC’s security objectives.

  • Delivery and ExecutionYou will lead cybersecurity risk assessments across banks, fintechs, third-party providers, and shared infrastructure. This includes executing detailed threat risk assessments, coordinating penetration testing, and reporting on findings. You will assess API security, consumer consent mechanisms, identity and authentication flows, and central registry infrastructure. You will also support the accreditation and security evaluation of third-party ecosystem participants and vendors, recommending new controls to mitigate emerging risks.

  • Communication - You will create and present risk reports and recommendations to executive management, translating technical risks into meaningful business context. You will develop and deliver learning and training materials to peers and junior advisory team members, and provide feedback on the design and implementation of security assessment processes. Your effective communication will support stakeholder engagement, secure solution design, and the promotion of a strong security culture.

  • Continuous Improvement - You will proactively identify opportunities to enhance existing security processes, tools, and frameworks. By staying current with industry best practices and regulatory requirements, you will recommend and implement improvements that strengthen CIBC’s cybersecurity posture.

  • Collaboration & Knowledge Sharing - You will foster a culture of collaboration by sharing your expertise and insights across teams. You will mentor peers and junior advisory members, contribute to cross-functional initiatives, and help build organizational awareness of cybersecurity risks and solutions.

Who you are

  • You can demonstrate 8-12 years of experience in Information Security Risk Management, Threat-risk assessments, Vulnerability & Penetration testing, and Threat modelling. You have familiarity with emerging technologies, cloud computing platforms (such as Azure and AWS), exposure to agile development processes, and hold or are pursuing a security certification such as CISSP, CISM, or CISA.

  • You have a Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Security, Engineering, or Information Systems

  • You're passionate about people. You find meaning in building strong relationships and collaborating with a diverse network of partners. You build trust through respect and authenticity, and are recognized as a trusted advisor to both business and technology leaders.

  • You embrace and advocate for change. You continuously evolve your thinking and approach, adapting to new challenges and driving secure innovation across the organization.

  • You're digitally savvy. You seek out innovative solutions, embrace evolving technologies, and can easily adapt to new tools and industry trends. Your technical proficiency spans secure-by-design principles, cloud security architectures, API security, and threat modeling methodologies.

  • Your influence makes a difference. You know that relationships and networks are essential to success. You inspire outcomes by sharing your expertise, translating technical risks into meaningful business context, and influencing stakeholders without direct authority.

  • You give meaning to data. You enjoy investigating complex problems, making sense of information, and communicating detailed findings in a clear and compelling way to drive actionable security recommendations.

  • Values matter to you. You bring your real self to work and you live our values – trust, teamwork and accountability.

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact [email protected]

  • CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).

  • We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

Toronto-81 Bay, 19th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Application Programming Interface (API), Application Programming Interface (API) Security, Building Trust, Business Risks, Cloud Security, Collaboration, Communication, Consulting, Cyber Risks, Cybersecurity, Information Security, Information Security Risk, Information Security Risk Management, Infrastructure Security, Leadership, Relationship Building, Risk Consulting, Risk Management, Security Architecture Design, Security Evaluations, Security Risk, Security Risk Management, Team Development, Teamwork
Sr. Consultant, Information Security - Open Banking at CIBC US | Renata