Posted:
1/22/2026, 11:14:56 PM
Location(s):
Toronto, Ontario, Canada ⋅ Ontario, Canada
Experience Level(s):
Senior
Field(s):
IT & Security
Workplace Type:
Hybrid
We’re building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what’s right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you'll be doing
As the Director, Configuration & Identity Exposure within the Cyber Threat Exposure Management team, you will play a pivotal role in safeguarding CIBC’s digital landscape. You will lead a specialized function responsible for uncovering, contextualizing, and reducing risks tied to identity, misconfigurations, and entitlement drift—attack paths frequently leveraged by threat actors. This is an opportunity to build and scale a team that continuously discovers exposures, prioritizes them using risk-based methodologies, and drives coordinated remediation across technology domains. Your work will strengthen CIBC’s enterprise cyber threat exposure management program, ensuring risks are measured, governed, and reduced with urgency and precision. This role will initially be an individual contributor until the team is assembled. At point, this role will manages people managers, specialized individual contributors, and work closely with other Directors to collectively oversee the operational aspects of cyber security for CIBC. This specific position is accountable for enterprise-wide Configuration & Identity Exposure management.
At CIBC we enable the work environment most optimal for you to thrive in your role. You’ll have the flexibility to manage your work activities within a hybrid work arrangement where you’ll spend 1-3 days per week on-site, while other days will be remote.
How you'll succeed
Exposure Discovery: Build and operate a proactive exposure-hunting capability focused on identity, configuration, and entitlement-related risks (e.g., privileged access weaknesses, misconfigured cloud roles, legacy IAM systems, MFA gaps).
Risk Analysis & Contextualization: Integrate and analyze signals from multiple platforms (vaulting solutions, identity platforms, identity governance and administration solutions) to produce a consolidated risk view using on-prem and cloud posture management solutions. Apply contextual risk scoring to exposures, factoring in exploitability, business criticality, and compensating controls using tools.
Remediation Leadership: Lead enterprise-wide campaigns targeting high-impact misconfigurations and identity weaknesses. Define scope, timelines, owners, and acceptance criteria for remediation efforts.
Governance & Collaboration: Establish governance routines with IAM, Cloud, Engineering, and Architecture teams to detect drift early and eliminate control regressions. Clarify collaboration boundaries with peer Director roles to ensure exposures are aggregated and prioritized for remediation.
Reporting & Metrics: Develop and maintain executive dashboards showing exposure trends, residual risk, and backlog health. Track and report on remediation progress and campaign outcomes.
Continuous Improvement: Drive ongoing improvement of identity and configuration exposure management practices, contributing to strategy and roadmap development across IAM, cloud security posture, configuration governance, and related domains.
External Benchmarking: Maintain an external network of industry peers to benchmark and inform the evolution of CIBC’s exposure reduction capabilities.
Who you are
#LI-TA
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, defined benefit pension plan*, an employee share purchase plan, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact [email protected]
CIBC is committed to clarity in our hiring process. All roles posted are opportunities we’re actively recruiting for, unless stated otherwise.
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills test (such as simulation, coding, French proficiency).
We use artificial intelligence tools during the recruitment process. Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
Toronto-81 Bay, 19th FloorEmployment Type
RegularWeekly Hours
37.5Skills
Analytical Thinking, Information Management, Information Security, Leadership, Long Term Planning, People Management, Security Risk, Security TrainingsWebsite: https://www.cibc.com/
Headquarter Location: Toronto, Ontario, Canada
Employee Count: 10001+
Year Founded: 1867
IPO Status: Public
Last Funding Type: Post-IPO Debt
Industries: Banking ⋅ Credit Cards ⋅ Financial Services