Sr. Manager Information Security Governance
CIBCAbout the role
We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
Protect the bank’s regulatory standing by ensuring compliance and exam readiness, managing regulatory risk. This is a high visibility/high impact role.
There are 3 primary components of the role: regulatory support, internal audit support, regulatory program compliance.
The Sr Manager, Information Security Regulatory & Exam is responsible for regulatory exam support, quarterly regulatory briefings and adhoc regulator asks. You will also support Internal Audit activities. You will also be responsible for overall regulatory compliance, including regulatory compliance program ownership (e.g. NY-DFS, GLBA, FFIEC), performing/overseeing assessments, monitoring regulatory changes and recommending action.
Provide regulatory reporting requirements and ensure timely, accurate and message appropriate reporting.
Support may also include other teams under the Chief Security Office. Support may include and is not limited to Fraud, Operational Resilience, Third Party Governance & Physical Security.
This is a hands on role with prep, coordination, direct activity ownership and oversight.
KEY ACCOUNTABILITIES
Regulatory Exams
End to end exam management
Ensure regulatory exam readiness
Review and suggest approach (responses, evidence) to regulatory exam letters
Coordinate response and evidence collection (which may include direct response/fulfillment), evaluating and questioning, aligning on strategic messaging, presenting to sr. leadership to align on audit ready responses
Regulatory Remediation
Actively engage in regulatory remediation activities, which may include analysis of regulatory feedback, suggesting recommended action, coordinating and evaluating responses, performing remediation actions, preparing regulatory update decks, creating speaking notes, ensuring messaging alignment with internal stakeholders and addressing any post meeting follow ups.
Regulatory Briefings
Prepare oversight briefing materials, which includes recommendations on approach/key themes, with speaking notes
Coordinate follow up activities
Internal Audit
Ensure internal teams are prepared for Internal Audit activities
Manage and socialize Internal Audit calendar
Coordinate audits, including fulfillment and evaluation of responses and evidence provided
Escalate potential issues before formal identification
Ensure timely review and response to audit reports
Oversee creation of new audit related deficiencies
Serve as point for monthly continuous monitoring
Program Management - Regulatory Program Compliance
Ensure NY DFS program annual activities are completed, including the NY Branch assessment, surveys, with risks identified and actioned
Ensure FFIEC/GLBA program activities are completed, including the annual assessment with risks identified and actioned
Complete annual Regulatory Control Management activities
Complete annual Regulatory Control Requirement Assessment
Reporting
Ensure overall CSO organization regulatory reporting dashboard is delivered
Monitor relevant laws, regulations and standards to ensure organization’s security practices align with regulatory requirements. Create and distribute monthly regulatory development update reporting.
Assist with creation of materials for Annual Cyber Security Board Review and Quarterly Board
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s