×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Technology and Cybersecurity Risk & Controls Specialist

Job in Bridgeport, Fairfield County, Connecticut, 06610, USA
Listing for: mtb
Full Time position
Listed on 2026-09-07
Job specializations:
  • Security
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 110000 - 170000 USD Yearly USD 110000.00 170000.00 YEAR
Job Description & How to Apply Below

This role offers a hybrid work schedule; offering the flexibility to work remotely one day a week, while providing the opportunity for in-person collaboration. Sponsorship is NOT available for this position.

Overview:

Executes and manages independent control testing and remediation plan closure validation activities across Technology, Cybersecurity, and Data domains. Influences risk management outcomes by partnering with Risk Advisors and Risk Owners on risk identification, control coverage, and control design adequacy. Provides subject matter expertise for complex testing and validation activities, reviews the work of peers, supports development and maintenance of the annual testing plan, and prepares management reporting to enable effective risk-based decision making.

Primary Responsibilities:
  • Maintain the Controls Testing methodology, procedures, standards, and quality assurance practices to ensure testing activities are executed consistently and in accordance with internal policies and requirements.
  • Lead the development, execution, and management of the Annual Controls Testing Plan utilizing risk-based principles, inherent risk assessments, regulatory expectations, emerging risks, and organizational priorities to ensure appropriate testing coverage across Technology, Cybersecurity, and Data risk domains.
  • Direct and execute independent assessments of control design and operating effectiveness to determine whether controls are appropriately designed and operating effectively to mitigate identified risks and maintain residual risk within approved risk appetite.
  • Provide effective challenge to Risk Advisors, Risk Owners, Control Owners, and Process Owners regarding risk identification, risk-to-control mappings, control coverage, control rationalization, testing scope, and control design adequacy.
  • Lead complex controls testing engagements and issue evaluations involving high-risk technologies, cybersecurity processes, data management capabilities, regulatory commitments, and strategic initiatives.
  • Evaluate the sustainability and effectiveness of remediation activities to independently confirm whether corrective actions effectively address identified root causes, design deficiencies, operating effectiveness failures, audit findings, regulatory issues, and self-identified issues.
  • Contribute to design and delivery of training programs to ensure comprehensive knowledge of technology and cybersecurity risk management and growing critical skills to enhance team's outcomes.
  • Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy and meeting regulatory request, organizing documents and packets, and leading exam management (i.e., template folders, review of first day letter and follow-up requests).
  • Prepare and deliver management reporting on testing results, thematic observations, control environment maturity, remediation status, and emerging risk trends.
  • Understand and adhere to the Company's risk and regulatory standards, policies and controls in accordance with the Company's Risk Appetite. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Promote an environment that supports diversity and reflects the M&T Bank brand.

Scope of Responsibilities:

This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs.

Work is accomplished with periodic direction. The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert.

Apply professional judgment in determining testing strategies, sample selection approaches, issue severity assessments, remediation validation requirements, and conclusions regarding control effectiveness and risk mitigation.

Review and challenges complex risk assessments to provide an independent opinion on the completeness of risk identification, appropriateness of control selection, and adequacy of control design

Serves as a recognized subject matter expert for controls testing methodology, control design assessment, operating effectiveness testing, issue validation, remediation validation, and risk-based assurance practices.

This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.

Education and Experience

Required:

Bachelor's degree and a minimum of 7 years' relevant work experience, or in lieu of a degree, a combined minimum of 11 years' higher education…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary