Senior Technology and Cybersecurity Risk & Controls Specialist

M&T Bank Corporation

Bridgeport (CT)

Hybrid

USD 151,000 - 251,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

M&T Bank is seeking an experienced Controls Testing professional to execute and manage independent testing across Technology, Cybersecurity, and Data domains. You will influence risk outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and design adequacy.

You will lead annual testing plan development, perform complex control design reviews, and prepare management reports to drive risk-based decisions.

Qualifications

  • Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience
  • Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles
  • Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit
  • Experience with NIST (NIST SP800-53 and 800-53a) and related frameworks
  • Strong knowledge of cybersecurity principles and industry best practices
  • Proven knowledge of IT security principles and implementation methods (e.g., firewalls, AD/LDAP, SAML)
  • Skilled in evaluating security controls based on CIA requirements
  • Experience managing multiple projects and meeting deadlines

Responsibilities

  • Maintain the Controls Testing methodology, procedures, standards, and QA practices
  • Lead development and management of Annual Controls Testing Plan
  • Direct and execute independent assessments of control design and operating effectiveness
  • Provide effective challenge to Risk Advisors and Owners on risk identification and control adequacy
  • Lead complex controls testing engagements involving high-risk tech, cybersecurity processes, and data management
  • Evaluate remediation effectiveness and confirm root causes are addressed
  • Contribute to training programs for risk management and skills development
  • Coordinate responses to regulatory engagements and exam management
  • Prepare and deliver management reporting on testing results and risk trends
  • Adhere to risk and regulatory standards and escalate issues as needed
  • Promote diversity and M&T Bank brand
  • Maintain internal control standards and audit point closure
  • Complete other related duties as assigned

Skills

Technology risk principles
Cybersecurity risk principles
NIST 800-53
Security controls testing
Risk management

Education

Bachelor's degree
Master's degree (preferred)

Tools

Active Directory/LDAP
SAML
Firewalls

Job description

This role offers a hybrid work schedule; offering the flexibility to work remotely one day a week, while providing the opportunity for in-person collaboration. Sponsorship is NOT available for this position.

Overview

Executes and manages independent control testing and remediation plan closure validation activities across Technology, Cybersecurity, and Data domains. Influences risk management outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and control design adequacy. Provides subject matter expertise for complex testing and validation activities, reviews the work of peers, supports development and maintenance of the annual testing plan, and prepares management reporting to enable effective risk-based decision making.

Primary Responsibilities
  • Maintain the Controls Testing methodology, procedures, standards, and quality assurance practices to ensure testing activities are executed consistently and in accordance with internal policies and requirements.
  • Lead the development, execution, and management of the Annual Controls Testing Plan utilizing risk-based principles, inherent risk assessments, regulatory expectations, emerging risks, and organizational priorities to ensure appropriate testing coverage across Technology, Cybersecurity, and Data risk domains.
  • Direct and execute independent assessments of control design and operating effectiveness to determine whether controls are appropriately designed and operating effectively to mitigate identified risks and maintain residual risk within approved risk appetite.
  • Provide effective challenge to Risk Advisors, Risk Owners, Control Owners, and Process Owners regarding risk identification, risk-to-control mappings, control coverage, control rationalization, testing scope, and control design adequacy.
  • Lead complex controls testing engagements and issue evaluations involving high-risk technologies, cybersecurity processes, data management capabilities, regulatory commitments, and strategic initiatives.
  • Evaluate the sustainability and effectiveness of remediation activities to independently confirm whether corrective actions effectively address identified root causes, design deficiencies, operating effectiveness failures, audit findings, regulatory issues, and self-identified issues.
  • Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.
  • Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).
  • Prepare and deliver management reporting on testing results, thematic observations, control environment maturity, remediation status, and emerging risk trends.
  • Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite.
  • Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.
Scope of Responsibilities
  • This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs.
  • Work is accomplished with periodic direction.
  • The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results.
  • It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert.
  • Apply professional judgment in determining testing strategies, sample selection approaches, issue severity assessments, remediation validation requirements, and conclusions regarding control effectiveness and risk mitigation.
  • Review and challenges complex risk assessments to provide an independent opinion on the completeness of risk identification, appropriateness of control selection, and adequacy of control design.
  • Serves as a recognized subject matter expert for controls testing methodology, control design assessment, operating effectiveness testing, issue validation, remediation validation, and risk-based assurance practices.
  • This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.
Education and Experience Required
  • Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience
  • Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles
  • Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit
  • Previous experience of NIST (National Institute of Standards and Technology) or Cybersecurity frameworks, with a strong focus NIST 800-53 and 800-53a
  • Strong knowledge of cybersecurity principles and industry best practices (relevant to confidentiality, integrity, availability)
  • Proven knowledge of information technology security principles and implementation methods (e.g., firewalls, demilitarized zones, encryption, Active Directory / LDAP, SAML)
  • Skilled in evaluating security controls based on confidentiality, integrity and availability requirements of systems
  • Experience with handling multiple projects
  • Experience meeting strict deadlines
  • Experience overseeing project tasks for less experienced team members
Education and Experience Preferred
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field
  • Active CISA (Certified Information Systems Auditor), CAP (Certified Authorization Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control) certification or Cybersecurity domain-related industry-recognized certification
  • Working knowledge of the current version of the NIST SP800-53 and 800-53a Controls, or other recognized control frameworks, such as COBIT (Control Objectives for Information and Related Technology) or ISO
  • Knowledge of organization's risk tolerance and/or risk management approach
  • Working knowledge of project management methodologyStrong and proven knowledge of security technologies and architecture, including encryption, cloud network security design, role-based access control, perimeter security and application security
  • Knowledge of Cybersecurity threats and emerging security issues
  • Experienced in conducting security control testing of systems IT Audit and/or First Line Control testing experience

