Lead Cybersecurity Engineer - DLP/Insider Threat

Buffalo, NY, United States

M&T Bank

With a community bank approach, M&T Bank helps people reach their personal and business goals with banking, mortgage, loan and investment services.

View all jobs at M&T Bank

Apply now Apply later

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.

Overview:   

Responsible for designing and implementing large scale-scale security systems and solutions to develop or enhance new or existing security solutions, solving advanced complex problems or enhancements. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.

Primary Responsibilities:

  • Lead Design and Implementation: Responsible for designing, implementing, and managing systems that prevent the transfer, sharing, and loss of sensitive data and evaluate Insider Threat risks.
  • Lead Policy Creation and Enforcement: Create and enforce policies to prevent data leakage, loss, or improper sharing, such as blocking certain file transfers or restricting access to classified information.
  • Integration with Security Tools: Integrate DLP and Insider Threat solutions with other security tools like firewalls, endpoint protection, and email gateways.
  • Lead Maintenance and Optimization: Maintain and optimize DLP tools, ensuring they perform effectively, updating rules, and refining policies based on evolving data protection needs.
  • Security Measures: Implement encryption, data labeling, access controls, and other security measures.
  • Lead Cross-Functional Integration: Develop an effective cross-functional cybersecurity insider threat operating model integrated into the broader Insider Threat Program and supporting processes.
  • Analytical Framework: Define an analytical framework that enables proactive identification and prioritization of use cases supported by a data strategy to develop sophisticated analytics.
  • Logging and Monitoring: Establish effective logging and monitoring processes and capabilities to build the foundation and baseline data for identifying out-of-pattern behavior.
  • Technology Capabilities: Develop robust technology capabilities that enable the operationalization of analytics and security visibility processes.
  • Security Solution Design: Design components of security solutions with significant complexity and moderate risk, ensuring alignment with cybersecurity objectives and organizational needs.
  • Control Configuration and Development: Configure and develop controls for security tools or systems to fortify system defenses.
  • Testing and Execution: Design and execute testing of systems and technology thoroughly in coordination with cross-functional teams to ensure reliability and effectiveness of security measures.
  • System Deployment: Deploy security systems and code, ensuring seamless integration into existing infrastructure while minimizing disruptions.
  • Continuous Monitoring and Tuning: Continuously monitor and tune security systems to enhance efficiency and effectiveness in mitigating and detecting threats.
  • Lead Automation: Develop and implement automated installation, configuration, and processes to streamline security operations and response activities.
  • Collaboration: Partner with Cybersecurity and Technology teams on security solutions implementations and maintenance.
  • Lead Process Enhancement: Proactively recommend process enhancements and implement prioritized improvements within the Cybersecurity team.
  • Vendor Engagement: Engage with vendors for routine security products or solutions support.
  • Risk and Regulatory Standards: Understand and adhere to the company’s risk and regulatory standards, policies, and controls in accordance with the company’s risk appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.

Education and Experience Required:

  • Bachelor's degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experience

Education and Experience Preferred:

  • Advanced understanding of the security system development and infrastructure lifecycle and architecture, and systems design
  • Proven experience with the development and customization of tools utilized in assigned Cybersecurity function
  • Demonstrated ability to translate architecture into technical requirements
  • Proficient level of critical thinking and problem-solving ability
  • Excellent communication and interpersonal skills
  • Experience partnering with leaders to design solutions to business needs.
  • Proficient persuasive communication skills to gain buy-in of others
  • Strong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sources
  • Ability effectively serves in indirect leadership role
  • Advanced proficiency in prioritizing and managing multiple responsibilities, ensuring that deadlines are met, and projects are executed efficiently.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $110,635.01 - $184,391.68 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

LocationBuffalo, New York, United States of America
Apply now Apply later
Job stats:  5  2  0

Tags: Analytics Automation Encryption Firewalls Monitoring Strategy

Perks/benefits: Competitive pay

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.