Sr. Security Service Manager, Application Security

CIBC

Toronto

Hybrid

CAD 140,000 - 200,000

Full time

24 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Incentive pay
Banking benefits
Benefits program
Defined benefit pension
Employee share purchase plan
Vacation offering
Wellbeing support
MomentMakers recognition

Job summary

CIBC in Toronto is seeking a Senior Security Services Manager, Application Security, to lead enterprise-wide security testing capabilities and integrate protection across the development lifecycle.

You will drive strategic governance, oversee SAST/DAST/SCA testing, communicate with executives, and advise cross-functional teams to strengthen the organization's security posture while maintaining a flexible, hybrid work model.

Qualifications

  • Experience in Application Security, Vulnerability Management, and data security best practices.
  • Certified professional assets such as CISSP/CISA/CISM are advantageous.
  • Strong background in both static and dynamic testing methods and security tooling.

Responsibilities

  • Strategic Leadership and Governance – shape the Application Security strategy and drive cross-functional projects.
  • Security Testing and Assessment – manage SAST, DAST, and SCA services and remediation tracking.
  • Communication and Advocacy – prepare executive-level documentation and train development teams.
  • Advisory and Relationship Management – guide DevOps teams to embed security in workflows and risk-based prioritization.

Skills

Application Security
Vulnerability Management
SAST
DAST
SCA
Penetration Testing
DevSecOps
Threat & Vulnerability Management
CISSP/CISA/CISM

Job description

We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.

At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.

To learn more about CIBC, please visit CIBC.com

What You Will Be Doing

As a Senior Security Services Manager, Application Security, you will play a pivotal role in advancing CIBC’s enterprise-wide Application Security program. Your primary focus will be to strengthen application security testing capabilities and to ensure that security and protection are integrated throughout the development lifecycle of all applications and the lifecycle of all data across the enterprise. Your efforts will directly contribute to safeguarding our clients, employees, and the bank, while supporting CIBC’s commitment to a flexible and empowering work environment.

At CIBC we enable the work environment most optimal for you to thrive in your role. You will have the flexibility to manage your work activities within a hybrid work arrangement where you will spend 1-3 days per week on-site, while other days will be remote.

How You Will Succeed
  • Strategic Leadership and Governance – You will drive the creation and ongoing refinement of the Application Security strategy, with a particular emphasis on advancing security testing methodologies and tools. This role requires strong cross-functional collaboration to gather requirements, develop business cases and lead projects, including proof of concepts, in the capacity of a product owner. Having a continuous improvement mindset is essential, as you will be responsible for identifying and implementing opportunities to enhance both security testing processes and operational efficiency within the domain.
  • Security Testing and Assessment – You will oversee the implementation, management, and continuous improvement of security testing services, such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). You will measure and report on the effectiveness of these activities to ensure comprehensive coverage and timely remediation of identified vulnerabilities. Additionally, you will conduct regular reviews and analysis of testing results, trends, and emerging threats, using these insights to inform and strengthen risk mitigation strategies.
  • Communication and Advocacy – You will prepare and delivery clear, compelling documentation and presentations to executive leadership, effectively articulating the value and necessity of security testing initiatives. You will also drive awareness and provide training to application development teams, ensuring they understand the importance and effective use of security testing tools and processes. Your role will include evaluating business needs against current and emerging risks and providing actionable recommendations to strengthen the organization’s security posture.
  • Advisory and Relationship Management – You will act as a trusted advisor to application development, operations, and infrastructure teams, guiding them to integrate security testing into their workflows and prioritize remediation efforts based on risk. You will oversee the identification, assessment and management of security risks and design flaws in key applications, offering practical and prioritized solutions. Staying current with the evolving threat landscape and cultivating partnerships with industry peers and vendors will be essential to ensuring CIBC remains at the forefront of application security.
Who You Are
  • You can demonstrate experience in Application Security, Vulnerability Management, and data security standards and best practices. You bring senior-level experience in application security, such as managing SAST, SCA, DAST, or similar security services. It is considered an asset if you have DevSecOps knowledge and experience. You can demonstrate experience in dynamic and static application security testing, penetration testing, web application firewalls, runtime protection, mobile application security, and broader threat and vulnerability management capabilities.
  • You are a certified professional and it is considered an asset if you hold a CISSP, CISA, or CISM designation in good standing.
  • You are passionate about people. You find meaning in relationships and surround yourself with a diverse network of partners. You connect with others through respect and authenticity.
  • You give meaning to data. You enjoy investigating complex problems and making sense of information. You communicate detailed information in a meaningful way.
  • You know that details matter. You notice things that others do not. Your critical thinking skills help to inform your decision making.
  • You embrace and champion change, continually evolving your approach to deliver your best work.
  • Values matter to you. You bring your real self to work, and you live our values – trust, teamwork, and accountability.
What CIBC Offers

At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.

  • We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
  • Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
  • We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
  • Subject to plan and program terms and conditions
What You Need To Know
  • CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact Mailbox.careers-carrieres@cibc.com
  • CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.
  • You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
  • We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).
  • We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location

Toronto-81 Bay, 18th Floor

Employment Type

Regular

Weekly Hours

37.5

Skills

Analytical Thinking, Application Security, Application Security Testing, Collaboration, Communication, Continual Improvement Process, Continuous Improvement, Critical Thinking, Dynamic Application Security Testing (DAST), Group Problem Solving, Information Security, Network Operations, Security Operations, Security Risk Assessment, Security Service, Security Standards, Security Strategy, Security Testing, Static Application Security Testing (SAST), Teamwork, Technical Knowledge, Vulnerability Management

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Service Manager, Application Security
Sr. Security Service Manager, Application Security

Socket.dev • Toronto

Hybrid
CAD 120,000 - 180,000
Competitive salary
MomentMakers recognition program
Purpose Day
Sr. Security Service Manager, Application Security
Sr. Security Service Manager, Application Security

Canadian Imperial Bank of Commerce • Toronto

Hybrid
CAD 150,000 - 190,000
Competitive salary
Banking benefits
Defined benefit pension plan
+4
Senior Consultant, Privileged Access Management
Senior Consultant, Privileged Access Management

CIBC • Toronto

Hybrid
CAD 110,000 - 140,000
Sr. Consultant, Supplier Risk Management
Sr. Consultant, Supplier Risk Management

CIBC • Toronto

Hybrid
CAD 110,000 - 140,000
Sr Director, App Delivery
Sr Director, App Delivery

CIBC • Toronto

Hybrid
CAD 180,000 - 230,000
Director, Design and Solutions
Director, Design and Solutions

CIBC • Toronto

On-site
CAD 150,000 - 190,000
MomentMakers recognition program
Employee share purchase plan
Defined benefit pension plan
Consultant, IT Quality Assurance
Consultant, IT Quality Assurance

Canadian Imperial Bank of Commerce • Toronto

On-site
CAD 90,000 - 120,000
Audit Manager, Technology Operations & Security
Audit Manager, Technology Operations & Security

CIBC • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Incentive pay
Banking benefits
+6
Senior Audit Manager, Validations Centre of Excellence
Senior Audit Manager, Validations Centre of Excellence

CIBC • Toronto

Hybrid
CAD 120,000 - 180,000
Competitive salary
Incentive pay
Banking benefits
+6
Consultant, Technology Controls
Consultant, Technology Controls

CIBC • Toronto

Hybrid
CAD 90,000 - 130,000
Competitive salary
Defined benefit pension plan
Employee share purchase plan
+3