Назад
Company hidden
7 часов назад

Principal Technology and Cybersecurity Risk & Controls Specialist

123 600 - 206 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Technology and Cybersecurity Risk & Controls Specialist (NIST 800-53/Cybersecurity Risk): Executing independent control testing, remediation validation, and risk-based assurance across Technology, Cybersecurity, and Data domains with an accent on control design, operating effectiveness, and regulatory readiness. Focus on leading complex testing engagements, challenging risk and control assessments, validating corrective actions, and preparing management reporting for risk-based decision making.

Location: Buffalo, New York, United States; hybrid schedule with remote work one day per week and in-person collaboration. Visa sponsorship is not available.

Salary: $123,600–$206,000 annual USD

Company

M&T Bank is a financial services organization with technology, cybersecurity, risk, audit, and regulatory functions.

What you will do

  • Maintain controls testing methodologies, procedures, standards, and quality assurance practices.
  • Lead the annual risk-based controls testing plan across Technology, Cybersecurity, and Data domains.
  • Execute independent assessments of control design and operating effectiveness.
  • Lead complex testing engagements and issue evaluations involving cybersecurity processes, data management, regulatory commitments, and strategic initiatives.
  • Validate remediation activities and confirm that corrective actions address root causes, control deficiencies, audit findings, and regulatory issues.
  • Prepare management reporting and coordinate responses to regulatory engagements.

Requirements

  • Bachelor’s degree and at least 7 years of relevant experience, or 11 years of combined higher education and work experience without a degree.
  • At least 6 years of relevant experience in Technology or Cybersecurity risk.
  • Expert knowledge of Technology and Cybersecurity risk principles and strong knowledge of cybersecurity best practices.
  • Experience with NIST frameworks, particularly NIST SP 800-53 and 800-53A.
  • Knowledge of security technologies and implementation methods, including firewalls, DMZs, encryption, Active Directory/LDAP, and SAML.
  • Experience with security control testing, multiple projects, strict deadlines, and overseeing tasks for less experienced team members.

Nice to have

  • Master’s degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or a related field.
  • Active CISA, CAP, CISSP, CISM, CRISC, or another recognized cybersecurity certification.
  • Knowledge of COBIT or ISO control frameworks, project management methodology, security architecture, cloud network security, RBAC, perimeter security, application security, and emerging cyber threats.
  • IT audit or first-line controls testing experience.

Culture & Benefits

  • Hybrid work arrangement with one remote workday per week.
  • Work with senior Technology, Cybersecurity Risk, Risk Division, Internal Audit, and Regulatory Affairs stakeholders.
  • Opportunity to present to regulators under the direction of senior Technology and Cybersecurity Risk leaders.
  • Role supports diversity and adherence to internal risk, regulatory, and control standards.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →