Cybersecurity Regulatory Senior Vice President

BBVA

New York (NY)

On-site

USD 185,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

BBVA is seeking a Cybersecurity Regulatory Engagement Senior Manager within the Information Security function for BBVA Corporate & Investment Banking (CIB) USA. This individual contributor role reports to the Head of Information Security for BBVA CIB USA and coordinates cybersecurity regulatory, audit, and security assurance activities.

You will lead engagements across the U.S., including regulatory examinations, inquiries, remediation, and implementation of evolving regulatory requirements,

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • 7+ years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines.
  • Experience coordinating internal audit engagements where Information Security is in scope, including supporting cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance.

Responsibilities

  • Lead and coordinate cybersecurity regulatory engagements for BBVA CIB USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities, serving as the primary Information Security coordination point.
  • Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to translate evolving regulatory requirements into actionable expectations.
  • Coordinate internal audit engagements involving Information Security, including preparation, evidence collection, walkthroughs, responses, and remediation tracking.
  • Maintain oversight of cybersecurity compliance and control maturity across applicable regulations, supervisory expectations, and industry frameworks.
  • Own and support maintenance of Information Security policies and procedures for BBVA CIB USA, alignment with regulatory requirements, audit expectations, and best practices.
  • Ensure coordination with Group Information Security policies and standards and consistent interpretation within the U.S. CIB environment.
  • Track and manage regulatory and audit findings, management actions, and remediation commitments with control owners.
  • Review the quality and defensibility of regulatory and audit evidence and management responses; identify themes and improvements.
  • Prepare concise management reporting and executive updates on examinations, audit status, control maturity, and remediation progress.

Skills

Regulatory engagement
Cybersecurity
Stakeholder mgmt
Information Security
Audits & Examinations
Regulatory frameworks
Risk management
Communication
Cross-functional
Regulatory reporting

Education

Bachelor's degree

Job description

The Cybersecurity Regulatory Engagement Senior Manager is an individual contributor role within the Information Security function for BBVA Corporate & Investment Banking (CIB) USA. The position reports directly to the Head of Information Security for BBVA CIB USA and serves as a key point of coordination for cybersecurity regulatory, audit, and security assurance activities.

This role is responsible for managing and executing cybersecurity regulatory engagements across the U.S. business, including regulatory examinations, supervisory inquiries, remediation activities, regulatory requests, and the implementation of new or evolving regulatory requirements.

The role also coordinates internal audit engagements where Information Security is in scope and leads or supports cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity.

The successful candidate will bring strong cybersecurity and regulatory judgment, excellent stakeholder-management skills, and the ability to work independently with senior cybersecurity leadership, engineering and control owners, and risk partners in a highly regulated U.S. financial-services environment.

Key Responsibilities
  • Lead and coordinate cybersecurity regulatory engagements for BBVA CIB USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities, serving as the primary Information Security coordination point to ensure responses, evidence, and presentations are accurate, complete, and timely.
  • Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to support regulatory and assurance activities, translating evolving cybersecurity regulatory requirements into actionable expectations for Information Security and control owners.
  • Coordinate internal audit engagements involving Information Security, including preparation, evidence collection, walkthroughs, responses, and remediation tracking, while also supporting regulatory attestations, control assessments, and framework maturity reviews to ensure outcomes are evidence-based and validated.
  • Maintain oversight of cybersecurity compliance and control maturity across applicable regulations, supervisory expectations, and industry frameworks by performing control mapping and gap assessments across regulatory requirements, internal policies, and security controls, and developing regulatory readiness capabilities such as evidence repositories, control mappings, regulatory inventories, and reusable documentation.
  • Own and support the maintenance, periodic review, and enhancement of Information Security policies and procedures for BBVA CIB USA, ensuring alignment with applicable regulatory requirements, audit expectations, and cybersecurity best practices.
  • Ensure coordination and adherence with broader BBVA Group Information Security policies and standards, supporting consistent interpretation, implementation, and execution of Group-wide cybersecurity requirements within the U.S. CIB environment.
  • Track and manage regulatory and audit findings, management actions, and remediation commitments, ensuring timely and sustainable closure, while partnering with control owners to embed regulatory requirements into effective and sustainable cybersecurity controls.
  • Review and challenge the quality and defensibility of regulatory and audit evidence and management responses prior to submission, identify recurring themes across engagements, and recommend improvements to strengthen the cybersecurity control environment.
  • Prepare concise management reporting and executive updates on examinations, audit status, control maturity, and remediation progress, and support interactions with regulators, auditors, and independent assessors, including walkthroughs, interviews, and control demonstrations.
Qualifications and Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • 7+ years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines, preferably within banking or financial services, with demonstrated experience managing or supporting regulatory examinations, supervisory reviews, internal audits, external audits, or independent cybersecurity assessments within a highly regulated environment.
  • Experience coordinating internal audit engagements where Information Security is in scope, including supporting cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity across the following regulations and frameworks:
  • 23 NYCRR Part 500
  • SEC cybersecurity requirements
  • NFA cybersecurity requirements
  • FFIEC Guidelines
  • DORA (Digital Operational Resilience Act)
  • SWIFT Customer Security Controls Framework (CSCF)
  • FedLine security requirements
  • CHIPS-related security requirements
  • NIST Cybersecurity Framework (NIST CSF)
  • CRI Profile
  • Other applicable regulatory and industry control frameworks
  • Strong understanding of the U.S. financial-services regulatory environment and the cybersecurity expectations applicable to banks, broker-dealers, financial institutions, and critical financial infrastructure.
  • Ability to understand and challenge cybersecurity controls across areas such as identity and access management, privileged access, vulnerability management, security monitoring, incident response, network security, data protection, cloud security, third-party security, secure development, and technology resilience.
  • Excellent written and verbal communication skills, with demonstrated ability to prepare regulatory responses, audit materials, executive summaries, management presentations, and concise risk assessments.
  • Strong stakeholder-management skills and demonstrated ability to influence outcomes across Cybersecurity, Engineering, Technology, Risk, Compliance, Legal, Audit, and senior management without direct reporting authority.
  • Ability to manage multiple concurrent regulatory and audit engagements while maintaining strong attention to quality, deadlines, governance, and documentation.
  • Relevant professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent cybersecurity, risk, or audit credentials are preferred.
  • Prior experience within a First Line of Defense cybersecurity or technology organization is strongly preferred, particularly where the role involved interaction with regulators, Internal Audit, Compliance, or independent risk functions.
  • Spanish proficiency is a plus
  • Ability to operate effectively within a global financial institution, in a multinational and multicultural environment, with frequent and continuous interaction with global counterparts across different regions, time zones, and functional areas.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

With respect to this position in our New York Office, the expected base salary ranges from $185,000 to $200,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

*Employment eligibility to work with BBVA in the U.S. is required as the company will not pursue visa sponsorship for these positions

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Regulatory Lead
Cybersecurity Regulatory Lead

Bbva Sa • New York (NY)

Hybrid
USD 185,000 - 200,000
Cybersecurity Regulatory Reporting Engagement Senior Vice President
Cybersecurity Regulatory Reporting Engagement Senior Vice President

BBVA • New York (NY)

On-site
USD 185,000 - 200,000
Cybersecurity Regulatory Engagement Leader
Cybersecurity Regulatory Engagement Leader

BBVA • New York (NY)

On-site
USD 185,000 - 200,000
IAM and Physical Security Senior Vice President
IAM and Physical Security Senior Vice President

BBVA • New York (NY)

On-site
USD 180,000 - 195,000
Generous employee benefits package
Discretionary bonus eligibility
IAM and Physical Security Senior Vice President
IAM and Physical Security Senior Vice President

Bbva Sa • New York (NY)

On-site
USD 185,000 - 200,000
US Cybersecurity Regulatory Engagement Lead
US Cybersecurity Regulatory Engagement Lead

Bbva Sa • New York (NY)

Hybrid
USD 185,000 - 200,000
Corporate Credit Analyst - Associate Lead
Corporate Credit Analyst - Associate Lead

Bbva Sa • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 155,000
Conduct Compliance Associate
Conduct Compliance Associate

BBVA • New York (NY)

On-site
USD 120,000 - 130,000
Generous employee benefits package
Discretionary bonus eligibility
Senior Cybersecurity Regulatory Engagement Lead
Senior Cybersecurity Regulatory Engagement Lead

BBVA • New York (NY)

On-site
USD 185,000 - 200,000
Client Lifecycle Management Associate
Client Lifecycle Management Associate

BBVA • New York (NY)

On-site
USD 102,000 - 125,000
Generous benefits package
Discretionary bonus