The role involves leading complex risk assessments in technology and cybersecurity, developing frameworks, mentoring analysts, and ensuring compliance with regulations.
Overview:
Leads risk analysis for complex initiatives, influencing overarching risk framework and providing advanced guidance to leadership for informed decision-making aligned with organizational imperatives.
Primary Responsibilities:- Develop and implement strategic approaches for in-depth risk assessments for comprehensive coverage of all technology capabilities.
- Develop and execute sophisticated risk management framework and programs that informs how to align practices with business objectives and regulatory requirements, including (but not limited to) developing complex process maps, leading risk controls self-assessments, and summary of complex findings.
- Drive enforcement of frameworks, providing expert guidance and continually assessing regulation and standards to achieve industry-leading technology risk compliance.
- Spearhead collaboration among cross-functional teams and senior or executive leadership to align technology practices with overarching business goals and regulatory requirements; maintain productive relationships with stakeholders and/or with third-party engagements to ensure resiliency of Technology, Cybersecurity, and the overall Bank.
- Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).
- Encourage innovation in risk management strategies through identification of advanced methodologies to address evolving threats and the recommendation of path for implementation to Technology and Cybersecurity Risk leadership.
- Provide advanced mentorship to mid-level analysts, fostering their professional growth and ensuring a high standard for all risk analysts within the team.
- Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.
- Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
- This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs.
- Work is accomplished with periodic direction. The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert.
- This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.
No supervisory responsibilities.
Education and Experience Required:- Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience
- Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles
- Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit
- EITHER: IT Audit experience (integrated/infrastructure audits, ITGCs, SOX, application controls) OR IT-specific risk experience (risk assessment, development of risks and controls/RCSA, risk consulting) in a technology org
- Must have operated in a highly independent role and have the ability to determine prioritization without much oversight
- Must be able to articulate the relationship between IT risks and controls, policy vs. standard vs. control, and the role of 1st/2nd line of defense vs. audit function
- A certification in one of the following areas (CISA, CISSP, CRISC, CIA)
- Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field
- Applicable certification align to function or domain such as Certified in Risk and Information Systems Control (CRISC®), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP)
- Ability to lead critical analysis of work and problem solve
- Excellent communication and interpersonal skills
- Experience partnering with leadership to design solutions aligned with business needs
- Excellent ability to strategically seek critical information, and apply across a broad array of processes
- Prior experience prioritizing across competing priorities and quickly changing landscape, and execute outcomes aligned with priorities
- Experience effectively influencing peers and leaders
- Ability to train and mentor peers
Top Skills
Cybersecurity
It Audit
Risk Management Frameworks
Similar Jobs
Information Technology • Cybersecurity
The role involves researching threats, creating reports, collaborating with teams, and advocating for product enhancements to improve cybersecurity strategies.
Top Skills:
AzureC/C++ElasticGoGoogleKibanaPythonSiem Tools
Artificial Intelligence • Big Data • Software • Analytics • Business Intelligence • Big Data Analytics
The Cloud Security Engineer will secure cloud infrastructure, manage security solutions, conduct assessments, and mentor engineers while collaborating with teams.
Top Skills:
Apollo GraphqlAWSKubernetesNode.jsPythonReactReduxTerraformTypeormTypescript
Artificial Intelligence • Cloud • Internet of Things • Machine Learning • Analytics • Industrial
Develop and verify embedded security controls, work with global engineering teams to identify and implement security risk controls on off-road equipment.
Top Skills:
BluetoothCanEmbedded Security ControlsEthernetGoJ1939JavaLinuxPythonRustUdsWi-Fi
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute