Назад
Company hidden
10 дней назад

Senior Technology and Cybersecurity Risk & Controls Specialist (Cybersecurity)

150 800 - 251 300$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Technology and Cybersecurity Risk & Controls Specialist (Cybersecurity): Executing independent control testing and remediation validation across Technology, Cybersecurity, and Data domains with an accent on risk-based assurance, control design adequacy, and regulatory engagements. Focus on leading complex testing activities, evaluating operating effectiveness, challenging risk and control assessments, and preparing management reporting on emerging risks and remediation status.

Location: Bridgeport, Connecticut, United States of America; hybrid schedule with remote work one day per week and in-person collaboration. Visa sponsorship is not available.

Salary: $150,800–$251,300 USD per year.

Company

M&T Bank is a banking organization with technology, cybersecurity, risk, regulatory, and internal audit functions.

What you will do

  • Maintain controls testing methodology, procedures, standards, and quality assurance practices.
  • Lead the annual, risk-based controls testing plan across Technology, Cybersecurity, and Data domains.
  • Execute independent assessments of control design and operating effectiveness.
  • Lead complex testing engagements and remediation validation for high-risk technologies, cybersecurity processes, data management capabilities, and regulatory commitments.
  • Challenge risk, control, testing scope, and control design assessments with Risk Advisors, Risk Owners, Control Owners, and Process Owners.
  • Prepare regulatory engagement materials and management reporting on testing results, control maturity, remediation, and emerging risk trends.

Requirements

  • Bachelor’s degree and at least 7 years of relevant experience, or 11 years of combined higher education and work experience in lieu of a degree.
  • At least 6 years of experience in the relevant Technology or Cybersecurity risk area or business unit.
  • Expert knowledge of Technology and/or Cybersecurity risk principles and strong knowledge of confidentiality, integrity, and availability requirements.
  • Experience with NIST frameworks, particularly NIST 800-53 and 800-53A, and security technologies including firewalls, DMZs, encryption, Active Directory/LDAP, and SAML.
  • Experience evaluating security controls, managing multiple projects, meeting strict deadlines, and overseeing tasks for less experienced team members.
  • Ability to work in the hybrid Bridgeport role; visa sponsorship is not available.

Nice to have

  • Master’s degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or a related field.
  • Active CISA, CAP, CISSP, CISM, CRISC, or another recognized cybersecurity certification.
  • Knowledge of COBIT, ISO, risk management approaches, project management methodologies, cybersecurity threats, and emerging security issues.
  • Experience with cloud network security, role-based access control, perimeter security, application security, security control testing, IT audit, or first-line control testing.

Culture & Benefits

  • Hybrid work schedule with remote work one day per week.
  • Collaboration with senior Technology, Cybersecurity Risk, Risk Division, Internal Audit, and Regulatory Affairs stakeholders.
  • Opportunity to present to regulators under the direction of senior risk leaders.
  • Work supporting risk-based decision-making, regulatory compliance, and control environment maturity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →