CIBC
Consultant, Application Security
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About CIBC
CIBC (Canadian Imperial Bank of Commerce) is a prominent financial institution in Canada, established in 1961 through the merger of the Canadian Bank of Commerce and the Imperial Bank of Canada. With a significant presence in both Canada and the United States, CIBC is dedicated to providing value to its stakeholders and has a history of innovation in banking services. CIBC operates through four main business units: Canadian Personal and Business Banking, Canadian Commercial Banking and Wealth Management, U.S. Commercial Banking and Wealth Management, and Capital Markets. The bank offers a wide range of products, including personal banking services like chequing and savings accounts, loans, and credit cards, as well as business banking solutions and wealth management services. CIBC Bank USA serves American clients with similar offerings, enhancing CIBC's reach in the U.S. market. Additionally, CIBC Mellon, a joint venture with BNY Mellon, provides asset servicing and custody solutions to institutional investors. CIBC is also involved in community initiatives, such as its naming rights to the CIBC Theatre in Chicago, reflecting its commitment to cultural engagement.
Security at CIBC
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“CIBC's AppSec philosophy emphasizes a developer-first approach to strengthen security posture, aiming to reduce friction and foster collaboration between security and development teams.”
Security Team
- The Application Security function is part of the Cyber Security Services Management portfolio at CIBC.
- Mihai Saveschi holds the position of Senior Director, Security Service Management, and is responsible for leading the implementation of enterprise security services.
Key Initiatives
- CIBC adopts a risk-based approach to security.
- Initiatives include integrating automated security tools into CI/CD pipelines, delivering training and awareness sessions to application development teams, and ensuring all employees complete annual mandatory training on privacy and information security.
- They also utilize web browser encryption and monitor activity on digital channels for enhanced security.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.