Director, US Internal Controls Validation
CIBCAbout the role
We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
The Director, US Internal Controls Validation, US ORM will be responsible for, but not limited to the following activities:
Sustain and enhance – as prudent – the US ICV Program and accompanying artifacts.
Develop US ICV fiscal year plan and provide reporting on program status.
Provide independent effective challenge over first line of defense control activities and threat based testing.
Test first line of defense controls as dictated by the US ICV Program.
Identify and notify the first line of defense of any control gaps, ineffective controls, or non-adherence to testing requirements as identified via US ICV program execution.
Promote a “controls and operational risk culture” that includes managing internal relationships to promote acceptance and implementation of operational risk programs.
Stay current on regulatory changes and industry leading practices in operational risk, control frameworks, and control testing to ensure CIBC operational risk management meets regulatory expectations, and is effective and efficient.
Recommend changes to first line of defense – primarily within the context of the control and control testing environments – in order to enhance oversight, operational efficiency, and effectiveness.
As a key contributor to the business unit, this job has the authority to recommend changes to business processes in order to enhance operational efficiency and effectiveness.
As a manager of people, this job has the authority to assign tasks to employees within their span of control, select individuals for hire, assess individual performance, make employee compensation decisions and take disciplinary measures up to and including termination.
10 years of relevant work experience in the financial industry is desired. Large Financial Institution or Large Foreign Banking Organization second line of defense experience is preferred.
At least 5 years of experience in cybersecurity control testing and/or second line of defense independent effective challenge over first line of defense cybersecurity control testing activities.
Strong understanding of cybersecurity frameworks (e.g. NIST, ISO 27001) and compliance requirements.
Bachelor’s degree preferably in information systems, computer science, information technology, network security, or cybersecurity.
Cyber related subject matter expert with a strong understanding of cybersecurity principles and tools.
Desired certifications include Certified Ethical Hacker (CEH); Certified Information Systems Security Professional (CISSP); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); and/or Certified Information Security Manager (CISM).
Excellent leadership a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s