Director, Information Security in Chicago, IL

$200K - $250K(Ladders Estimates)

Bank of Montreal   •  

Chicago, IL 60601

Industry: Finance & Insurance


8 - 10 years

Posted 38 days ago

This job is no longer available.


Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Acts as a trusted advisor to senior leaders for making business decisions and implementing strategic initiatives.
  • Develops an expert understanding of business/group challenges.
  • Networks with industry contacts to gather competitive insights and best practices.
  • Drives innovation through observation of common information security problems to identify emerging information security challenges, identifies alternative or emerging solutions, identifies opportunities for rationalization among existing solutions.
  • Influences senior leaders to change the way they do things in order to operate in a more secure manner and conform to industry standards and best practices.
  • Recommends measures to improve organizational effectiveness.
  • Acts as a subject matter expert on relevant regulations and policies.
  • Understands and can explain to others the core processes, risks & mitigation techniques for designated areas.
  • Influences and negotiates to achieve business objectives.
  • Recommends and implements solutions based on analysis of issues and implications for the business.
  • Identifies emerging issues and trends to inform decision-making.
  • Develops solutions and makes recommendations based on an understanding of the business strategy and stakeholder needs.
  • Anticipates and reduces complexity for others.
  • Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.
  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
  • Helps determine business priorities and best sequence for execution of business/group strategy.
  • Conducts independent analysis and assessment to resolve strategic issues.
  • Acts as the prime contact for internal/external stakeholder relationships, which may include regulators.
  • Acts as the prime subject matter expert for internal/external stakeholders.
  • Ensures alignment between stakeholders.
  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
  • Presents and communicates at all levels within IT and across business units.
  • May work with vendors to troubleshoot issues to meet service expectations.
  • Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations.
  • Analyzes trends and stays current with industry events to proactively prevent information security issues.
  • Identifies opportunities to strengthen the capability of the information security organization at BMO, such as: sharing expertise to promote technical development, mentoring employees, building communities of practice and networks across information security and technology.
  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
  • Provides advice, counsel and support on information security matters - recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
  • Creates professional presentations and deliver them in a meaningful concise way.
  • Assesses information security impact to a project's benefits and risks when scope changes.
  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
  • Manages people and leads a team capable of delivering the desired business results.
  • Operates at a group/enterprise-wide level and serves as a senior specialist resource across BMO.
  • Influences how teams/groups work together.
  • Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to multiple, interdependent, complex problems.
  • Communicates abstract concepts in simple terms.
  • Fosters strong internal and external networks and works with and across multiple teams to achieve business objectives.
  • Anticipates trends and responds by implementing appropriate changes.
  • Broader work or accountabilities may be assigned as needed.


  • Typically 9+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Must have at multiple certifications in a related field, with strong preference for information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
  • Excellent understanding of industry standards and frameworks eg. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc.
  • Excellent knowledge of business analysis, project delivery practices and standards across the project lifecycle.
  • Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls.
  • Possesses a deep understanding and problem solving ability of information security issues within their business group.
  • Has an expert understanding of information security risk and regulatory requirements.
  • Possesses excellent partnering, communication, and negotiation skills.
  • Superior understanding of the information security industry standards and frameworks.
  • Demonstrates expertise in all areas of information security and has in depth leadership abilities.
  • Knowledge of the technical/business environment and the corporate processes and procedures.
  • Seasoned expert with extensive industry knowledge.
  • Technical leader viewed as a thought leader for innovation.
  • Verbal & written communication skills - Expert.
  • Analytical and problem solving skills - Expert.
  • Influence skills - Expert.
  • Collaboration & team skills; with a focus on cross-group collaboration - Expert.
  • Able to manage ambiguity.
  • Data driven decision making - Expert.

Valid Through: 2019-10-9