Principal Technology and Cybersecurity Risk & Controls Specialist

Posted 3 Days Ago
Be an Early Applicant
Buffalo, NY, USA
In-Office
124K-206K Annually
Senior level
Fintech
The Role
Leads independent technology, cybersecurity, and data control testing, including control design and operating effectiveness assessments, remediation validation, risk-based testing plans, regulatory engagement support, issue evaluation, training, and management reporting. Partners with risk and control owners to challenge risk assessments, control coverage, testing scope, and remediation effectiveness. Serves as a subject matter expert and may present findings to regulators.
Summary Generated by Built In

This role offers a hybrid work schedule; offering the flexibility to work remotely one day a week, while providing the opportunity for in-person collaboration.  Sponsorship is NOT available for this position.

Overview:     

Executes and manages independent control testing and remediation plan closure validation activities across Technology, Cybersecurity, and Data domains. Influences risk management outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and control design adequacy. Provides subject matter expertise for complex testing and validation activities, reviews the work of peers, supports development and maintenance of the annual testing plan, and prepares management reporting to enable effective risk-based decision making.

Primary Responsibilities:

  • Maintain the Controls Testing methodology, procedures, standards, and quality assurance practices to ensure testing activities are executed consistently and in accordance with internal policies and requirements.

  • Lead the development, execution, and management of the Annual Controls Testing Plan utilizing risk-based principles, inherent risk assessments, regulatory expectations, emerging risks, and organizational priorities to ensure appropriate testing coverage across Technology, Cybersecurity, and Data risk domains.

  • Direct and execute independent assessments of control design and operating effectiveness to determine whether controls are appropriately designed and operating effectively to mitigate identified risks and maintain residual risk within approved risk appetite.

  • Provide effective challenge to Risk Advisors, Risk Owners, Control Owners, and Process Owners regarding risk identification, risk-to-control mappings, control coverage, control rationalization, testing scope, and control design adequacy.

  • Lead complex controls testing engagements and issue evaluations involving high-risk technologies, cybersecurity processes, data management capabilities, regulatory commitments, and strategic initiatives.

  • Evaluate the sustainability and effectiveness of remediation activities to independently confirm whether corrective actions effectively address identified root causes, design deficiencies, operating effectiveness failures, audit findings, regulatory issues, and self-identified issues.

  • Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.

  • Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).

  • Prepare and deliver management reporting on testing results, thematic observations, control environment maturity, remediation status, and emerging risk trends.

  • Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite.  Identify risk-related issues needing escalation to management.

  • Promote an environment that supports diversity and reflects the M&T Bank brand.

  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.

  • Complete other related duties as assigned.

Scope of Responsibilities:

  • This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs. 

  • Work is accomplished with periodic direction.  The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert. 

  • Apply professional judgment in determining testing strategies, sample selection approaches, issue severity assessments, remediation validation requirements, and conclusions regarding control effectiveness and risk mitigation.

  • Review and challenges complex risk assessments to provide an independent opinion on the completeness of risk identification, appropriateness of control selection, and adequacy of control design

  • Serves as a recognized subject matter expert for controls testing methodology, control design assessment, operating effectiveness testing, issue validation, remediation validation, and risk-based assurance practices.

  • This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.

Education and Experience Required:

  • Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience

  • Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles

  • Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit

  • Previous experience of NIST (National Institute of Standards and Technology) or Cybersecurity frameworks, with a strong focus NIST 800-53 and 800-53a

  • Strong knowledge of cybersecurity principles and industry best practices (relevant to confidentiality, integrity, availability)

  • Proven knowledge of information technology security principles and implementation methods (e.g., firewalls, demilitarized zones, encryption, Active Directory / LDAP, SAML)

  • Skilled in evaluating security controls based on confidentiality, integrity and availability requirements of systems

  • Experience with handling multiple projects

  • Experience meeting strict deadlines

  • Experience overseeing project tasks for less experienced team members

Education and Experience Preferred:

  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field

  • Active CISA (Certified Information Systems Auditor), CAP (Certified Authorization Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control) certification or Cybersecurity domain-related industry-recognized certification

  • Working knowledge of the current version of the NIST SP800-53 and 800-53a Controls, or other recognized control frameworks, such as COBIT (Control Objectives for Information and Related Technology) or ISO

  • Knowledge of organization's risk tolerance and/or risk management approach

  • Working knowledge of project management methodology

  • Strong and proven knowledge of security technologies and architecture, including encryption, cloud network security design, role-based access control, perimeter security and application security

  • Knowledge of Cybersecurity threats and emerging security issues

  • Experienced in conducting security control testing of systems

  • IT Audit and/or First Line Control testing experience

#LI-JB3

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $123,600.00 - $206,000.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

LocationBuffalo, New York, United States of America

Skills Required

  • Bachelor's degree and at least 7 years of relevant work experience, or 11 years of combined higher education and work experience
  • Expert knowledge of technology and/or cybersecurity risk principles
  • At least 6 years of relevant experience in technology, cybersecurity risk, or the applicable business unit
  • Experience with NIST or cybersecurity frameworks, especially NIST SP 800-53 and 800-53A
  • Strong knowledge of cybersecurity principles and confidentiality, integrity, and availability practices
  • Knowledge of information technology security principles and implementation methods, including firewalls, demilitarized zones, encryption, Active Directory or LDAP, and SAML
  • Ability to evaluate security controls against system confidentiality, integrity, and availability requirements
  • Experience handling multiple projects
  • Experience meeting strict deadlines
  • Experience overseeing project tasks for less experienced team members
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or a related field
  • Active CISA, CAP, CISSP, CISM, CRISC, or another recognized cybersecurity certification
  • Working knowledge of NIST SP 800-53 and 800-53A or other control frameworks such as COBIT or ISO
  • Knowledge of organizational risk tolerance or risk management approaches
  • Working knowledge of project management methodology
  • Strong knowledge of security technologies and architecture, including encryption, cloud network security, role-based access control, perimeter security, and application security
  • Knowledge of cybersecurity threats and emerging security issues
  • Experience conducting security control testing of systems
  • IT audit and/or first-line control testing experience

M&T Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about M&T Bank and has not been reviewed or approved by M&T Bank.

  • Retirement Support Retirement benefits are positioned as a strong pillar, including a 401(k) match and the possibility of an additional employer contribution, plus access to an employee stock purchase plan.
  • Leave & Time Off Breadth Time-off offerings are framed as competitive, with a flexible PTO approach and paid volunteer time called out as a meaningful add-on to standard leave.
  • Wellbeing & Lifestyle Benefits Wellbeing support appears comparatively robust, highlighted by mental-health therapy/coaching sessions and broader wellness programming alongside community-oriented perks.

M&T Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Buffalo, NY
21,590 Employees
Year Founded: 1856

What We Do

M&T Bank is a multi-state community-focused bank serving New York, Maryland, New Jersey, Pennsylvania, Delaware, Connecticut, Virginia, West Virginia and Washington, D.C. Founded in 1856, the company provides banking, investment, insurance and mortgage financial services to more than 3.6 million consumer, business and government clients.

Similar Jobs

EliseAI Logo EliseAI

Recruiting Coordinator

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Real Estate
In-Office
New York City, NY, USA
550 Employees
60K-90K Annually

NBCUniversal Logo NBCUniversal

Architect

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
180K-230K Annually

Philo Logo Philo

Ad Partnerships Manager

Cloud • Digital Media • News + Entertainment • On-Demand
Easy Apply
Hybrid
Brooklyn, NY, USA
165 Employees
120K-180K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account