Cybersecurity Regulatory Lead

Posted 3 Days Ago
Be an Early Applicant
New York, NY, USA
In-Office
185K-200K Annually
Senior level
Fintech • Information Technology • Financial Services
The Role
Lead and coordinate cybersecurity regulatory engagements and internal audit activities for BBVA CIB USA. Manage examinations, supervisory inquiries, remediation tracking, control assessments, attestations, and regulatory readiness. Partner with Cybersecurity, Technology, Risk, Compliance, Legal, and Audit to translate regulatory requirements into actionable controls, maintain evidence repositories, and produce executive reporting on control maturity and remediation progress.
Summary Generated by Built In
Excited to grow your career?

BBVA is a global company with more than 160 years of history that operates in more than 25 countries where we serve more than 80 million customers. We are more than 121,000 professionals working in multidisciplinary teams with profiles as diverse as financiers, legal experts, data scientists, developers, engineers and designers.

About the job:

The Cybersecurity Regulatory Engagement Senior Manager is an individual contributor role within the Information Security function for BBVA Corporate & Investment Banking (CIB) USA. The position reports directly to the Head of Information Security for BBVA CIB USA and serves as a key point of coordination for cybersecurity regulatory, audit, and security assurance activities.

This role is responsible for managing and executing cybersecurity regulatory engagements across the U.S. business, including regulatory examinations, supervisory inquiries, remediation activities, regulatory requests, and the implementation of new or evolving regulatory requirements.

The role also coordinates internal audit engagements where Information Security is in scope and leads or supports cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity.

The successful candidate will bring strong cybersecurity and regulatory judgment, excellent stakeholder-management skills, and the ability to work independently with senior cybersecurity leadership, engineering and control owners, and risk partners in a highly regulated U.S. financial-services environment.

Key Responsibilities

  • Lead and coordinate cybersecurity regulatory engagements for BBVA CIB USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities, serving as the primary Information Security coordination point to ensure responses, evidence, and presentations are accurate, complete, and timely.

  • Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to support regulatory and assurance activities, translating evolving cybersecurity regulatory requirements into actionable expectations for Information Security and control owners.

  • Coordinate internal audit engagements involving Information Security, including preparation, evidence collection, walkthroughs, responses, and remediation tracking, while also supporting regulatory attestations, control assessments, and framework maturity reviews to ensure outcomes are evidence-based and validated.

  • Maintain oversight of cybersecurity compliance and control maturity across applicable regulations, supervisory expectations, and industry frameworks by performing control mapping and gap assessments across regulatory requirements, internal policies, and security controls, and developing regulatory readiness capabilities such as evidence repositories, control mappings, regulatory inventories, and reusable documentation.

  • Own and support the maintenance, periodic review, and enhancement of Information Security policies and procedures for BBVA CIB USA, ensuring alignment with applicable regulatory requirements, audit expectations, and cybersecurity best practices.

  • Ensure coordination and adherence with broader BBVA Group Information Security policies and standards, supporting consistent interpretation, implementation, and execution of Group-wide cybersecurity requirements within the U.S. CIB environment.

  • Track and manage regulatory and audit findings, management actions, and remediation commitments, ensuring timely and sustainable closure, while partnering with control owners to embed regulatory requirements into effective and sustainable cybersecurity controls.

  • Review and challenge the quality and defensibility of regulatory and audit evidence and management responses prior to submission, identify recurring themes across engagements, and recommend improvements to strengthen the cybersecurity control environment.

  • Prepare concise management reporting and executive updates on examinations, audit status, control maturity, and remediation progress, and support interactions with regulators, auditors, and independent assessors, including walkthroughs, interviews, and control demonstrations.

Qualifications and Experience

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.

  • 7+ years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines, preferably within banking or financial services, with demonstrated experience managing or supporting regulatory examinations, supervisory reviews, internal audits, external audits, or independent cybersecurity assessments within a highly regulated environment.

  • Experience coordinating internal audit engagements where Information Security is in scope, including supporting cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity across the following regulations and frameworks:

  • 23 NYCRR Part 500

  • SEC cybersecurity requirements

  • NFA cybersecurity requirements

  • FFIEC Guidelines

  • DORA (Digital Operational Resilience Act)

  • SWIFT Customer Security Controls Framework (CSCF)

  • FedLine security requirements

  • CHIPS-related security requirements

  • NIST Cybersecurity Framework (NIST CSF)

  • CRI Profile

  • Other applicable regulatory and industry control frameworks

  • Strong understanding of the U.S. financial-services regulatory environment and the cybersecurity expectations applicable to banks, broker-dealers, financial institutions, and critical financial infrastructure.

  • Ability to understand and challenge cybersecurity controls across areas such as identity and access management, privileged access, vulnerability management, security monitoring, incident response, network security, data protection, cloud security, third-party security, secure development, and technology resilience.

  • Excellent written and verbal communication skills, with demonstrated ability to prepare regulatory responses, audit materials, executive summaries, management presentations, and concise risk assessments.

  • Strong stakeholder-management skills and demonstrated ability to influence outcomes across Cybersecurity, Engineering, Technology, Risk, Compliance, Legal, Audit, and senior management without direct reporting authority.

