Jobs and Careers
CI

US Information Security Director of Regulatory and Controls

CIBC
IL-70 W Madison St, 9th Fl, United States, United Statesfull_timeVerifiedPosted 16 Jul 2025
💰 $210,000/yr($190,000/yr$210,000/yr)

About the role

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

As the US Region Information Security Director of Regulatory and Controls, you will be responsible for the department’s efforts in ensuring compliance with relevant regulations and effectiveness of information security controls.

What you'll be doing

As the US Region Information Security Director of Regulatory and Controls, you will be responsible for the department’s efforts in ensuring compliance with relevant regulations and effectiveness of information security controls. You will monitor relevant laws, regulations, and standards to ensure CIBC US security practices align with regulatory requirements and you will own regulatory compliance programs such as NY-DFS, GLBA and FFIEC.  You will serve as primary point of contract for regulatory bodies during audits and be responsible for creation of materials for and participation in exams and quarterly briefings.  You will be responsible for Information Security control management and providing oversight of controls that impact the US team.   This includes conducting the Risk and Control Self-Assessment (RCSA) for Information Security and provide input into RCSA’s for all other lines of business.

Work Arrangement: At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.

How you'll succeed

Here are some key duties for this role:

Regulatory and Reporting

  • Monitor relevant laws, regulations and standards to ensure organization’s security practices align with regulatory requirements.

  • Own regulatory compliance programs such as NY-DFS, GLBA and FFIEC assessments.

  • Serve as primary point of contract for regulatory bodies during audits.

  • Creation of materials for and participation in regulatory exams and quarterly briefings to regulators as required.

  • Develop responses and drive resolution of Issues, Deficiencies, Matters Requiring Attention (MRAs), and Supervisory Recommendations (SR’s) assigned to US Region Information Security.

  • Work closely with US TI&I Risk & Controls Team, Regulatory Affairs, Operational Risk Management (ORM) and Internal Audit as required.

  • Assist with creation of materials for Annual Cyber Security Board Review and Quarterly Board Risk Committee Meetings.

  • Creation of materials for various reporting committees and forums, including weekly status

  • Creation of materials for various reporting committees and forums, including weekly reports, business unit reviews and horizontal reviews.

Control Management

  • Conduct Risk and Control Self-Assessment (RCSA) for Info

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CIBC

View company profile →