This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week
Overview:Responsible for analyzing, documenting, and monitoring compliance with Workforce Identity Access Management policies, procedures, and best practices. Creates new or updates existing processes and governance that ensure resiliency and security of organization..
Primary Responsibilities:- Create policies and processes to assist Cybersecurity with consistently monitoring and securing organization.
- Participate in the development, review, and update of strategies, policies and procedures pertaining to various governance areas.
- Research and analyze industry best practices and regulatory requirements and make recommendations for policy enhancements to improve resiliency and security of organization.
- Maintain and implement systems and processes for monitoring compliance to policies and procedures and identifying data for daily business management.
- Analyze and produce insightful reports with recommendations for Cybersecurity senior leadership.
- Partner with Cybersecurity, Technology, and First Line Risk teams and, at times, business lines to proactively mitigate risk through creation of robust policies and procedures.
- Coordinate responses to audit and regulatory requests, by gathering data and actively participating in documentation reviews for accuracy.
- Collaborate with Cybersecurity teams and managers to create process documentation, reporting, and performance metrics.
- Coordinates various aspects of remediation activities by tracking team completion and drafting key actions, timeline, and communication plan.
- Build relationships among stakeholders in Cybersecurity teams to ensure successful creation and implementation of processes.
- Serve as a resource to Cybersecurity teams and managers to educate and assist with projects.
- Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
- Partners with peers, manager, Cybersecurity team and leadership, First Line Risk team, Internal Audit team, and external auditors
- Determines and develops approach to solutions. Work is evaluated upon completion to ensure objectives have been met. Work is accomplished with periodic check-ins for alignment and limited direction.
- Working knowledge of multiple cybersecurity platforms and applications within function
No supervisory responsibilities.
Education and Experience Required:- Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience inclusive of a minimum 2 years’ work experience in Cybersecurity, Technology, or Risk/Audit
- Demonstrated intermediate knowledge of IAM principles and compliance requirements.
- Experience with Power BI and/or SQL
- Working knowledge of SailPoint, Azure AD, Entra ID, CyberArk, or PAM solutions
- Experience with IAM road mapping, tooling strategy and modernization
- Familiar with cloud identity strategy such as Azure AD, Entra ID, RBAC, conditional access, and privileged role governance
- Working knowledge of multiple cybersecurity platforms and applications within function
- Proficient level of thinking critically and solving problems
- Excellent written and verbal communication skills
- Proven experience collaborating with leaders to execute results.
- Demonstrated intermediate knowledge of technology risk principles and compliance requirements
- Demonstrated ability to translating technical requirements into clear policies and procedures.
Skills Required
- Bachelor's degree and at least 3 years of relevant work experience, or 7 years of combined higher education and work experience including at least 2 years in Cybersecurity, Technology, or Risk/Audit
- Intermediate knowledge of IAM principles and compliance requirements
- Experience with Power BI and/or SQL
- Working knowledge of SailPoint, Azure AD, Entra ID, CyberArk, or PAM solutions
- Experience with IAM road mapping, tooling strategy, and modernization
- Familiarity with cloud identity strategy, Azure AD, Entra ID, RBAC, conditional access, and privileged role governance
- Working knowledge of multiple cybersecurity platforms and applications
- Proficient critical thinking and problem-solving skills
- Excellent written and verbal communication skills
- Proven experience collaborating with leaders to execute results
- Intermediate knowledge of technology risk principles and compliance requirements
- Ability to translate technical requirements into clear policies and procedures
M&T Bank Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about M&T Bank and has not been reviewed or approved by M&T Bank.
-
Retirement Support — Retirement benefits are positioned as a strong pillar, including a 401(k) match and the possibility of an additional employer contribution, plus access to an employee stock purchase plan.
-
Leave & Time Off Breadth — Time-off offerings are framed as competitive, with a flexible PTO approach and paid volunteer time called out as a meaningful add-on to standard leave.
-
Wellbeing & Lifestyle Benefits — Wellbeing support appears comparatively robust, highlighted by mental-health therapy/coaching sessions and broader wellness programming alongside community-oriented perks.
M&T Bank Insights
What We Do
M&T Bank is a multi-state community-focused bank serving New York, Maryland, New Jersey, Pennsylvania, Delaware, Connecticut, Virginia, West Virginia and Washington, D.C. Founded in 1856, the company provides banking, investment, insurance and mortgage financial services to more than 3.6 million consumer, business and government clients.








