Principal Technology and Cybersecurity Risk & Controls Specialist
$123.6k - $206kM&T Bank
This role offers a hybrid work schedule; offering the flexibility to work remotely one day a week, while providing the opportunity for in-person collaboration. Sponsorship is NOT available for this position.Overview: Executes and manages independent control testing and remediation plan closure validation activities across Technology, Cybersecurity, and Data domains. Influences risk management outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and control design adequacy. Provides subject matter expertise for complex testing and validation activities, reviews the work of peers, supports development and maintenance of the annual testing plan, and prepares management reporting to enable effective risk-based decision making.Primary Responsibilities:Maintain the Controls Testing methodology, procedures, standards, and quality assurance practices to ensure testing activities are executed consistently and in accordance with internal policies and requirements.Lead the development, execution, and management of the Annual Controls Testing Plan utilizing risk-based principles, inherent risk assessments, regulatory expectations, emerging risks, and organizational priorities to ensure appropriate testing coverage across Technology, Cybersecurity, and Data risk domains.Direct and execute independent assessments of control design and operating effectiveness to determine whether controls are appropriately designed and operating effectively to mitigate identified risks and maintain residual risk within approved risk appetite.Provide effective challenge to Risk Advisors, Risk Owners, Control Owners, and Process Owners regarding risk identification, risk-to-control mappings, control coverage, control rationalization, testing scope, and control design adequacy.Lead complex controls testing engagements and issue evaluations involving high-risk technologies, cybersecurity processes, data management capabilities, regulatory commitments, and strategic initiatives.Evaluate the sustainability and effectiveness of remediation activities to independently confirm whether corrective actions effectively address identified root causes, design deficiencies, operating effectiveness failures, audit findings, regulatory issues, and self-identified issues.Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).Prepare and deliver management reporting on testing results, thematic observations, control environment maturity, remediation status, and emerging risk trends.Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite. Identify risk-related issues needing escalation to management.Promote an environment that supports diversity and reflects the M&T Bank brand.Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.Complete other related duties as assigned.Scope of Responsibilities:This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs. Work is accomplished with periodic direction. The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert. Apply professional judgment in determining testing strategies, sample selection approaches, issue severity assessments, remediation validation requirements, and conclusions regarding control effectiveness and risk mitigation.Review and challenges complex risk assessments to provide an independent opinion on the completeness of risk identification, appropriateness of control selection, and adequacy of control designServes as a recognized subject matter expert for controls testing methodology, control design assessment, operating effectiveness testing, issue validation, remediation validation, and risk-based assurance practices.This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.Education and Experience Required: Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experienceDemonstrated expert knowledge of Technology and/or Cybersecurity risk principlesMinimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unitPrevious experience of NIST (National Institute of Standards and Technology) or Cybersecurity frameworks, with a strong focus NIST 800-53 and 800-53aStrong knowledge of cybersecurity principles and industry best practices (relevant to confidentiality, integrity, availability)Proven knowledge of information technology security principles and implementation methods (e.g., firewalls, demilitarized zones, encryption, Active Directory / LDAP, SAML)Skilled in evaluating security controls based on confidentiality, integrity and availability requirements of systemsExperience with handling multiple projectsExperience meeting strict deadlinesExperience overseeing project tasks for less experienced team membersEducation and Experience Preferred: Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related fieldActive CISA (Certified Information Systems Auditor), CAP (Certified Authorization Professional), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control) certification or Cybersecurity domain-related industry-recognized certificationWorking knowledge of the current version of the NIST SP800-53 and 800-53a Controls, or other recognized control frameworks, such as COBIT (Control Objectives for Information and Related Technology) or ISOKnowledge of organization's risk tolerance and/or risk management approachWorking knowledge of project management methodologyStrong and proven knowledge of security technologies and architecture, including encryption, cloud network security design, role-based access control, perimeter security and application securityKnowledge of Cybersecurity threats and emerging security issuesExperienced in conducting security control testing of systemsIT Audit and/or First Line Control testing experience#LI-JB3M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $123,600.00 - $206,000.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.LocationBuffalo, New York, United States of AmericaSummaryLocation: Buffalo, NYType: Full time
