×
Register Here to Apply for Jobs or Post Jobs. X

Managing Director - Insider Threat Program

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: BMO
Full Time position
Listed on 2026-07-17
Job specializations:
  • IT/Tech
    Cybersecurity, Data Security, Information Security, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 225000 - 300000 USD Yearly USD 225000.00 300000.00 YEAR
Job Description & How to Apply Below

Leads the Bank’s enterprise insider threat program, defining strategy, governance, and operating model to proactively identify, assess, mitigate, and prevent insider-driven risk. Establishes a risk-based approach to insider threat, strengthening the Bank’s ability to anticipate emerging threats, close control gaps, and enhance operational resilience. Maintains a forward-looking view of emerging insider risks, including employee-enabled fraud, credential misuse, data exfiltration, collusion, third-party insider risk, and cyber-enabled activity.

The insider threat program is a centralized program requiring strict governance and confidentiality, with only involving stakeholders on a need-to-know basis in a controlled escalation environment.

Strategy & Operating Model
  • Defines and leads the enterprise insider threat strategy and long-term roadmap.

  • Builds a consistent global framework aligned to regulatory, legal, privacy and labor requirements; regulatory first design.

  • Establishes governance structures, escalation protocols, and decision-making forums.

  • Matures capabilities from reactive investigations to proactive, intelligence-led prevention.

Cross-Functional Leadership & Integration
  • Partners across Cybersecurity, Fraud, Financial Crimes, Corporate Security, Operations, Legal, Global Investigations, Risk, Privacy, and Human Resources.

  • Integrates insider threat capabilities across systems, platforms, and control environments.

  • Establishes clear routines for collaboration, escalation, and coordinated response.

  • Promotes a culture of proactive risk identification and responsible escalation.

Data, Analytics & Intelligence
  • Develops and optimizes insider threat analytics (i.e., user and entity behavior analytics), tools, and capabilities to support scalable, intelligence-driven risk detection.

  • Builds a consolidated insider threat intelligence capability integrating cyber, fraud, financial crime, HR, and investigative signals (data fusion).

  • Delivers executive-level reporting and insights on insider threat posture, emerging risks, significant cases, control effectiveness, and remediation progress.

  • Leverages data, analytics, and risk indicators to inform strategy, prioritization, and investment decisions.

Detection, Investigation & Response
  • Owns the end-to-end insider threat control framework, including prevention rules, risk-based detection models, behavioral analytics, investigative protocols, case management standards, and escalation processes.

  • Embeds privacy-by-design and ethical monitoring practices, ensuring transparency, proportionality, and protection of employee dignity.

  • Develops and enhances intelligence-led detection capabilities and response frameworks to enable proactive risk identification and mitigation.

  • Partners with Global Investigations to ensure that consistent triage, investigation, escalation, and resolution related to Insider threat occurs across the enterprise.

  • Defines standards for response actions ensuring timeliness, proportionality, governance, and defensibility.

  • Participates in complex, high-risk investigations involving employees, contractors, third parties, cyber events, fraud activity, and control breaches, as required partnering with the Global Investigations team.

Governance, Risk & Regulatory Oversight
  • Identifies systemic control gaps and drives remediation across identity and access management, privileged access, data protection, fraud controls, vendor access, and critical operations.

  • Oversees adherence to the Bank’s Risk Appetite Framework, ensuring insider threat risks are managed within defined tolerances.

  • Defines and manages key risk indicators (KRIs), key performance indicators (KPIs), and insider threat risk appetite.

  • Supports regulatory exams, audits, and governance reviews, ensuring readiness and effective response across cyber risk, fraud, conduct risk, and operational resilience.

Leadership & Culture
  • Within the mandate of this role, promotes and supports the Bank’s risk culture including ensuring employees understand their accountabilities for risk-taking activities, promoting an environment of open communication and effective challenge, and establishing the “tone from the top” through…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary