Posted in

Lead Cybersecurity Engineer – Vulnerability

Lead Cybersecurity Engineer – Vulnerability

CompanyM&T Bank
LocationBuffalo, NY, USA
Salary$110635.01 – $184391.68
TypeFull-Time
DegreesBachelor’s
Experience LevelSenior, Expert or higher

Requirements

  • Bachelor’s degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experience
  • In-depth knowledge and hands-on experience with vulnerability tools and technologies (e.g., Blackduck, Veracode, Qualsys, Rapid7, Checkmarx, Burp Suite, etc.)
  • Strong knowledge of DevSecOps practices and secure integration into CI/CD pipelines.

Responsibilities

  • Evaluate, design, implement, and manage vulnerability scanning tools and automated processes to streamline detection and response workflows
  • Lead integrations of vulnerability scanning tools into the software development & lifecycle process, through collaboration with DevSecOps, IT, infrastructure and security teams, to ensure vulnerability management processes align with security best practices and organizational goals
  • Design security systems or solutions with significant complexity and moderate risk, ensuring alignment with cybersecurity objectives and organizational needs.
  • Configure and develop controls for security systems with significant complexity, to fortify system defenses and optimize performance of technologies.
  • Lead testing efforts for systems and technology, coordinating with cross-functional teams and providing technical expertise in identifying and resolving issues.
  • Manage deployment of security solutions for complex systems or technology, ensuring smooth integration with existing infrastructure and minimal disruption.
  • Define and implement tuning methodologies for systems and technologies, using advanced analytical techniques to maximize efficiencies.
  • Develop and implement automation and orchestration for complex systems to streamline security operations and response activities.
  • Lead collaboration efforts with Cybersecurity and Technology teams to effectively implement and maintain security solutions for the organization.
  • Lead improvement initiatives within Cybersecurity team, implementing best practices and optimizing processes to enhance security capabilities.
  • Actively partner with vendor to optimize security products and/or drive resolution of complex support issues.
  • Assist leadership with vendor relationships by maintaining when licenses need to be renewed, informing when hardware needs to be refreshed or new technologies should be considered.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Preferred Qualifications

  • Proficiency in scripting and automation (e.g., Python, PowerShell, bash, Java, or similar).
  • Experience with container security and cloud security tools (e.g., Docker, Kubernetes, AWS, Azure).
  • Relevant certifications (e.g., CISSP, SSCP, CompTIA Security+, AWS Certified Security Specialty, Azure Security Engineer, or similar cybersecurity certifications) are a plus.
  • Experience with security frameworks (e.g., NIST, CIS, OWASP)
  • Advanced understanding of the security system development and infrastructure lifecycle and architecture, and systems design
  • Proven experience with the development and customization of tools utilized in assigned Cybersecurity function
  • Demonstrated ability to translate architecture into technical requirements
  • Proficient level of critical thinking and problem solving ability
  • Excellent communication and interpersonal skills
  • Experience partnering with leaders to design solutions to business needs.
  • Proficient persuasive communication skills to gain buy-in of others
  • Strong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sources
  • Ability effectively serves in indirect leadership role