  • Ability to manage multiple concurrent regulatory and audit engagements while maintaining strong attention to quality, deadlines, governance, and documentation.

  • Relevant professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent cybersecurity, risk, or audit credentials are preferred.

  • Prior experience within a First Line of Defense cybersecurity or technology organization is strongly preferred, particularly where the role involved interaction with regulators, Internal Audit, Compliance, or independent risk functions.

  • Spanish proficiency is a plus

  • Ability to operate effectively within a global financial institution, in a multinational and multicultural environment, with frequent and continuous interaction with global counterparts across different regions, time zones, and functional areas.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

With respect to this position in our New York Office, the expected base salary ranges from $185,000 to $200,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

*Employment eligibility to work with BBVA in the U.S. is required as the company will not pursue visa sponsorship for these positions

Legal requirements

It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

Pay Transparency Policy Statement

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information (41 C.F.R. 60-1.35 (c)).

Individuals with Disabilities

BBVA USA, BBVA Securities Inc., and BBVA S.A. New York Branch invite all interested and qualified applicants to apply for employment opportunities. If you are a U.S.-based job seeker with a disability who is unable to use our online tools to search and apply for jobs, please contact us by emailing: [email protected] or by calling toll-free (in the U.S.) 1-844-664-9275. Please indicate the specific type of assistance needed*.

*The disability access telephone line and email address are reserved solely for job seekers with disabilities requesting accessibility assistance or an accommodation. Please do not call about the status of your job application if you do not require accessibility assistance or an accommodation. Messages left for other purposes, such as following up on an application or non-disability related or technical issues, will not receive a response.

EEO Statement

BBVA USA, BBVA Securities Inc., and BBVA S.A. New York Branch have a firm and unwavering policy to provide equal employment opportunity without regard to age, citizenship, color, disability, ethnic origin, gender, gender identity and expression, marital status, nationality, national origin, race, religion, sexual orientation, genetic predisposition, protected veteran status, or any other status or classification protected by federal, state or local law. This policy includes all job groups, classifications and organizational units. With regard to employment, this policy extends to applicants and covers our recruiting, hiring, promotion, transfer, demotion, discipline, termination, benefits, compensation and training practices as well as social and recreational activities.

View the "EEO is the Law" & "View the EEO is the Law Supplement Poster" poster. BBVA USA, BBVA Securities, Inc., and BBVA NY are equal opportunity and affirmative action employer.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or related field.
  • 7+ years progressive experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, or related disciplines.
  • Experience managing or supporting regulatory examinations, supervisory reviews, internal/external audits, or independent cybersecurity assessments in a regulated environment.
  • Experience coordinating internal audit engagements where Information Security is in scope, including cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance.
  • Knowledge and hands-on experience with regulatory frameworks and standards: 23 NYCRR Part 500, SEC cybersecurity requirements, NFA requirements, FFIEC, DORA, SWIFT CSCF, FedLine, CHIPS, NIST CSF, CRI Profile.
  • Strong understanding of the U.S. financial-services regulatory environment and cybersecurity expectations for banks, broker-dealers, financial institutions, and critical financial infrastructure.
  • Ability to evaluate and challenge cybersecurity controls across identity and access management, privileged access, vulnerability management, security monitoring, incident response, network security, data protection, cloud security, third-party security, secure development, and technology resilience.
  • Excellent written and verbal communication skills, including preparing regulatory responses, audit materials, executive summaries, and management presentations.
  • Strong stakeholder-management skills with ability to influence across Cybersecurity, Engineering, Technology, Risk, Compliance, Legal, Audit, and senior management without direct authority.
  • Ability to manage multiple concurrent regulatory and audit engagements with strong attention to quality, deadlines, governance, and documentation.
  • Relevant professional certifications such as CISSP, CISM, CRISC, or CISA.
  • Prior experience within a First Line of Defense cybersecurity or technology organization.
  • Spanish proficiency.
  • Ability to operate effectively within a global financial institution and interact continuously with global counterparts across regions and time zones.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bilbao, Vizcaya
87,534 Employees
Year Founded: 1857

What We Do

At BBVA we are leading the transformation of banking worldwide, united in pursuing our goal of bringing the age of opportunity to everyone. Firmly focused on the future, our on-going digital transformation is already producing disruptive innovations that power our vision of banking. Every one of our 112,465 employees, from branch staff to senior leaders, plays an essential role in giving our 85 million customers the cutting edge banking solutions that they deserve. Building on 165 years of history we know the importance of constant development, which is why we place so much confidence in the collaborative working environment that enables our people to grow and excel. If you would like to learn about the culture and opportunities on offer at a company that is leading the way for 21st century banking, head to the ‘Life’ tab to find out more.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
9 Locations
40000 Employees
45K-85K Annually
Hybrid
Pomona, NY, USA
205000 Employees
38K-67K Hourly

Wells Fargo Logo Wells Fargo

Personal Banker Holbrook DeNovo

Fintech • Financial Services
Hybrid
Holbrook, NY, USA
205000 Employees
23-31 Hourly
Hybrid
Monsey, NY, USA
205000 Employees
38K-67K Hourly

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account