Principal First Line Risk Specialist - Cybersecurity and AI Initiatives

Posted 6 Days Ago
Be an Early Applicant
Buffalo, NY, USA
In-Office
148K-247K Annually
Expert/Leader
Fintech
The Role
Leads cybersecurity and AI risk governance initiatives, developing risk frameworks, controls, standards, and mitigation strategies for emerging technologies. Advises engineering, architecture, security, and executive stakeholders, including the CISO, on control effectiveness and regulatory expectations. Supports audits, regulatory examinations, risk assessments, and remediation efforts while monitoring evolving threats and technology risks. Operates independently as a subject matter expert and represents the organization in governance and regulatory activities.
Summary Generated by Built In

This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week

Overview:     

Leads risk analysis and governance activities for emerging Cybersecurity and Artificial Intelligence (AI) initiatives, influencing the design of risk frameworks, controls, and standards that support evolving technologies. Provides expert guidance to senior leadership, engineering, and architecture teams to proactively identify, assess, and mitigate technology risks while ensuring alignment with regulatory expectations and organizational objectives.


Primary Responsibilities:
  • Develop and implement risk frameworks, controls, and standards supporting Cybersecurity and AI engineering capabilities, ensuring comprehensive coverage of emerging technologies.
  • Act as a first line of risk advisor to engineering, architecture, and security teams, proactively identifying risks, control gaps, and opportunities to strengthen governance.
  • Lead the assessment of emerging technology trends, regulatory guidance, and industry developments to ensure organizational readiness and compliance.
  • Design, enhance, and implement risk management processes, procedures, and standards that support new and evolving Cybersecurity and AI initiatives.
  • Partner directly with the Chief Information Security Officer (CISO), senior technology leaders, engineers, and architects to evaluate strategic initiatives and provide risk-informed recommendations.
  • Drive the identification, development, and implementation of new controls to address emerging risks and strengthen the organization's risk posture.
  • Lead and support audit activities, regulatory examinations, and risk assessments, ensuring timely remediation of findings and sustainable control improvements.
  • Collaborate across Technology, Cybersecurity, AI, Enterprise Risk, Internal Audit, and Regulatory Affairs functions to align practices with business objectives and regulatory expectations.
  • Monitor and assess evolving threat landscapes and emerging technology risks, integrating advanced risk management methodologies to address changing business and regulatory requirements.
  • Prepare and present complex risk assessments, control evaluations, and recommendations to senior leadership and executive stakeholders.
  • Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Identify risk-related issues requiring escalation to management.
  • Promote an environment that supports belonging and reflects the Company's values and culture.
  • Maintain internal control standards, including timely implementation of internal and external audit recommendations together with any issues raised by regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:
  • This position works closely with the CISO, senior engineering and architecture leaders, Cybersecurity leadership, Technology and Cybersecurity Risk leadership, Enterprise Risk, Internal Audit, Regulatory Affairs, and other senior stakeholders across the organization.
  • Serves as a key risk partner for Cybersecurity and AI engineering initiatives, applying significant judgment and expertise to identify emerging risks, evaluate control effectiveness, and recommend strategic solutions.
  • Exercises substantial independence in determining approaches to risk management, control design, and governance activities for emerging technologies, while collaborating with executive stakeholders on critical decisions.
  • May represent the organization during regulatory examinations, audits, and governance reviews related to Cybersecurity, AI, and emerging technology risk management.
  • Functions as a subject matter expert on Cybersecurity and AI risk, advising leadership on industry trends, regulatory developments, control design, and risk mitigation strategies.

Supervisory/Managerial Responsibilities:

No supervisory responsibilities.


Education and Experience Required:
  • Bachelor's degree and a minimum of 9 years’ relevant work experience, or in lieu of a degree, a combined minimum of 13 years’ higher education and/or work experience
  • Demonstrated expert knowledge of Technology and Cybersecurity risk principles
  • Minimum of 8 years' relevant work experience in and/or with the specific risk area and/or business unit

Education and Experience Preferred:
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field
  • Applicable certification align to function or domain such as Certified in Risk and Information Systems Control (CRISC®), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP)
  • Experience supporting Cybersecurity, AI, and emerging technology initiatives, including risk assessments, governance, and control design.
  • Proven ability to identify control gaps, develop new controls, and implement risk mitigation strategies within a first line of risk environment.
  • Experience developing processes, procedures, standards, and risk frameworks that support cybersecurity programs, AI adoption, and evolving technology capabilities.
  • Strong understanding of emerging technology trends, cybersecurity risks, and regulatory guidance related to AI and information security.
  • Experience partnering directly with senior leaders, engineering and architecture teams, and executive stakeholders, including the CISO, to provide risk-informed recommendations and influence strategic decision-making.
  • Experience supporting audits, regulatory examinations, and control reviews, with a demonstrated ability to proactively identify risks, drive remediation efforts, and communicate effectively with both technical and business audiences.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $148,300.00 - $247,100.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

LocationBuffalo, New York, United States of America

Skills Required

  • Bachelor's degree and at least 9 years of relevant work experience, or 13 years of combined higher education and work experience
  • Expert knowledge of technology and cybersecurity risk principles
  • At least 8 years of relevant experience in the specific risk area or business unit
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or a related field
  • Relevant certification such as CRISC, CISA, CISM, or CISSP
  • Experience supporting cybersecurity, AI, and emerging technology initiatives, including risk assessments, governance, and control design
  • Experience identifying control gaps, developing controls, and implementing risk mitigation strategies in a first-line risk environment
  • Experience developing processes, procedures, standards, and risk frameworks for cybersecurity programs, AI adoption, and evolving technology capabilities
  • Strong understanding of emerging technology trends, cybersecurity risks, and regulatory guidance related to AI and information security
  • Experience partnering with senior leaders, engineering and architecture teams, and executive stakeholders, including the CISO
  • Experience supporting audits, regulatory examinations, and control reviews, including risk identification and remediation

M&T Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about M&T Bank and has not been reviewed or approved by M&T Bank.

  • Retirement Support — Retirement benefits are positioned as a strong pillar, including a 401(k) match and the possibility of an additional employer contribution, plus access to an employee stock purchase plan.
  • Leave & Time Off Breadth — Time-off offerings are framed as competitive, with a flexible PTO approach and paid volunteer time called out as a meaningful add-on to standard leave.
  • Wellbeing & Lifestyle Benefits — Wellbeing support appears comparatively robust, highlighted by mental-health therapy/coaching sessions and broader wellness programming alongside community-oriented perks.

M&T Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Buffalo, NY
21,590 Employees
Year Founded: 1856

What We Do

M&T Bank is a multi-state community-focused bank serving New York, Maryland, New Jersey, Pennsylvania, Delaware, Connecticut, Virginia, West Virginia and Washington, D.C. Founded in 1856, the company provides banking, investment, insurance and mortgage financial services to more than 3.6 million consumer, business and government clients.

Similar Jobs

Airwallex Logo Airwallex

Solutions Engineer

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Hybrid
New York, NY, USA
2300 Employees

Marble Health Logo Marble Health

Account Executive

Healthtech • Kids + Family • Social Impact • Software • Telehealth • Conversational AI
Hybrid
New York City, NY, USA
35 Employees
185K-205K Annually

MetLife Logo MetLife

Director - Internal Communications, US Business

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
43000 Employees
129K-172K Annually

MetLife Logo MetLife

Manager, Marketing Review Process Lead

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
93K-115K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account