CIBC

Senior Security Service Manager

CIBC$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in security operations, particularly with Akamai ION, WAF, and web application security controls.
  • Degree/diploma in Computer Science, Engineering, Information Security, or Risk Management; certifications like CISSP or CISM are beneficial.
  • Strong understanding of security frameworks such as NIST and ISO/IEC, applicable to financial services.
  • Experience in collaborating across multifunctional teams and managing stakeholder relationships effectively.
  • Proven ability to drive initiatives and demonstrate ownership in projects.

Responsibilities

  • Collaborate with various security teams to embed features and address operational security needs.
  • Evaluate and integrate new security technologies, with a focus on Akamai and WAF solutions.
  • Ensure comprehensive risk assessments are conducted on all web-facing applications and services.
  • Monitor security trends, document potential threats, and operationalize security controls within development lifecycles.
  • Create and maintain documentation related to security processes, incident responses, and risk management.
  • Identify automation opportunities to enhance efficiency in security testing and assessment processes.

Benefits

  • Competitive salary and incentive pay.
  • Comprehensive benefits program including banking benefits, and a pension plan.
  • Employee share purchase plan to invest in the company’s future.
  • Generous vacation offering and wellbeing support.
  • Purpose Day - a paid day devoted to personal growth and development initiatives.
Full Job Description
What You'll Be Doing

The Security Service Management (SSM) function within Cyber Security at CIBC is responsible for ensuring that critical web applications and digital services are protected by robust security controls, in accordance with enterprise frameworks and standards. SSM develops, operationalizes, and continuously improves security services-such as Akamai ION, Web Application Firewall (WAF), and other cloud-based security solutions-to identify vulnerabilities, enforce remediation, reduce risks, ensure regulatory readiness, and enable secure innovation across the bank. This Senior Consultant, Security Service Management will support CIBC's SSM practices by evaluating new security technologies (e.g., Akamai ION, WAF, DDoS mitigation), developing effective operational plans in partnership with business teams and other risk control groups, and providing security services to the enterprise. The position will be responsible for ensuring that all web-facing applications and services are appropriately risk-assessed, as required by the Risk Assessment Process. The Senior Consultant will work collaboratively with application development, network security, security engineering, and oversight bodies to ensure that all security testing requirements are adhered to and are effective in managing web application and network-related risks.

At CIBC, we foster an environment that enables you to thrive in your role. You'll have the flexibility to manage your work activities within a hybrid work arrangement where you'll spend 1-3 days per week on-site, with the remaining days remote.

How You'll Succeed
  • Providing Solutions to Reduce Security Risk: Collaborate with risk management, application security, IAM, DLP, and network security teams to address web and network security needs, embed security features, and reduce operational pain points. Propose solutions to risk and control teams and contribute to enterprise security standards and educational resources.
  • Lead the Evaluation and Integration of Security Technologies: Conduct market comparisons and vendor assessments for Akamai and other security platforms, manage vendor selection and proof-of-concept processes, and oversee RFI documentation. Set up testing environments and evaluate solutions for future rollouts.
  • Ensure Applications Are Managed and Tested with High Assurance: Work with security vendors to develop and deploy controls that enable identification, assessment, and mitigation of web application and network risks. Ensure compliance with governance requirements and support CIBC's leadership in secure web and digital service delivery. Assist with ongoing risk reporting and reviews.
  • Translate Research into Actionable Insights: Monitor and report on trends in web application and network security, document potential threats, and ensure new security features address emerging risks. Develop and refine security processes and tools, and operationalize security controls within the application lifecycle and runtime environments.
  • Ignite Innovation: Evaluate the latest features in Akamai ION, WAF, and related services. Support the development and adoption of strategies and success metrics, and actively participate in all security service meetings.
  • Develop and Maintain Comprehensive Documentation: Create essential documentation such as RACI matrices, operational processes, playbooks, and procedures for WAF policy management, incident response, and runtime protection. Define workflows, scanning frequency, issue review protocols, and escalation paths for risk assessment. Collect and analyze health check metrics to measure service improvement, maintain backlogs based on service capabilities, and develop data flow diagrams from an architectural perspective. Manage the ServiceNow Catalogue for access and identify new roles for security configuration management. Oversee the end-to-end risk management process for WAF and Akamai ION requests. Ensure enterprise standards are updated with the latest security control requirements and facilitate discussions with stakeholders to finalize all processing documentation.
  • Enable Automation: Identify and document opportunities for automation to reduce human effort in testing and assessment processes, and track expected outcomes such as hours saved within operations.


Who You Are
  • You can demonstrate 5+ years of experience in Security operations and hands-on experience in Akamai ION, WAF, DDoS mitigation, and web application security controls. You understand the production lifecycle and have assessed controls and evidence in regulated environments. You are familiar with NIST, ISO/IEC security standards, and can embed new processes to reduce application and network risk in financial services, translating requirements into pragmatic, auditable security controls. You apply data protection, threat mitigation, security-by-design, and third-party risk practices to safeguard clients and the bank, and support positive outcomes for society.
  • You have a degree/diploma in relevant field (e.g., Computer Science, Engineering, Information Security, Risk Management). Certifications such as CISSP, CISM, or Akamai certifications are assets.
  • Your influence makes a difference. You know that relationships and networks are essential to success. You inspire outcomes by sharing your expertise.
  • You act like an owner. You thrive when you're empowered to take initiative, go above and beyond, and deliver results.
  • You embrace and advocate for change. You continuously evolve your thinking and the way you work in order to deliver your best.
  • You look beyond the moment. You know what you do will make a difference today and tomorrow. You look for new opportunities to define what's possible.
  • Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.


#LI-TA

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.


*Subject to plan and program terms and conditions

Job Location
Toronto-141 Bay, 17th Floor

Employment Type
Regular

Weekly Hours
37.5

Skills
Application Security, Business Operations, Cybersecurity, Information Security, Network Security, Security Service

About CIBC

The Canadian Imperial Bank of Commerce is a Canadian multinational banking and financial services corporation headquartered in Toronto, Ontario. The bank is headquartered at Commerce Court in the city's Financial District. CIBC's Institution Number is 010, and its SWIFT code is CIBCCATT. It is one of two Big Five banks founded in Toronto, the other being the Toronto-Dominion Bank. The Canadian Imperial Bank of Commerce was formed through the June 1, 1961, merger of the Canadian Bank of Commerce and the Imperial Bank of Canada, the largest merger between chartered banks in Canadian history. The bank has four strategic business units: Canadian Personal and Business Banking, Canadian Commercial Banking and Wealth Management, U.S. Commercial Banking and Wealth Management, and Capital Markets. It has international operations in the United States, the Caribbean, Asia, and United Kingdom; Globally. CIBC serves more than eleven million clients, and has over 40,000 employees. The company ranks at number 172 on the Forbes Global 2000 listing.
Learn more about CIBC
Market Cap
$43.5 billion
Industry
Founded
1867
5 Year Trend
+8.8%

Similar Jobs

More Jobs at CIBC

More Information Technology Jobs

Find similar Senior Security Service Manager jobs: