Senior CIEM Specialist, Information Security & IAM
BMOAbout the role
Application Deadline:
10/30/2024Address:
4100 Gordon Baker RoadJob Family Group:
TechnologyCloud Infrastructure Enablement Management (CIEM) experience is a MUST
Provides leadership within IAM Security Governance and Security best practice in support of businesses/groups and BMO overall. Builds relationships and liaises with stakeholders to understand problems and opportunities and recommends solutions leveraging Cloud Infrastructure Enablement Management (CIEM) tools for optimal management of identities and privileges in cloud environments. Ensures that requirements map to a real business need, are approved by all relevant stakeholders, and meet essential quality standards. Participates or conducts user acceptance testing to ensure that changes made are in alignment with business requirements. Provides great customer service in support of the information security processes, applications and infrastructure.
- Provides strategic input into Security best practices as a trusted advisor and a subject matter expert on relevant regulations and policies
- Assesses BMO cloud environments & applications for compliance with IAM standards.
- Identifies gaps and recommend remediation strategies based on security best practices
- Configures CIEM tool to monitor and report on IAM standards and controls
- Collaborates with stakeholders for remediation and continuous improvements
- Develops cloud governance processes and recommends IAM controls & design patterns based on Security practices
- Presents and communicates at all levels within IT and across business units.
- Prepares and delivers presentations for senior leaders.
- Gathers requirements and documents these requirements for use in various audits, reports, & projects.
- Identifies opportunities to strengthen the capability of the information security organization at BMO, such as: sharing expertise to promote technical development, mentoring employees, building communities of practice and networks across information security and technology.
- Works with stakeholders for remediation and continuous improvements
- Performs documentation writing and maintenance of new and existing processes, procedures and requirements.
- Recommends remediation strategies on the control gaps/ findings and approaches to streamline and integrate information security processes in the organization to improve overall efficiency.
- Remains alert to new information security technologies and threats that present risk to the enterprise and determines the best approach to mitigate these risks.
- Stays abreast of industry trends/risks related to information security, technology and business trends / risks through participation in professional associations, practice communities & individual learning.
- Ensures consistent, high quality security practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
- Operates at a group/enterprise-wide level and serves as a specialist resource to senior leaders and stakeholders.
- Implements changes in response to shifting trends.
- Broader work or accountabilities may be assigned as needed.
Qualifications:
- Typically, between 10-15 years of relevant experience in Information Security domain and 5+ years in a leadership capacity
- Bachelor’s Degree in Computer Science, Engineering, Information Security or related disciplines
- Information Security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
- Expert in information security, technology governance and processes
- Deep acumen in Identity Access Management and Privileged Access Management space especially in a cloud setting using CIEM platforms
- Experience with CIEM ecosystem from a process compliance and configuration perspective
- Experienced with IAM controls & design patterns based on Security practices
- Experience identifying gaps and recommending remediation strategies based on security best practices
- Understanding and experience in one or more information security domains (e.g. data protection and privacy, compliance, risk management, application and cloud security, and incident management)
- Experience in developing policy and implementing security control framework in the Financial or any other highly regulated industry
- A clear understanding of regulatory, governance, privacy, and industry best practices.
- Knowledge of Information Security processes, procedures and controls - Expert.
- Understanding and problem-solving ability of Information Security issues across the bank - Expe
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s