Talent.com
cibc
Sr. Security Service Manager, Application Securitycibc • Toronto, ON
Search for other jobs
Sr. Security Service Manager, Application Security

Sr. Security Service Manager, Application Security

cibc • Toronto, ON
22 days ago
Job type
  • Full-time
Job description

Nous bâtissons une banque axée sur les relations pour un monde moderne. Nous recrutons des professionnels talentueux et passionnés qui ont à cœur de faire ce qu’il faut pour nos clients.

À la Banque CIBC, nous misons sur vos forces et vos ambitions pour vous donner le pouvoir d’agir. Les membres de notre équipe disposent de ce dont ils ont besoin pour apporter une contribution significative et être valorisés, à la fois pour ce qu’ils sont et ce qu’ils font.

Pour en savoir plus sur la Banque CIBC, visitez le site .

What you will be doing

As a Senior Security Services Manager, Application Security, you will play a pivotal role in advancing CIBC’s enterprise-wide Application Security program. Your primary focus will be to strengthen application security testing capabilities and to ensure that security and protection are integrated throughout the development lifecycle of all applications and the lifecycle of all data across the enterprise. Your efforts will directly contribute to safeguarding our clients, employees, and the bank, while supporting CIBC’s commitment to a flexible and empowering work environment.

How you will succeed

  • Strategic Leadership and Governance – You will drive the creation and ongoing refinement of the Application Security strategy, with a particular emphasis on advancing security testing methodologies and tools. This role requires strong cross-functional collaboration to gather requirements, develop business cases and lead projects, including proof of concepts, in the capacity of a product owner. Having a continuous improvement mindset is essential, as you will be responsible for identifying and implementing opportunities to enhance both security testing processes and operational efficiency within the domain.
  • Security Testing and Assessment – You will oversee the implementation, management, and continuous improvement of security testing services, such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). You will measure and report on the effectiveness of these activities to ensure comprehensive coverage and timely remediation of identified vulnerabilities. Additionally, you will conduct regular reviews and analysis of testing results, trends, and emerging threats, using these insights to inform and strengthen risk mitigation strategies.
  • Communication and Advocacy – You will prepare and delivery clear, compelling documentation and presentations to executive leadership, effectively articulating the value and necessity of security testing initiatives. You will also drive awareness and provide training to application development teams, ensuring they understand the importance and effective use of security testing tools and processes. Your role will include evaluating business needs against current and emerging risks and providing actionable recommendations to strengthen the organization’s security posture.
  • Advisory and Relationship Management – You will act as a trusted advisor to application development, operations, and infrastructure teams, guiding them to integrate security testing into their workflows and prioritize remediation efforts based on risk. You will oversee the identification, assessment and management of security risks and design flaws in key applications, offering practical and prioritized solutions. Staying current with the evolving threat landscape and cultivating partnerships with industry peers and vendors will be essential to ensuring CIBC remains at the forefront of application security.

Who You Are

  • You can demonstrate experience in Application Security, Vulnerability Management, and data security standards and best practices. You bring senior-level experience in application security, such as managing SAST, SCA, DAST, or similar security services. It is considered an asset if you have DevSecOps knowledge and experience. You can demonstrate experience in dynamic and static application security testing, penetration testing, web application firewalls, runtime protection, mobile application security, and broader threat and vulnerability management capabilities.
  • You are a certified professional and it is considered an asset if you hold a CISSP, CISA, or CISM designation in good standing.
  • You are passionate about people. You find meaning in relationships and surround yourself with a diverse network of partners. You connect with others through respect and authenticity.
  • You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.
  • You know that details matter. You notice things that others do not. Your critical thinking skills help to inform your decision making.
  • You embrace and champion change, continually evolving your approach to deliver your best work.
  • Values matter to you. You bring your real self to work, and you live our values – trust, teamwork, and accountability.

#LI-TA

Ce que la Banque CIBC vous offre

À la Banque CIBC, vos objectifs sont une priorité. En fonction de vos forces et de vos ambitions en tant qu’employé, nous nous efforçons de créer des occasions qui vous permettront d’exploiter votre potentiel. Notre objectif est de vous offrir une carrière, pas uniquement un chèque de paie.

  • Nous nous efforçons de vous récompenser de façon personnalisée et pertinente, notamment en vous offrant un salaire concurrentiel, une rémunération au rendement, des avantages bancaires, l’adhésion à un programme d’avantages sociaux*, à un régime de retraite à prestations déterminées* et à un régime d’achat d’actions par les employés, des vacances, du soutien pour votre bien-être et Créateur de moments, notre programme social de reconnaissance basé sur des points.

  • Grâce à nos espaces et à nos outils technologiques, il devient facile de réunir les grands esprits pour créer des solutions novatrices qui améliorent les choses pour nos clients.

  • Nous favorisons une culture qui encourage l’expression de vos ambitions au moyen d’initiatives comme la journée Raison d’être, une journée de congé payé dont vous pouvez profiter pour investir dans votre croissance et votre perfectionnement.

* Sous réserve des modalités du régime et du programme

Ce que vous devez savoir

  • La Banque CIBC s’est engagée à créer un milieu de travail intégrateur où tous les membres de l’équipe et les clients se sentent à leur place. Nous recherchons des candidats dotés d’un large éventail de compétences et offrons une expérience accessible aux candidats. Si vous avez besoin d’une solution d’adaptation, écrivez à .

  • La Banque CIBC s’engage à faire preuve de clarté dans le cadre de son processus d’embauche. Tous les affichages visent à pouvoir des postes pour lesquels nous recrutons activement, à moins d’avis contraire.

  • Vous devez être légalement admissible à travailler au Canada dans les lieux précisés ci-dessus et, s’il y a lieu, détenir un permis de travail ou d’études valide.

  • Nous pourrions vous demander de remplir une évaluation fondée sur les attributs et d’autres tests de compétences (comme la simulation, la programmation, la maîtrise du français)

  • Nous utilisons des outils d’intelligence artificielle pendant le processus de recrutement. Notre objectif pour le processus de demande est d’en apprendre davantage sur vous et sur tout ce que vous avez à offrir, et de vous donner l’occasion d’en apprendre davantage sur nous.

Lieu de travail

Toronto-81 Bay, 18th Floor

Type d’emploi

Permanent

Heures de travail hebdomadaires

37.5

Compétences

Amélioration continue, Collaboration, Communication, Connaissances techniques, Évaluation des risques de sécurité, Exploitation du réseau, Gestion de vulnérabilité, Normes de sécurité, Opérations de sécurité, Pensée analytique, Pensée critique, Programme d’amélioration continuelle, Résolution de problèmes en groupe, Sécurité d'applications, Sécurité de l'information, Service de sécurité, Stratégie de sécurité, Test de sécurité, Test de sécurité des applications, Test dynamique de sécurité des applications (DAST), Test statique de sécurité des applications (SAST), Travail d'équipe

Create a job alert for this search

Sr. Security Service Manager, Application Security • Toronto, ON