$123.6k - $206k
...work from home one day per week.Overview: Leads risk assessments and control evaluations for complex Technology initiatives, influencing the organization's risk... ...strategic approaches for evaluating technology and cybersecurity risks, control effectiveness, and audit...SuggestedFull timeWork experience placementWork from home1 day per week- ...Principal Program Cost Control Analyst (PCA)At Northrop Grumman, our employees have incredible opportunities... ...us to be at the forefront of many technological advancements in our nation's history... ...development, budget baseline, cost risk analysis/ assessment and visibility...SuggestedFull timeContract work
$139.7k - $232.9k
...experienced engineers across Technology. Primary Responsibilities: •... ..., infrastructure, cybersecurity, and architecture teams. • Serve... ...with stakeholders to identify risks and optimization opportunities... ...needed. • Maintain internal control standards and compliance expectations...PrincipalFull timeWork experience placement$139.7k - $232.9k
...Browser. Solves highly complex cybersecurity challenges while aligning... ...that reduce organizational risk while supporting business transformation... ...Browser, and other security controls supporting secure access and... ...of data protection technologies across the organization.Lead...PrincipalFull timeWork experience placementWork from home$85.5k - $123.2k
...engineering career while working with cutting-edge automation and manufacturing technology?Join our Buffalo Milk️Bone team and become a key technical leader responsible for the site's controls, automation, and electrical systems. In this role, you'll lead high-impact...SuggestedFull timeShift workNight shift$85.6k - $128.4k
...Principal Contract AdministratorAt Northrop Grumman, our employees... ...be at the forefront of many technological advancements in our nation's... ...conditions to address provisions and risks of financial terms,... ...give you the flexibility and control to choose the benefits that make...PrincipalContract workShift work- ...Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS015, P3, Band... ...Responsibilities: - Provide project control and business support services in support... ...to identify variances, trends, and risks from financial data. - Excellent written...Minimum wageContract workTemporary workWork experience placementRemote work
$85k - $110k
...Senior Controls EngineerThis manufacturing facility in Buffalo, NY is seeking a Senior Controls Engineer to lead power and control systems... ...base and a replacement plan for obsolete equipment and technologies.This role builds and maintains a sustainable skill development...Local area$85.6k - $128.4k
...be at the forefront of many technological advancements in our nation's... ...for you to join our team as a Principal Contract Administrator based... ...conditions to address provisions and risks of financial terms,... ...give you the flexibility and control to choose the benefits that make...PrincipalContract workRelocationShift work$102.17k
...passionate about water and technology, Trinnex is the place for you... ...operate at the intersection of cybersecurity and DevSecOps to protect... ...lifecycle-embedding security controls, identifying vulnerabilities... ...analysis (SCA), open-source risk management, and vulnerability...Work experience placementH1b$104.8k - $192.2k
...passwordless authentication technologies. The ideal candidate will... ...detection, and identity assurance controls. Implement IAL2-grade... ...with IAM architects, cybersecurity teams, application owners, and... ...takeover and impersonation risks. Improved onboarding user...For contractorsSummer holidayFlexible hours- ...of the Seneca Nation. Seneca Holdings is seeking a Sr. Project Controls Analyst. The Senior Project Controls Analyst plays a critical role... ...standards are met. Additionally, the role involves managing risks, resolving issues, escalating concerns when necessary, and supporting...Full timeContract workFor subcontractorWork at officeFlexible hours
$80k - $110k
...outside of work. Job Title : Program Controls Analyst Reporting To: Manager,... ...that allows for constantly developing technology and excellent career opportunities.... ...leading the consolidation of schedule, cost, risk, and milestone data into accurate, timely...Flexible hours$128.9k - $214.9k
...to work from home one day a week. Senior Risk Manager - Enterprise OperationsThe Senior Risk Manager is a key member of the Technology & Enterprise Operations First Line Risk team... ...practices, enhance risk frameworks and controls, and ensure alignment with the Bank's...Full timeWork from home1 day per week$103k - $171.6k
OverviewThe Senior Risk Analyst II - Finance Oversight is a strategic contributor within the second line of defense, supporting the Finance... ...directly with first-line teams to assess adequacy of risk controls and compliance with regulatory standards.Position is pivotal in...Full timeWork at office$100k - $135k
...Lighthouse Technology Services is partnering with our client to fill their Senior Innovation... ...priorities. Bridge technical specialists, product teams, and leadership by transforming... ...case fundamentals (TCO, ROI, payback), and risk analysis Deliver decision-ready recommendations...$119.77k
Title: Model Risk Analyst - Validation [Multiple Positions Available]Job Location: 345 Main St, Buffalo, NY 14203. Position requires... ...factors that augment quantitative models. Review to confirm proper controls and adequate documentation are in place. Recommend, as necessary...Full timeWork at office$85.5k - $123.2k
SENIOR CONTROLS ENGINEERProvide key leadership with regard to power and control systems, equipment specification and maintenance, proper... ...and apply control, simulation and process modeling technologies to analyze and improve overall process and packaging operationsCompensation...Local area$123.6k - $206k
Overview: The Expert Risk Analyst will support, and report, to the Segment Risk Manager responsible for oversight of market risk. The... ...oversight activities.Adhere to applicable compliance/operational risk controls in accordance with Company or regulatory standards and policies....Full timeWork experience placement$25k
...time /HybridGHJ is looking for a Principal/Partner- Forensic Accounting &... ...investigations, advise clients on fraud risk mitigation and improvements to internal controls. The successful candidates will... ...leadership opportunities, technology initiatives, as well as developing...PrincipalFull timeLocal areaWorldwide$148.3k - $247.1k
...capabilities that support 24x7x365 technology operations. This leader will... ...with Infrastructure, Cybersecurity, Application Development, and... ..., reduce operational risk, and establish modern service... ...through automation, risk-based controls, and streamlined processes.Enhance...Full timeWork experience placementNight shift$94.2k - $141.2k
...has enabled us to be at the forefront of many technological advancements in our nation's history - from... ...get to do:Responsible for Supplier Quality risk management.Develops and implements supplier quality evaluation and control systems.Assures supplier process and product...PrincipalShift work- ...works collaboratively to support of all risk and compliance assessment activities of... ...organizational risk and business partners, the technology organization, and global delivery teams... ...risk areas and to ensure proper controls are implemented.Accountable for the review...Contract workFor contractorsWork at officeLocal area
$167.6k - $279.4k
...Engineering Programs within Cybersecurity Infrastructure Engineering.... ...Prevention, and Encryption controls, ensuring alignment with overall... ...effectively based on risk assessments and strategic priorities... ...in partnership with technology risk and enterprise risk teams...Full timeTemporary workWork experience placement$97.1k - $161.8k
...industry trends and emerging technologies related to PKI, encryption, and cybersecurity to enhance the bank's... ...adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the... ...), Certified Encryption Specialist (CES), or Certified Information...Full timeWork experience placementWork from home$167.6k - $279.4k
...seeking an experienced and innovative cybersecurity leader to serve as Senior Manager of Workforce... ..., secrets management, identity controls, application onboarding, access... ...ensuring alignment with Cybersecurity, Technology, Risk Management, and enterprise business objectives...Full timeWork experience placementWork from homeRelocation package1 day per week$167.6k - $279.4k
...indirectly managing several diverse types of Technology operations and/or support function teams... ..., compliance, human resources and risk operations within the departments.Direct... ...and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite...Full timeTemporary workWork experience placementFlexible hours- ...; ensure all costs on the invoice are accurate, appropriately supported and reconcile to the accounting system. - Assist program control staff with ad hoc financial and cost analysis as requested by program management and corporate finance. - Provide analytical support...Minimum wageContract workTemporary workWork experience placementFor subcontractorWork at office
$100k - $115k
Job Title Location 665 Hertel Avenue, Buffalo, NY, 14207, United States Base Pay $100,000.00 - $115,000.00 / Year Employee Type Exempt Required Degree Masters Manage Others Yes Minimum Experience 5 Years Description RequirementsPrincipal$128.9k - $214.9k
...strategic objectives of the Bank, improving risk management and ensuring efficiency/... ...Operations (FinOps), partnering across Technology, Finance, Architecture, Engineering, and... ...and regulatory standards, policies and controls in accordance with the Company's Risk Appetite...Full timeWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Technology and Cybersecurity Risk & Controls Specialist. Be the first to apply!