M&T Bank is unwavering when it comes to providing equal employment opportunities to all employees and applicants without regard to race, color, national origin, religion, ethnicity, sex, gender identity, age, disability, citizenship, pregnancy, veteran status, military status, marital status, sexual orientation, genetic information or any other characteristic protected under applicable federal, state or local laws.

Compensation

The pay range for this position is $150,800.00 - $251,300.00 (USD).

Location

Bridgeport, Connecticut, United States of America

About M&T Bank

Great companies have an enduring sense of purpose. At M&T, our purpose is a simple one: make a difference in people’s lives and uplift the communities we serve. M&T Bank Corporation is a financial holding company headquartered in Buffalo, New York. M&T’s affiliates offer advice, guidance, expertise and solutions across the entire financial spectrum, combining M&T Bank’s traditional banking services with the wealth management and institutional capabilities offered by Wilmington Trust. M&T Bank has a network of over 1,000 branches and 2,200 ATMs that span 12 states from Maine to Virginia and Washington, D.C. For more than 165 years, M&T has strived to take an active role in our communities and build long-lasting relationships with our customers. We are a bank for communities—combining the capabilities of a large bank with the care of a locally focused institution. As an employer of choice, we are proud to offer competitive benefits ranging from medical and retirement to forty hours of paid volunteer time, each year. Our core values – integrity, ownership, collaboration, curiosity, and candor – drive the work we do. We seek to further build upon our record of success by bringing in top talent and fresh skill sets while continuing to support the growth and development of all our team members. View M&T’s Human Capital Report to learn more.

M&T Bank Corporation has policies and procedures in place to promote a drug free workplace.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technology and Cybersecurity Risk & Controls Specialist
Senior Technology and Cybersecurity Risk & Controls Specialist

M&T Bank • Bridgeport (CT)

Hybrid
USD 151,000 - 251,000
Sr. Software Engineer - .Net Full Stack
Sr. Software Engineer - .Net Full Stack

M&T Bank Corporation • Buffalo (NY)

On-site
USD 97,000 - 162,000
Technical Engineer III
Technical Engineer III

M&T Bank Corporation • Buffalo (NY)

On-site
USD 97,000 - 162,000
Technical Engineer IV
Technical Engineer IV

M&T Bank Corporation • Buffalo (NY)

On-site
USD 116,000 - 194,000
Business Systems Team Leader
Business Systems Team Leader

M&T Bank Corporation • Village of Williamsville (NY)

On-site
USD 103,000 - 172,000
Medical benefits
Retirement plan
Volunteer time off
Institutional Services Policies & Procedures Lead
Institutional Services Policies & Procedures Lead

M&T Bank Corporation • Wilmington (DE)

On-site
USD 94,000 - 157,000
Head of Tech Governance & Analytics
Head of Tech Governance & Analytics

M&T Bank Corporation • Buffalo (NY)

On-site
USD 168,000 - 279,000
Business Systems Analyst IV
Business Systems Analyst IV

M&T Bank Corporation • Buffalo (NY), Northern (KY)

Hybrid
USD 72,000 - 119,000
Medical benefits
Retirement plan
Volunteer hours
Business Systems Analyst IV
Business Systems Analyst IV

M&T Bank Corporation • Town of Amherst (NY)

On-site
USD 72,000 - 119,000
Technical Engineer - ATM Technology Platforms
Technical Engineer - ATM Technology Platforms

M&T Bank Corporation • Buffalo (NY)

On-site
USD 97,000 - 162,000