M&T Bank Corporation

Principal Technology and Cybersecurity Risk & Controls Specialist

M&T Bank Corporation$123K — $206K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 7+ years of relevant experience or equivalent combination of education and experience.
  • Expert knowledge of Technology and Cybersecurity risk principles.
  • 6+ years of practical work experience in Technology or Cybersecurity risk management.
  • Familiarity with NIST frameworks, especially NIST 800-53 and 800-53a.
  • Strong grasp of cybersecurity principles and industry best practices.

Responsibilities

  • Maintain and enhance the Controls Testing methodology and quality assurance practices.
  • Develop and manage the Annual Controls Testing Plan based on risk assessments and organizational priorities.
  • Conduct independent assessments of control design and effectiveness regarding risk mitigation.
  • Challenge stakeholders on risk identification and control adequacy to ensure comprehensive coverage.
  • Lead testing engagements involving high-risk technologies and regulatory commitments.
  • Validate the effectiveness of remediation activities addressing identified issues and deficiencies.
  • Prepare management reporting on testing results and risk trends.

Benefits

  • Flexible hybrid work schedule with remote work opportunities.
  • Supportive environment promoting diversity and inclusion.
  • Professional development through training program contributions.
  • Collaborative work with senior leaders and cross-functional teams.
Full Job Description
This role offers a hybrid work schedule; offering the flexibility to work remotely one day a week, while providing the opportunity for in-person collaboration. Sponsorship is NOT available for this position.

Overview:

Executes and manages independent control testing and remediation plan closure validation activities across Technology, Cybersecurity, and Data domains. Influences risk management outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and control design adequacy. Provides subject matter expertise for complex testing and validation activities, reviews the work of peers, supports development and maintenance of the annual testing plan, and prepares management reporting to enable effective risk-based decision making.

Primary Responsibilities:
  • Maintain the Controls Testing methodology, procedures, standards, and quality assurance practices to ensure testing activities are executed consistently and in accordance with internal policies and requirements.
  • Lead the development, execution, and management of the Annual Controls Testing Plan utilizing risk-based principles, inherent risk assessments, regulatory expectations, emerging risks, and organizational priorities to ensure appropriate testing coverage across Technology, Cybersecurity, and Data risk domains.
  • Direct and execute independent assessments of control design and operating effectiveness to determine whether controls are appropriately designed and operating effectively to mitigate identified risks and maintain residual risk within approved risk appetite.
  • Provide effective challenge to Risk Advisors, Risk Owners, Control Owners, and Process Owners regarding risk identification, risk-to-control mappings, control coverage, control rationalization, testing scope, and control design adequacy.
  • Lead complex controls testing engagements and issue evaluations involving high-risk technologies, cybersecurity processes, data management capabilities, regulatory commitments, and strategic initiatives.
  • Evaluate the sustainability and effectiveness of remediation activities to independently confirm whether corrective actions effectively address identified root causes, design deficiencies, operating effectiveness failures, audit findings, regulatory issues, and self-identified issues.
  • Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.
  • Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).
  • Prepare and deliver management reporting on testing results, thematic observations, control environment maturity, remediation status, and emerging risk trends.
  • Understand and adhere to the Company's risk and regulatory standards, policies and controls in accordance with the Company's Risk Appetite. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.


Scope of Responsibilities:
  • This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs.
  • Work is accomplished with periodic direction. The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert.
  • Apply professional judgment in determining testing strategies, sample selection approaches, issue severity assessments, remediation validation requirements, and conclusions regarding control effectiveness and risk mitigation.
  • Review and challenges complex risk assessments to provide an independent opinion on the completeness of risk identification, appropriateness of control selection, and adequacy of control design
  • Serves as a recognized subject matter expert for controls testing methodology, control design assessment, operating effectiveness testing, issue validation, remediation validation, and risk-based assurance practices.
  • This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.


Education and Experience Required:
  • Bachelor's degree and a minimum of 7 years' relevant work experience, or in lieu of a degree, a combined minimum of 11 years' higher education and/or work experience
  • Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles
  • Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit
  • Previous experience of NIST (National Institute of Standards and Technology) or Cybersecurity frameworks, with a strong focus NIST 800-53 and 800-53a
  • Strong knowledge of cybersecurity principles and industry best practices (relevant to confidentiality, integrity, availability)
  • Proven knowledge of information technology security principles and implementation methods (e.g., firewalls, demilitarized zones, encryption, Active Directory / LDAP, SAML)
  • Skilled in evaluating security controls based on confidentiality, integrity and availability requirements of systems
  • Experience with handling multiple projects
  • Experience meeting strict deadlines
  • Experience overseeing project tasks for less experienced team members


