
Sr. Analyst, Information Security
Job Description
We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you'll be doing
The role is responsible for managing the process of developing and supporting the activities and tools used for validating and ensuring technology based information security using selected third party vendors. The role troubleshoots problems and provides technical training to less experienced employees, acting as the central point of contact between Information Security and Internal Audit. The role uses judgement and autonomy on day to day tasks, managing and leading Information Security internal audit related findings and activities, and resolving identified vulnerabilities. The role facilitates the provision of security risk information from third parties and the communication of information to management. In addition, the role proactively addresses problems within the scope of responsibility and identifies areas for possible improvements.
At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.
How you'll succeed
- Operations – Collaborate with senior consultants to implement and support PAM processes for privileged identities. Participate in the discovery and assessment of privileged accounts, address user issues, and contribute to technical discussions. Provide support for cloud technologies and participate in on-call rotations.
- Security Assessments – Assist in implementing security patches, helping to maintain compliance with security standards. Apply basic knowledge of processes and tools to support data protection.
- Consulting – Support project teams and partners in designing and implementing PAM solutions for new and existing infrastructure. Ensure compliance with IAM standards and policies, and assist in investigating and remediating security incidents.
- Risk Reviews – Analyze requirement documents and architecture diagrams, and provide recommendations to improve information system security, guided by senior team members. Help evaluate business needs and security concerns.
- Continuous Improvement – Recommend process improvements to streamline workflows and reduce risk. Assist in documenting procedures, conducting gap analyses, and maintaining controls and training documentation related to PAM.
Who you are
- You can demonstrate experience in PAM with practical experience as an Idira Consultant (formerly CyberArk) in a self-hosted environment. You have supported CyberArk components, performed troubleshooting, and assisted with upgrades and server maintenance. You participate in root cause analysis and document findings, working closely with stakeholders. Familiarity with SCM, enterprise change management, cloud technologies, Agile methods, and code promotion is valued. Documentation skills in SharePoint and Jira/Confluence are helpful, and CISSP certification is an asset. You are aware of cybersecurity trends and risks impacting IAM and PAM.
- You have a good understanding of Idira/CyberArk, IAM, and PAM, and can support and integrate technologies across multiple environments, including Windows, Unix, Linux, Mainframe, Active Directory, and Azure Active Directory. You have a background in engineering or development, with experience in REST APIs, integration, and workflow automation. Skills in Python and PowerShell are good to have. You contribute to security solutions and support complex application environments.
- You are familiar with a variety of technology solutions, focused on CyberArk, IAM, PAM, and related platforms. Application support and integration experience is important. You can work with REST APIs and automate workflows using Python and PowerShell.
- You are passionate about people. You foster relationships, build trust, and collaborate with diverse teams.
- You are digitally savvy. You seek out innovative solutions and adapt to new technologies.
- Your influence makes an impact. You understand the importance of networking and inspire positive outcomes.
- You give meaning to data. You analyze problems and communicate findings effectively.
- Values matter to you. You bring authenticity to your work and uphold trust, teamwork, and accountability.
#LI-TA
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact [email protected]
CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).
We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
Toronto-141 Bay, 17th FloorEmployment Type
RegularWeekly Hours
37.5Skills
Analytical Thinking, Decision Making, Information Security, Internal Auditing, Security Risk, Technical Training, Troubleshooting, Vendor Management