Sr. Consultant, Supplier Risk Management

CIBC US

Toronto

Hybrid

CAD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CIBC in Toronto is seeking a Senior Consultant, Supplier Risk Management to conduct third party due diligence and identify information security risks. You will collaborate with business units, suppliers and technology teams to implement practical risk controls.

The role blends advisory and delivery work, with a focus on detailed risk assessments, reporting, and remediation guidance across the supplier landscape, in a hybrid environment with on-site and remote days.

Qualifications

  • Experience in Information Security and Third Party risk assessments.
  • Familiarity with cyber assessments in financial/legal environments is a plus.
  • Knowledge of cloud computing technologies and security monitoring.

Responsibilities

  • Conduct ongoing third party due diligence and assess information security risks.
  • Review independent assurance reports and determine risk impact.
  • Provide practical remediation guidance to suppliers and partners.
  • Maintain third party risk database and deliver analytics to stakeholders.
  • Communicate risk findings to executive management with actionable recommendations.

Skills

Information Security
Third Party risk assessments
Vulnerability testing
Penetration testing
Application security
Cloud computing

Tools

Archer GRC
Black Kite

Job description

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients. At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute. To learn more about CIBC, please visit CIBC.com.

What you’ll be doing

You are passionate about Information Security and Risk Advisory services and want to join our growing information security group. As a Senior Consultant, Supplier Risk Management you will be responsible for conducting Third Party due diligence assessments to identify potential risks to help our technology and business stakeholders meet security goals and objectives. Utilizing your relationship building skills, you will partner with line of business, Third Party suppliers, technology teams and help them proactively identify potential risks and present recommendations that are practical and achievable. At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.

How you’ll succeed

Advisory/Assessment Services – Conduct ongoing Third Party due diligence, including the review of independent assurance reports to help determine the potential information security risk to CIBC. Assess business needs against potential risks and provide your recommendations to enhance our information security landscape.

Delivery and Execution - You will help us execute detailed Information Security risk assessments for key Third Party suppliers, conduct ongoing monitoring of these suppliers and provide detailed reporting/analytics. Provide direction and remediation directions to Third Parties and business partners. Maintain and manage third party risk database to ensure proper risk management and proper awareness.

Communication - Build and present documentation to executive management aimed at communicating potential risks and providing recommendations. Provide feedback to and participate in the design and implementation of security assessment processes across the organization. Research, design, and implement security monitoring practices and operationalize these processes across the group.

Who you are

You can demonstrate experience in Information Security, Third Party risk assessments, Vulnerability & Penetration testing, and application security development projects (with exposure to Agile Development processes). It's an asset if you have familiarity with the Financial Services industry and experience with cyber assessments on legal firms. You have experience in Cloud Computing technologies, use of the Archer GRC tool, External Threat Intelligence tools (specifically Black Kite), and CISSP, CTPRP, CISM, or related cyber certifications are considered assets. (This role will be supporting the Legal LoB.)

You’re passionate about people. You find meaning in relationships, and surround yourself with a diverse network of partners. You build trust through respect and authenticity. You’re digitally savvy. You seek out innovative solutions and embrace evolving technologies. You can easily adapt to new tools and trends. Your influence makes an impact. You know that relationships and networks are essential to success. You inspire outcomes by making yourself heard. You give meaning to data. You enjoy investigating complex problems, and making sense of information. You’re confident in your ability to communicate detailed information in an impactful way. Values matter to you. You bring your real self to work and you live our values – trust, teamwork and accountability.

Prior to starting in this role, security checks, including a criminal record check must be successfully completed to the satisfaction of CIBC. An annual criminal record check may also be required.

What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck. We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program. Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients. We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development. *Subject to plan and program terms and conditions

What you need to know

CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com.

CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise. You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit. We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency). We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.

Job Location Toronto-81 Bay, 19th Floor Employment Type Regular Weekly Hours 37.5 Skills Due Diligence, Information Security Risk, Regulatory Compliance, Risk Management At CIBC, we are in business to help our clients, employees and shareholders achieve what is important to them. Our ability to create value for all CIBC stakeholders is driven by a business culture based on common values: Trust, Teamwork and Accountability. Working with CIBC makes you a part of a work environment committed to our clients, employees and communities - a place where you can excel. Every day, our 48,000 employees help our clients achieve their financial goals, because what matters to our clients, matters to us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Specialist
Senior Information Security Specialist

CIBC US • Toronto

Hybrid
CAD 110,000 - 140,000
Competitive salary
Banking benefits
Defined benefit pension plan
+2
Consultant, Risk Governance
Consultant, Risk Governance

CIBC US • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Incentive pay
Banking benefits
+6
Senior Information Security Specialist
Senior Information Security Specialist

CIBC • Toronto

Hybrid
CAD 110,000 - 180,000
Sr. Consultant, Business Enablement and Governance
Sr. Consultant, Business Enablement and Governance

CIBC US • Toronto

Hybrid
CAD 110,000 - 140,000
Hybrid work arrangement
Senior Director, Group Product Owner - Enterprise Governance, Risk & Compliance (eGRC)
Senior Director, Group Product Owner - Enterprise Governance, Risk & Compliance (eGRC)

CIBC US • Toronto

Hybrid
CAD 180,000 - 240,000
Competitive salary
Incentive pay
Banking benefits
+4
Consultant, Risk Analytics and Credit Decisioning
Consultant, Risk Analytics and Credit Decisioning

CIBC US • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive compensation
Banking benefit*
Wellbeing support
+2
Senior Compliance Officer, Corporate Functions Compliance
Senior Compliance Officer, Corporate Functions Compliance

CIBC US • Toronto

Hybrid
CAD 110,000 - 150,000
Hybrid work model
Consultant, Technology Enablement
Consultant, Technology Enablement

CIBC US • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Banking benefits
Defined benefit pension plan
+1
Consultant, Data Risk (12-months Fixed Term)
Consultant, Data Risk (12-months Fixed Term)

CIBC US • Toronto

On-site
CAD 90,000 - 120,000
Competitive compensation
Banking benefit
Wellbeing support
+2
Director, Inclusion - External Partnerships
Director, Inclusion - External Partnerships

CIBC US • Toronto

Hybrid
CAD 140,000 - 190,000