ForgeApply · Job listing
Cybersecurity Regulatory Lead
BBVA
See all 7 open roles at BBVA →
Tailor your resume for this BBVA job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for BBVA's site. Free trial, no card required.
About this role
Excited to grow your career?
BBVA is a global company with more than 160 years of history that operates in more than 25 countries where we serve more than 80 million customers. We are more than 121,000 professionals working in multidisciplinary teams with profiles as diverse as financiers, legal experts, data scientists, developers, engineers and designers.
About the job:
The Cybersecurity Regulatory Engagement Senior Manage r is an individual contributor role within the Information Security function for BBVA Corporate & Investment Banking (CIB) USA . The position reports directly to the Head of Information Security for BBVA CIB USA and serves as a key point of coordination for cybersecurity regulatory, audit, and security assurance activities.
This role is responsible for managing and executing cybersecurity regulatory engagements across the U.S. business, including regulatory examinations, supervisory inquiries, remediation activities, regulatory requests, and the implementation of new or evolving regulatory requirements.
The role also coordinates internal audit engagements where Information Security is in scope and leads or supports cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity.
The successful candidate will bring strong cybersecurity and regulatory judgment, excellent stakeholder-management skills, and the ability to work independently with senior cybersecurity leadership, engineering and control owners, and risk partners in a highly regulated U.S. financial-services environment.
Key Responsibilities • Lead and coordinate cybersecurity regulatory engagements for BBVA CIB USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities, serving as the primary Information Security coordination point to ensure responses, evidence, and presentations are accurate, complete, and timely.
• Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to support regulatory and assurance activities, translating evolving cybersecurity regulatory requirements into actionable expectations for Information Security and control owners.
• Coordinate internal audit engagements involving Information Security, including preparation, evidence collection, walkthroughs, responses, and remediation tracking, while also supporting regulatory attestations, control assessments, and framework maturity reviews to ensure outcomes are evidence-based and validated.
• Maintain oversight of cybersecurity compliance and control maturity across applicable regulations, supervisory expectations, and industry frameworks by performing control mapping and gap assessments across regulatory requirements, internal policies, and security controls, and developing regulatory readiness capabilities such as evidence repositories, control mappings, regulatory inventories, and reusable documentation.
• Own and support the maintenance, periodic review, and enhancement of Information Security policies and procedures for BBVA CIB USA, ensuring alignment with applicable regulatory requirements, audit expectations, and cybersecurity best practices.
• Ensure coordination and adherence with broader BBVA Group Information Security policies and standards, supporting consistent interpretation, implementation, and execution of Group-wide cybersecurity requirements within the U.S. CIB environment.
• Track and manage regulatory and audit findings, management actions, and remediation commitments, ensuring timely and sustainable closure, while partnering with control owners to embed regulatory requirements into effective and sustainable cybersecurity controls.
• Review and challenge the quality and defensibility of regulatory and audit evidence and management responses prior to submission, identify recurring themes across engagements, and recommend improvements to strengthen the cybersecurity control environment.
• Prepare concise management reporting and executive updates on examinations, audit status, control maturity, and remediation progress, and support interactions with regulators, auditors, and independent assessors, including walkthroughs, interviews, and control demonstrations.
Qualifications and Experience • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business , or a related field.
• 7+ years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines, preferably within banking or financial services, with demonstrated experience managing or supporting regulatory examinations, supervisory reviews, internal audits, external audits, or independent cybersecurity assessments within a highly regulated environment.
• Experience coordinating internal audit engagements where Information Security is in scope , including supporting cybersecurity control assessments , attestations , and evidence-based demonstrations of compliance and control maturity across the following regulations and frameworks:
• 23 NYCRR Part 500
• SEC cybersecurity requirements
• NFA cybersecurity requirements
• FFIEC Guidelines
• DORA (Digital Operational Resilience Act)
• SWIFT Customer Security Controls Framework (CSCF)
• FedLine security requirements
• CHIPS-related security requirements
• NIST Cybersecurity Framework (NIST CSF)
• CRI Profile
• Other applicable regulatory and industry control frameworks
• Strong understanding of the U.S. financial-services regulatory environment and the cybersecurity expectations applicable to banks, broker-dealers, financial institutions, and critical financial infrastructure.
• Ability to understand and challenge cybersecurity controls across areas such as identity and access management, privileged access, vulnerability management, security monitoring, inc
Salary insight
The midpoint of this range ($193k) is about 16% above the median disclosed salary for New York roles listed on ForgeApply ($165k across 7,817 jobs).
See full Security Engineer salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this BBVA role before you apply.
Tailor my resume for this jobSimilar jobs
- Cybersecurity Lead — Pingwind · Huntsville, AL
- Cybersecurity Engineer Lead — Pingwind · Shaw AFB, SC
- Director, Regulatory Affairs - Global Cyber Security — RBC · Jersey City, New Jersey, United States
- Project Lead - Cybersecurity — ICF · Washington, DC
- Director, Cybersecurity Engineering Lead — Blackrock · New York, NY
- Space Cybersecurity Engineering Lead — The Aerospace Corporation · Los Angeles AFB, CA
- Team Lead-Cyber Security — GDIT · USA MD Bethesda
- Cybersecurity Control Testing Lead, VP — MUFG · Jersey City, NJ
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)