About the Role
Serve as a trusted, strategic security advisor to senior and executive leaders in technology and business units. Build strategic relationships to align cybersecurity strategies with business objectives, ensuring security measures support business operations. Manage risk by identifying vulnerabilities, influencing control implementation, and guiding regulatory compliance.
Responsibilities
- Serve as the senior cybersecurity advisor to business units, providing direct counsel to Senior Executive Vice Presidents (SEVPs) and Executive Vice Presidents (EVPs).
- Foster and maintain strategic relationships with business units to deliver security-by-design controls throughout the initiative lifecycle.
- Champion a culture of cybersecurity continuous improvement by sharing knowledge of current security threats, vulnerabilities, and mitigations.
- Identify and document threats and vulnerabilities, integrating findings into strategic plans and risk management frameworks.
- Engage with executive business unit leaders and cross-functional teams to address systematic issues hindering efficient security controls.
- Strategize with leaders to define key performance indicators and metrics aligning with business initiatives, delivering them to non-technical teams comprehensibly.
- Provide guidance and advocacy to business unit leadership regarding cybersecurity investment prioritization while balancing business enablement.
- Advise business unit leadership on cybersecurity-related risk issues and influence actions in partnership with Technology Risk Management.
- Understand and adhere to the Company’s risk and regulatory standards, policies, and controls.
- Design, implement, maintain, and enhance internal controls to mitigate risk.
- Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of audit points and regulatory issues.
- Complete other related duties as assigned.
Requirements
- Bachelor's degree and a minimum of 9 years’ relevant work experience, or a combined minimum of 13 years’ higher education and/or work experience, including a minimum of 7 years’ relevant work experience in an operationally focused security practitioner role.
- Minimum of 5 years’ experience working with business leadership and enterprise projects.
- Minimum of 15 years of experience in cybersecurity, technology risk, and/ or business unit.
- Master’s degree in information assurance, computer science, business administration, or related field.
- Excellent communication and interpersonal skills; ability to effectively convey messages to technical and executive business leaders.
- Excellent ability to translate complex cybersecurity issues to business leader initiatives and strategies.
- Experience building strategic plans in partnership with senior leadership, third parties, project managers, technical and cybersecurity subject matter experts, and business subject matter experts.
- Strong understanding of cybersecurity technologies, their purpose, and their security requirements and data protection needs.
- Excellent understanding of threats, risk mitigations, and technical controls recommended by security leaders.
- Experience partnering with senior leaders to design solutions to meet business needs while delivering a strong cybersecurity posture.
- Excellent ability to influence bank-wide efforts through effective clear communication, leveraging program management principles, and escalating when necessary.
- Excellent ability to prioritize and deliver results across changing priorities and quickly changing landscape based on business and technology needs.
- Excellent ability to work effectively with unique teams and varying personalities and adapt leadership and influence styles to effectively reach mutually beneficial outcomes.
- Excellent knowledge of national and global cybersecurity policies, regulations, and security frameworks.
Skills
- Cybersecurity
- Technology Risk
- Business Unit Strategy
- Risk Management
- Regulatory Compliance
- Strategic Planning
- Communication
- Interpersonal Skills
- Problem Solving
- Leadership
- Influence
- Program Management
Location
- Buffalo, New York, United States of America
Work Type
- Onsite
Experience Level
- Minimum of 9 years’ relevant work experience
- Minimum of 13 years’ higher education and/or work experience
- Minimum of 7 years’ relevant work experience in an operationally focused security practitioner role
- Minimum of 5 years’ experience working with business leadership and enterprise projects
- Minimum of 15 years of experience in cybersecurity, technology risk, and/ or business unit
Education Level
- Bachelor's degree
- Master’s degree in information assurance, computer science, business administration, or related field
Salary/Compensations
- $148,300.00 - $247,100.00 Annual (USD)
About the Company
- M&T Bank is committed to fair, competitive, and market-informed pay for our employees.
