Manages the activities and strategic priorities of multiple cybersecurity departments. Responsible for financial and human capital planning to ensure short- and long-term strategic efforts support and protect the Bank from internal and external cybersecurity threats. This role oversees 2 or more functions/teams or a department within Cybersecurity and may act as a lead Cybersecurity representative with Regulators. Accountable for developing and executing budget for functions/teams they oversee. This role manages one or more functions/teams/departments within Cybersecurity, including Operations and Threat, Cloud and Architecture, Security Assessments and Business Information Security Officers (BISO), Identity and Access Management, and Security Engineering. The Head of Cybersecurity Defense Operations is responsible for driving the development and execution of comprehensive cybersecurity strategies, ensuring alignment with overall cybersecurity vision and organizational needs. They partner with Cyber senior leadership and Finance to direct business and financial resources effectively based on risk assessments and strategic priorities. This role monitors and reviews the effectiveness of risk measurement strategy, updates assessments and procedures in partnership with technology risk and enterprise risk teams, and communicates risk status to senior management. They lead strategic initiatives across Cybersecurity that drive continuous improvement and operational efficiencies, while maintaining or improving overall outcomes. Establishing and maintaining incident response policies and procedures, ensuring they align with industry best practices and regulatory requirements, is also a key responsibility. The Head of Cybersecurity Defense Operations collaborates with engineering and architecture teams to select appropriate security technologies, leverages industry knowledge to inform best practices and policies, and may represent the organization in industry forums and regulatory engagements. Furthermore, this role is responsible for creating a strong workforce plan, guiding the creation and maintenance of internal Cybersecurity training needs, developing Cybersecurity strategy and programs, and partnering with procurement and vendor management teams to assess vendor security controls. They exercise usual authority of a manager concerning staffing, performance appraisals, promotions, salary recommendations, performance management, and terminations. The role requires understanding and adherence to the Company’s risk and regulatory standards, policies, and controls, and designing, implementing, maintaining, and enhancing internal controls to mitigate risk. Promoting an environment that supports belonging and reflects the M&T Bank brand, and maintaining M&T internal control standards are also essential.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager