Director, Information Security - Minnesota City

Only for registered members Minnesota City, United States

1 day ago

Default job background
Full time $190,000 - $230,000 (USD)
We're building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what's right for our clients. · At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what ...
Job description

We're building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what's right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit

What you'll be doing: As the US Region Information Security Director of Regulatory and Controls, you will be responsible for the department's efforts in ensuring compliance with relevant regulations and effectiveness of information security controls.

You will monitor relevant laws, regulations, and standards to ensure CIBC US security practices align with regulatory requirements and you will own regulatory compliance programs such as NY-DFS, GLBA and FFIEC.

You will serve as primary point of contract for regulatory bodies during audits and be responsible for creation of materials for and participation in exams and quarterly briefings.

You will be responsible for Information Security control management and providing oversight of controls that impact the US team.

This includes conducting the Risk and Control SelfAssessment (RCSA) for Information Security and provide input into RCSA's for all other lines of business.

Work Arrangement: At CIBC we enable the work environment most optimal for you to thrive in your role. You'll have the flexibility to manage your work activities within a hybrid work arrangement where you'll spend 1-3 days per week on-site, while other days will be remote.

Key Duties:

Regulatory and Reporting:

  • Monitor relevant laws, regulations and standards to ensure organization's security practices align with regulatory requirements.
  • Own regulatory compliance programs such as NY-DFS, GLBA and FFIEC assessments.
  • Serve as primary point of contract for regulatory bodies during audits.
  • Creation of materials for and participation in regulatory exams and quarterly briefings to regulators as required.
  • Develop responses and drive resolution of Issues, Deficiencies, Matters Requiring Attention (MRAs), and Supervisory Recommendations (SR's) assigned to US Region Information Security.
  • Work closely with US TI&I Risk & Controls Team, Regulatory Affairs, Operational Risk Management (ORM) and Internal Audit as required.
  • Assist with creation of materials for Annual Cyber Security Board Review and Quarterly Board Risk Committee Meetings.
  • Creation of materials for various reporting committees and forums, including weekly status.
  • Creation of materials for various reporting committees and forums, including weekly reports, business unit reviews and horizontal review.

Control Management:

  • Conduct Risk and Control Self-Assessment (RCSA) for Information Security and provide input into RCSA for all other lines of business. .
  • Mapping of controls to industry frameworks (e.g. NIST, PCI, MITRE)
    • Work closely with controls testing teams.
  • Drive remediation of ineffective controls owned by the US and provide oversight of control effectiveness for enterprise controls impacting the US.
    • Act as secretary for the Cyber Security Controls Oversight Council.

Leadership and Cross-Functional Relationships:

  • Recruiting and hiring of Information Security professionals to support target operating model changes.
  • Provides ongoing advice and direction on a variety of complex conceptual or interpretative issues.
  • Establishing and leveraging peer's relationships within the US Region and Parent bank organizations.
  • Will be required to foster relationships with middle to senior management, and senior executives across a range of functions including Risk Management and Technology.

Who You Are:

  • You can demonstrate experience at a financial institution of similar scope and scale with direct experience working with regulators and regulatory compliance programs.
  • It's an asset if you have advanced knowledge of applicable US laws and regulations as they relate to Information Security and the effective management of Information Security Risks.
  • You are a caring and accountable leader.
  • You have experience developing and implementing strategic team goals. You have experience coaching employees and inspiring successful team performance.
  • You know that details matter. You notice things that others don't. Your critical thinking skills help to inform your decision-making.
  • Values matter to you. You bring your real self to work, and you live our values - trust, teamwork, and accountability

This role is Hybrid and requires 2-3 days on-site per week.

At CIBC, we offer a competitive total rewards package. This role has an expected salary range of $190, $230,000.00 for the Chicago market based on experience, qualifications, and location of the position. The successful candidate may be eligible to participate in the relevant business unit's incentive compensation plan, which may also include a discretionary bonus component. CIBC offers a full range of benefits and programs to meet our employee's needs; including Medical, Dental, Vision, Health Savings Account, Life Insurance, Disability, and Other Insurance Plans, Paid Time Off (including Sick Leave, Parental Leave and Vacation), Holidays and 401(k), in addition to other special perks reserved for our team members.

This position does not offer visa sponsorship. ​

#LI-TA  

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.

  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.

  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.

*Subject to plan and program terms and conditions

What you need to know

  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-

  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.

  • We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location

MN-Minnesota - Virtual

Employment Type

Regular

Weekly Hours

40

Skills

Analytical Thinking, Information Management, Information Security, Leadership, Long Term Planning, People Management, Security Risk, Security Trainings


Similar jobs

  • Work in company

    Director Information Security

    Only for registered members

    This position establishes and administers the overall strategies and procedures for the information security function.Develops and implements governance, risk, and compliance (GRC), through Identity & Access Management, 3rd party risk management, business continuity, data managem ...

    Saint Paul $126,495 - $189,743 (USD)

    1 month ago

  • Work in company

    Director of Information Security

    Only for registered members

    >The Director of Information Security is responsible for designing, leading, and sustaining an enterprise-wide information security and risk management program that protects the organization's data, systems, and operations. · Establish and execute a comprehensive information secu ...

