Cyber and Technology Operational Risk Manager
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Information Security
Cyber and Technology Operational Risk Manager
3 days ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients. At CIBC, we embrace your strengths and your ambitions, so you are empowered team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute. To learn more about CIBC, please visit
What You’ll Be DoingThe US Operational Technology and Cyber Risk Manager (Risk Manager) acts as a second line of defense in ensuring that the bank’s technology and cybersecurity operational risk and control frameworks, policies, standards and procedures are understood and used effectively to manage operational risk. As the Risk Manager in the second line of defense risk management function, you will provide expert oversight and support for the identification, measurement, mitigation, monitoring, and reporting of cyber and technology risk across CIBC US region.
You will collaborate closely with information security, technology, and risk partners to ensure a consistent, integrated approach to risk management. At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 3 days per week on-site, while other days will be remote.
You’ll Succeed
- Risk Management & Portfolio Oversight - Review operational practices, risk assessments, controls, deficiencies, metrics, and other relevant information to form an independent view of cyber risks and perform effective challenges. Apply a risk-based approach to assess and manage risks related to information/cyber security, ensuring alignment with operational risk management policies, the CIBC risk appetite, and specific risk tolerances. Conduct independent assessments of business lines and initiatives, such as projects, risk and control self-assessments, and incidents, using established operational risk tools and processes.
Leverage strong data and analytical skills to conduct detailed research, generate actionable risk insights, and document findings for distribution to various internal audiences. Prepare high-quality, impactful risk reporting and portfolio-level insights for senior operational risk management leadership and committees. - Technical & Analytical Expertise - Bring credibility and influence by leveraging your broad technology experience and deep risk expertise in areas such as cloud, network, cybersecurity, Dev Ops, vulnerability management, and IT service management to assess and challenge risks and controls across technology and business lines. Support risk activities across the team, including incident management, deficiency management, risk reviews, and risk assessments, operating within a matrix team environment, and driving continuous improvement in risk management methodologies.
- Advisory & Continuous Improvement - Maintain a forward-looking, industry-informed view of the technology and cyber risk landscape, staying current with best practices, performance benchmarks, and emerging trends. Provide expert guidance on the management and mitigation of cyber risks and contribute to the continuous enhancement of operational risk management methodologies and practices.
- Collaboration & Relationship Building - Leverage effective communication and people skills to build and sustain trusted internal relationships, positioning yourself as a valued partner who provides sound risk guidance and demonstrates a deep understanding of both the business and technology environments. Collaborate closely with information security, technology, risk, and business partners to ensure a consistent and integrated approach to risk management.
- Risk Culture - Promote a culture of risk awareness and the importance of robust operational and cyber risk management practices. Ensure operational risk policies, processes, and continuous improvement initiatives are effectively communicated.
- A…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).