What You'll Be Doing
You’ll be joining CIBC’s Cyber Operations (CO) team as a Web Application Security Consultant. As a Web Application Security Consultant, you’ll be responsible for managing the web application security configurations for CIBC applications. This includes onboarding new applications onto the Web Application Firewall (WAF), bot controls, DDoS controls, and other security products. You’ll also work closely with other groups such as Security Service Management, SOC, and application teams across CIBC to ensure that our applications are safeguarded against web-based threats.
At CIBC we enable the work environment most optimal for you to thrive in your role you’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.
How You'll Succeed
- Web security application - Work closely with application teams across CIBC to onboard applications onto WAF, bot controls, and other web application security products. Monitor and analyze traffic for onboarded applications, fine tuning security settings as needed to reduce false positives and ensure minimal impact on legitimate users. Assist in troubleshooting and resolving security related issues for applications and sharing timely adjustments to security configurations where required to address evolving threats or operational concerns. Participate in POC evaluations for new web application security products, assessing their effectiveness and potential to enhance the organization's web application security posture.
- Driving continuous improvement - Proactively identify opportunities to improve security configurations, processes, and workflows
- Problem solving – There will always be impediments and blockers to success, but we need to shine a light on them in order to properly identify and plan to overcome them. Better still, present options for overcoming the roadblock when calling it out, and the path(s) forward once it is resolved.
- Work Collaboratively and cross-functionally – Effective communication, collaboration, information sharing and teamwork are essential to success in this space. No one has all the answers, but more often than not, the answers can be found close at hand, either simply by asking the right questions, or putting the right heads together to solve for the problem at hand.
Who You Are
- You can demonstrate 5 years of experience in an Information Security Consultant or a similar role. You can demonstrate technical expertise in web application security. You have a strong understanding of web-based attacks, web application firewalls, bot management, DDoS mitigation and other application layer security solutions.
- You understand that success is in the details. You notice things that others don't. Your critical thinking skills help to inform your decision making.
- You act like an owner. You thrive when you're empowered to take initiative, go above and beyond, and deliver results.
- You're digitally savvy. You seek out innovative solutions and embrace evolving technologies. You can easily adapt to new tools and trends.
- You have a degree/diploma in Computer Science, Engineering, or a related field.
- You’re a certified professional. It’s an asset if you have your CISSP, CRISC, or CISM designation.
- Values matter to you. You bring your real self to work and you live our values - trust, teamwork, and accountability.
**Prior to starting in this role, security checks, including a criminal record check must be successfully completed to the satisfaction of CIBC. An annual criminal record check may also be required.
#LI-TA
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
Job Location
Toronto-141 Bay, 15th Floor
Employment Type
Regular
Weekly Hours
37.5
Skills
Application Firewall, Application Security, AWS Web Application Firewall (WAF), Communication, Creativity, Group Problem Solving, Information Security, Information System Security, Network Security, Open Web Application Security Project (OWASP), OWASP Mobile Security Testing Guide (MSTG), OWASP Top 10, OWASP Zed Attack Proxy (ZAP), Personal Initiative, System Security, Teamwork, Web Application Firewall (WAF), Web Applications, Web Application Security, Web Application Security Assessment, Web Application Security Testing, Web Security, Web Security Testing