    Saint Paul

    1 month ago

  • Work in company

    Information Security Analyst

    Only for registered members

    This position will provide secure technical support, problem resolution and implementation of information security solutions. · ...

    Saint Paul

    3 weeks ago

  • Work in company

    Information Security Engineer

    Only for registered members

    + Deploy, integrate, and support security tools to protect cloud, on-premises, and hybrid environments. · + Lead engineering efforts for security standards development, · operational support,& collaboration with IT & business stakeholders to mitigate risks. · Job summary: Secure ...

    Saint Paul $85,000 - $110,000 (USD)

    1 week ago

  • Work in company

    Director of Information Security

    Only for registered members

    The Director of Information Security is responsible for designing and leading an enterprise-wide information security program that protects the organization's data and systems. · Establish and execute a comprehensive information security strategy · Lead enterprise-wide risk iden ...

    St Paul, MN

    1 month ago

  • Work in company

    Information Security Engineer

    Only for registered members

    Join the 2,800+ professionals of Minnesota IT Services (MNIT) who connect Minnesotans to services that will improve their lives. This position will be part of the Enterprise Security team, which embeds security protection statewide. · Job Summary · The Information Security Engine ...

    Saint Paul $77,402 - $127,660 (USD)

    21 hours ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The State of Minnesota is committed to equity and inclusion, and invests in employees by providing benefits, support resources, and training and development opportunities. · ...

    St Paul, MN

    1 month ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The State of Minnesota is committed to equity and inclusion. Join our team as a Principal Information Security Engineer (PISE) and take the lead in protecting the state's most important information and systems. · Mentor and train team members to build skills. · Design security co ...

    Saint Paul $39.73 - $67.92 (USD)

    1 month ago

  • Work in company

    Information Security Analyst

    Only for registered members

    The work you'll do is more than just a job. · Position requires a minimum of three (3) years of IT related experience in an IT related field that includes direct experience using information security tools. · ...

    St Paul, MN

    3 weeks ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The Information Security Engineer is responsible for deploying, integrating and supporting security tools and solutions that protect the organization's cloud on premises and hybrid environments.Frequently leads engineering efforts. · Contributes to the development of security sta ...

    Saint Paul $85,000 - $110,000 (USD)

    1 week ago

  • Work in company

    Information Security Analyst

    Only for registered members

    Job summary: · The work you'll do is more than just a job.At the State of Minnesota, employees play a critical role in developing policies, providing essential services,and working to improve the well-being and quality of life for all Minnesotans. · The State of Minnesota is comm ...

    Saint Paul $33.38 - $54.87 (USD)

    4 weeks ago

  • Work in company

    Director of Information Security

    Only for registered members

    The Director of Information Security is responsible for designing, leading, and sustaining an enterprise-wide information security and risk management program that protects the organization's data, systems, and operations. · ...

    Saint Paul

    1 month ago

  • Work in company

    Information Security Engineer

    Only for registered members

    Join the 2,800+ professionals of Minnesota IT Services (MNIT) who connect Minnesotans to services that will improve their lives. This position will be part of the Enterprise Security team, which embeds security protection statewide. · Job Summary · The · Information Security Engi ...

    St Paul, MN $95,000 - $165,000 (USD) per year

    12 hours ago

  • Work in company

    Information Security Engineer

    Only for registered members

    +Job summary · An Information Security Engineer will work closely with application and cloud platform teams to provide security consulting and support while championing security initiatives. · +Recommend security controls... · Develop system security plans... · ...

    Saint Paul

    1 week ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The State of Minnesota is committed to equity and inclusion, and invests in employees by providing benefits, support resources, and training and development opportunities.Join the 2, · 800+ professionals of Minnesota IT Services (MNIT) who connect Minnesotans to services that wil ...

    Saint Paul $39.14 - $66.92 (USD)

    4 weeks ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The Information Security Engineer will work closely with application and cloud platform teams to provide security consulting and support while championing security initiatives on behalf of the MNIT Enterprise Security Office (ESO). · ...

    St Paul, MN

    1 week ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The Information Security Engineer will work closely with application and cloud platform teams to provide security consulting and support while championing security initiatives on behalf of the MNIT Enterprise Security Office (ESO). The engineer will recommend security controls, p ...

    Saint Paul $37.07 - $61.14 (USD)

    1 week ago

  • Work in company

    Information Security Engineer

    Only for registered members

    Join our team as a Principal Information Security Engineer (PISE) and take the lead in protecting the state's most important information and systems. · ...

    Saint Paul

    1 month ago

  • Work in company

    Information Security Engineer

    Only for registered members

    Join our team as a Principal Information Security Engineer (PISE) and take the lead in protecting the state's most important information and systems. · ...

    Saint Paul, MN

    1 month ago

  • Work in company

    Information Security Engineer

    Only for registered members

    The Information Security Engineer (ISE) will work closely with application and cloud platform teams to provide security consulting and support while championing security initiatives on behalf of the MNIT Enterprise Security Office (ESO). · ...

    Saint Paul, MN

    1 week ago

  • Work in company

    Director Information Security

    Only for registered members

    This position establishes and administers the overall strategies and procedures for the information security function. Develops and implements governance, risk, and compliance (GRC), through Identity & Access Management, 3rd party risk management, business continuity, data manage ...

    St Paul, MN

    1 month ago