Cybersecurity Risk Advisor

$110,635 - $184,392/Yr

M&T Bank - Buffalo, NY

posted 3 months ago

Full-time - Mid Level
Buffalo, NY
1,001-5,000 employees
Credit Intermediation and Related Activities

About the position

The Cybersecurity Risk Advisor role is situated within the Technology and Cybersecurity Risk Operations (TCRO) organization at M&T Bank. This position operates with a moderate level of autonomy, relying on connections with team peers and support from Risk Specialists and senior members to execute second line risk management functions. The primary focus of this role is proactive risk management for assigned areas within the Technology and Cybersecurity division. This includes providing oversight, effective challenge, assessment, and advisory services. The advisor will engage in direct oversight of Technology and Cybersecurity operations, documenting engagement activities, identifying areas of concern, and measuring potential risks in relation to the organization's risk appetite. Responsibilities may involve issuing reports, reviewing remediation plans, and validating closure evidence. The role requires appropriate management of Technology and Cybersecurity risk activities, including findings, validations, and remediation plans. The advisor will execute independent and annual Targeted Reviews, planning and reporting on detailed fieldwork concerning high and medium-high risk areas within the division. Additionally, the advisor will assist in overseeing Technology and Cybersecurity Risk Control Self Assessments (RCSAs) and other risk management reporting, which includes conducting gap and delta assessments. Engaging with assigned oversight areas is crucial, as the advisor must understand the technology and provide guidance on project and product work prior to implementation, leveraging past experience and expertise in risk management practices. The advisor will also be responsible for identifying and assessing emerging risks associated with new products, services, markets, or changes to existing offerings. Fieldwork responsibilities include analysis, investigations, and monitoring of Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs). Participation in audits and in-depth reviews of Technology and Cybersecurity business line efforts and risk management activities is expected. The advisor must adhere to operational risk controls in accordance with company and regulatory standards, utilizing hands-on experience in Technology and Cybersecurity roles and knowledge of industry frameworks such as NIST, FFIEC AIO, and ITIL to provide guidance and build trusted partnerships with internal staff and third parties. The role also involves developing and analyzing Technology and Cybersecurity metrics specific to the organization.

Responsibilities

  • Manage Technology and Cybersecurity risk activities including findings, validations, and remediation plans.
  • Execute independent and annual Targeted Reviews, planning and reporting on detailed fieldwork regarding high/medium-high risk areas.
  • Assist with oversight of Technology and Cybersecurity Risk Control Self Assessments (RCSAs) and other risk management reporting.
  • Engage with assigned oversight areas to understand technology and advise on project/product work prior to implementation.
  • Identify and assess emerging risks associated with new products, services, markets, or changes to existing offerings.
  • Conduct fieldwork including analysis, investigations, and monitoring of KRIs and KPIs.
  • Participate in audits and in-depth reviews of Technology/Cybersecurity business line efforts and risk management activities.
  • Adhere to operational risk controls in accordance with company or regulatory standards.
  • Leverage experience in Technology and Cybersecurity roles to provide guidance and build partnerships with internal staff and third parties.
  • Develop and analyze Technology & Cybersecurity metrics.

Requirements

  • Bachelor's degree and six years' experience in compliance, legal, audit, risk, or other relevant function, OR a combined minimum of ten years' higher education and/or work experience including six years' experience in compliance, legal, audit, risk, or other relevant function.
  • Proficient computer skills including spreadsheet and word processing software.
  • Strong analytical skills and working knowledge of applicable laws.
  • Excellent written and verbal communication skills with all levels.

Nice-to-haves

  • Industry Cybersecurity Certificates preferred.
  • Practical hands-on experience in Incident Response, Security Operations Centers, Operational Resilience (BCM/DR), cloud security, application security, and cyber risk management.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service