What You'll Be DoingYou’ll be joining CIBC’s Cyber Operations (CO) team as a Web Application Security Consultant. As a Web Application Security Consultant, you’ll be responsible for managing the web application security configurations for CIBC applications. This includes onboarding new applications onto the Web Application Firewall (WAF), bot controls, DDoS controls, and other security products. You’ll also work closely with other groups such as Security Service Management, SOC, and application teams across CIBC to ensure that our applications are safeguarded against web-based threats, Work closely with application teams across CIBC to onboard applications onto WAF, bot controls, and other web application security products. You will monitor and analyze traffic for onboarded applications, fine tuning security settings as needed to reduce false positives and ensure minimal impact on legitimate users. You assist in troubleshooting and resolving security related issues for applications and sharing timely adjustments to security configurations where required to address evolving threats or operational concerns. You will participate in POC evaluations for new web application security products, assessing their effectiveness and potential to enhance the organization's web application security posture
At CIBC we enable the work environment most optimal for you to thrive in your role you’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 2 days per week on-site, while other days will be remote.
How You'll Succeed
- Driving continuous improvement - Proactively identify opportunities to improve security configurations, processes, and workflows
- Call Out Problems and Roadblocks 6 There will always be impediments and blockers to success, but we need to shine a light on them in order to properly identify and plan to overcome them. Better still, present options for overcoming the roadblock when calling it out, and the path(s) forward once it is resolved.
- Work Collaboratively, Both Within Your Team, and Without 6 Effective communication, collaboration, information sharing and teamwork are essential to success in this space. No one has all the answers, but more often than not, the answers can be found close at hand, either simply by asking the right questions, or putting the right heads together to solve for the problem at hand.
Who You Are
- You can demonstrate technical expertise in web application security. You have a strong understanding of web-based attacks, web application firewalls, bot management, DDoS mitigation and other application layer security solutions. You have at least five years of experience as an Information Security Consultant or a similar role.
- You understand that success is in the details. You notice things that others don't. Your critical thinking skills help to inform your decision making.
- You love to problem solve. You enjoy investigating complex issues and making sense of information. You're confident in your ability to communicate detailed information in an impactful way.
- You’re digitally savvy. You seek out innovative solutions and embrace evolving technologies. You can easily adapt to new tools and trends.
- You have a degree/diploma in Computer Science, Engineering, or a related field.
- You’re a certified professional. It’s an asset if you have your CISSP, CRISC, or CISM designation.
- Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).
We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
Toronto-141 Bay, 15th Floor
Employment Type
Regular
Weekly Hours
37.5
Skills
Analytical Thinking, Application Firewall, Communication, Decision Making, Information Security, Investigating, IT Governance, Mentorship, Risk Assessments, Security Technologies, Security Testing, System Security, Troubleshooting, Web Application Firewall (WAF), Web Application Security, Web Application Vulnerabilities