The Role
Formulates requirements, configures, tests, and enhances centralized cybersecurity control assessment technologies. Develops compliance standards, operational procedures, reporting improvements, escalation processes, and audit documentation. Supports vulnerability assessment teams, vendor relationships, technology stakeholders, budgeting, and regulatory compliance. Provides technical guidance and mentorship to Risk Process team members while monitoring cybersecurity risks and remediation activities.
Summary Generated by Built In
This is a remote position.
PRIMARY RESPONSIBILITIES:
Formulate business requirements that drive implementation or enhancement of technologies to meet centralized control assessment objectives including vulnerability scanning and penetration testing tools, server compliance assessment tools and static code analysis tools.
Configure centralized control assessment technologies.
Develop and document operational procedures for use of centralized control assessment technologies.
Identify, evaluate, and implement process and reporting enhancements within centralized control assessment technologies; provide support to the vulnerability assessment team.
Participate in conversations with centralized assessment technology vendors.
Develop test scripts for implementation or upgrade of centralized assessment technologies and document test results.
Design and document technical compliance standards for Bank systems and infrastructure.
Develop escalation procedures to track and remediate centralized control assessment findings.
Research and train on industry trends surrounding centralized control assessment technologies. Share information with management and the Risk Process team.
Provide input to management during annual budgeting process.
Own relationships with Technology teams that support centralized assessment technologies.
Lead, supervise and mentor less experienced members of the Risk Process Team.
Understand and adhere to the Company's risk and regulatory standards, policies and controls in accordance with the Company's Risk Appetite. Identify risk-related issues needing escalation to management.
Promote an environment that supports diversity and reflects the M&T Bank brand.
Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
Complete other related duties as assigned.
SUPERVISORY/MANAGERIAL RESPONSIBILITIES:
Not Applicable.
EDUCATION AND EXPERIENCE REQUIRED:
Associates degree and a minimum of 7 years relevant work experience, or in lieu of a degree, a combined minimum of 9 years higher education and/or work experience, including a minimum of 7 years relevant work experience.
Prior experience with vulnerability assessment tools.
Strong customer-service orientation.
Excellent written and verbal communication skills.
Prior experience working independently and providing direction to team as needed.
Experience generating, collecting, storing and retaining audit data.
Working knowledge in various scanning solutions and vulnerability risk management platform.
Knowledge on Cybersecurity standards.
Experience in technical writing skills.
EDUCATION AND EXPERIENCE PREFERRED:
Bachelors degree.
CISSP (Certified Information Systems Security Professional), CRISC (Certified Risk and Information Systems Control) certification and/or Cybersecurity domain-related industry-recognized certification.
Proficient technical writing skills.
Detail-oriented.
Prior experience with Incident Response.
Working knowledge on Vulnerability Risk Management lifecycle solutions (ex. Archer VRM).
Working knowledge of eGRC.
Skills Required
- Associates degree and at least 7 years of relevant work experience, or 9 years of combined higher education and work experience including at least 7 relevant years
- Prior experience with vulnerability assessment tools
- Strong customer-service orientation
- Excellent written and verbal communication skills
- Experience working independently and providing direction to a team
- Experience generating, collecting, storing, and retaining audit data
- Working knowledge of scanning solutions and vulnerability risk management platforms
- Knowledge of cybersecurity standards
- Technical writing skills
- Bachelor's degree
- CISSP, CRISC, or another recognized cybersecurity certification
- Proficient technical writing skills
- Detail-oriented work style
- Prior experience with incident response
- Working knowledge of vulnerability risk management lifecycle solutions, such as Archer VRM
- Working knowledge of eGRC
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
CTI Consulting is a South Florida technology solutions and staffing firm founded in 1998. It provides IT staffing and nearshore staffing services for startups through Fortune 100 companies, alongside digital-product work such as designing, testing, deploying, improving, and updating mobile applications. The company emphasizes close client collaboration, comprehensive candidate evaluation, continuing education, and innovative, scalable software solutions that improve operational efficiency.