Education and Experience Preferred:
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field
  • Active CISA (Certified Information Systems Auditor), CAP (Certified Authorization Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control) certification or Cybersecurity domain-related industry-recognized certification
  • Working knowledge of the current version of the NIST SP800-53 and 800-53a Controls, or other recognized control frameworks, such as COBIT (Control Objectives for Information and Related Technology) or ISO
  • Knowledge of organization's risk tolerance and/or risk management approach
  • Working knowledge of project management methodology
  • Strong and proven knowledge of security technologies and architecture, including encryption, cloud network security design, role-based access control, perimeter security and application security
  • Knowledge of Cybersecurity threats and emerging security issues
  • Experienced in conducting security control testing of systems
  • IT Audit and/or First Line Control testing experience


#LI-JB3

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $123,600.00 - $206,000.00 Annual (USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.

Location
Buffalo, New York, United States of America

About M&T Bank Corporation

M&T Bank is a financial holding company headquartered in Buffalo, New York. M&T's principal banking subsidiary, M&T Bank, operates banking offices in New York, Maryland, New Jersey, Pennsylvania, Delaware, Connecticut, Virginia, West Virginia, and the District of Columbia. Trust-related services are provided by M&T's Wilmington Trust-affiliated companies and by M&T Bank. M&T Bank traces its origins to the founding of Manufacturers and Traders Bank in Buffalo, New York. As a result of mergers, acquisitions, and name changes, M&T Bank Corporation's principal bank is now known as Manufacturers and Traders Trust Company or M&T Bank. M&T Bank reorganized under a bank holding company in 1969 called First Empire State Corporation. The name was changed in 1998 to M&T Bank Corporation, whose common stock is listed on the New York Stock Exchange and trades under the symbol "MTB."

M&T Bank Corporation Careers

Join the vibrant team at M&T Bank Corporation, a leading financial institution where innovation meets tradition, offering a plethora of job opportunities across various sectors. As one of the most respected banks in the nation, M&T Bank Corporation is the perfect place to jumpstart or advance your career in the financial services industry.

Work You’ll Do

At M&T Bank Corporation, you will be part of a culture that cherishes diversity, leadership, and professional growth. Engage in work that makes a real difference in the community while fostering your career development through comprehensive training programs and diverse learning opportunities.

Innovate and Lead

Embrace the chance to work on projects that integrate cutting-edge financial technologies with robust, traditional banking practices. M&T Bank Corporation is at the forefront of the financial industry, offering innovative solutions that redefine banking standards. Our leadership in the market is driven by a commitment to excellence and continuous improvement.

Career Growth and Opportunities

Whether you are looking for an entry-level position or a more senior role, M&T Bank Corporation provides a dynamic pathway for career advancement. With a variety of job opportunities ranging from internships to full-time positions, you can find the perfect match for your skills and ambitions. Our team is dedicated to helping you navigate your career path with tailored development plans and leadership training.

Join Our Team

Explore job opportunities and join a team that values hard work, creativity, and strategic thinking. M&T Bank Corporation is hiring professionals who are passionate about finance and eager to contribute to a team-oriented environment. Enhance your skills through hands-on experience and ongoing professional development.

Networking and Professional Development

At M&T Bank Corporation, networking and professional development are part of our DNA. Connect with industry leaders, participate in high-impact networking events, and take advantage of our mentorship programs. Our employees benefit from a supportive network that boosts their career trajectories and fosters meaningful professional relationships.

Benefits and Culture

Enjoy a comprehensive benefits package that supports both your professional and personal life. M&T Bank Corporation offers competitive salaries, health benefits, and retirement plans designed to ensure the well-being of our team members and their families. Experience a supportive and inclusive culture where every employee is valued and given the opportunity to thrive.

How to Apply

Ready to take the next step in your career? Visit the M&T Bank Corporation Careers page to browse current openings, submit your resume, and prepare for your interview. We are excited to see how your skills and ideas can contribute to our continued growth and success.

Stay Connected

Keep up to date with the latest from M&T Bank Corporation by following our careers blog. Gain insights from our experts and stay informed about new job openings and upcoming networking events. Join M&T Bank Corporation today and be part of a team that is dedicated to growth, innovation, and leadership in the banking industry. Your future starts here!
Learn more about M&T Bank Corporation
Size
17,115 employees
Market Cap
$25.2 billion
Industry
Net Income
$1.3 billion
Founded
1868
5 Year Trend
+0.2%
NASDAQ

Similar Jobs

More Jobs at M&T Bank Corporation

More Information Technology Jobs

Find similar Principal Technology and Cybersecurity Risk & Controls Specialist jobs: