Third Party Cybersecurity Risk Manager

Posted:
9/3/2024, 6:40:28 AM

Location(s):
New York, United States ⋅ Buffalo, New York, United States

Experience Level(s):
Senior

Field(s):
IT & Security

Overview:

Provides strategic and tactical direction in support of the TPRM Cyber team .    Manages multiple teams and Subject Matter Experts (SMEs) with diverse responsibilities including, but not limited to, development and execution of Cybersecurity Operations strategies, Cybersecurity Risk and Controls assessments, Vulnerability assessments, Cybersecurity controls testing and validation, Cybersecurity policies and standards, and Cybersecurity awareness and training program.  Represents Cybersecurity on various committees.  Identifies and communicates Cybersecurity threats, vulnerabilities, risks, emerging trends, and mitigation strategies in alignment with the organization's risk appetite. Recommends and reports on Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for areas of responsibility and ensures appropriate remediation when required.  Promotes awareness of Cybersecurity policy, standards and governance among management and throughout the enterprise and ensures sound principles are reflected in the organization’s mission, vision and goals.

Primary Responsibilities:

  • Manage TPRM Cyber team and own Cybersecurity portion of the TPRM program
  • Stand up and manage a SaaS Posture Management vendor and support team
  • Communicate the delivery roadmap to our technology teams by inspiring the team through the vision. 
  • Be responsible for one or more key security systems or processes, working directly with stakeholders and vendors to ensure seamless integration and operation.
  • Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support cybersecurity goals and objectives and reduce overall organizational risk.
  • Lead multiple diverse stakeholders and manage multiple projects and initiatives concurrently to establish and maintain enterprise continuity of operations program, strategy, and mission assurance.
  • Lead, manage, and oversee diverse security improvement actions across multiple teams to evaluate, validate, and implement solutions as required.
  • Lead, align, and manage cybersecurity priorities within the Department's overall security strategy and in coordination with closely-related departments and within Cybersecurity.
  • Actively manage, report, and lead efforts to define and improve the effectiveness of the enterprise's cybersecurity safeguards to ensure they provide the intended level of protection.
  • Lead and oversee the preparation, creation, distribution, and maintenance of plans, instructions, guidance, and Standard Operating Procedures (SOPs) concerning the security of Cybersecurity Operations for the team, multiple teams, or within Cybersecurity.
  • Fully manage from identification until completion the protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
  • Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite.  Design, implement, maintain and enhance internal controls to mitigate risk on an ongoing basis.  Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Education and Experience Required:

Associates degree in an applicable discipline and a minimum of 9 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience, including a minimum of 9 years’ relevant work experience

Minimum of 2 years’ managerial experience

Relevant work and leadership experience in two or more of the following Cybersecurity domains:  Security and Risk Management, Asset Security, Security Engineering, Communication and Network Security, Identity and Access Management, Security Testing and Security Operations

Demonstrated detailed knowledge and understanding of Cybersecurity operational processes

Demonstrated detailed knowledge of Cybersecurity threats, vulnerabilities, emerging trends, and regulatory and operational impacts

Demonstrated ability to utilize feedback to drive process and service improvement

Proven experience managing multiple stakeholder relationships, including determining needs, requirements, and resources, and managing stakeholder expectations while committing to delivering quality results

Proven experience communicating complex information, concepts, or ideas in a confident, accurate, and well-organized manner through verbal, written, and/or visual media

Proven experience adjusting and operating in a diverse, challenging, and unpredictable fast-paced work environment

Proven experience coordinating, collaborating, and disseminating information to multiple subordinate, peer, and leadership teams, departments, and organizations

Prior experience advising and providing assistance to operations and intelligence decision makers in response to dynamic situations

Education and Experience Preferred:

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $130,795.52 - $217,992.53 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Buffalo, New York, United States of America