ForgeApply
Try it free

ForgeApply · Job listing

Principal Cybersecurity Infrastructure Engineer

M&T Bank

Buffalo, NY, US$140k – $233khybrid

See all 147 open roles at M&T Bank

Tailor your resume for this M&T Bank job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for M&T Bank's site. Free trial, no card required.

About this role

This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week Overview:     Responsible for designing, implementing, and optimizing enterprise security architectures, platforms, and frameworks that protect the organization's users, applications, data, and cloud services. Leads the development and enhancement of Security Service Edge (SSE) capabilities including Web/Cloud Proxy, Data Loss Prevention (DLP), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Enterprise Browser. Solves highly complex cybersecurity challenges while aligning security outcomes with business objectives, regulatory requirements, and evolving threat landscapes. Acts as a knowledge resource and mentor for less experienced engineers across multiple cybersecurity disciplines. Completes day-to-day engineering support activities and strategic transformation initiatives.

Primary Responsibilities: • Partner with senior engineers and leadership to define enterprise SSE, Zero Trust, and data protection strategies that reduce organizational risk while supporting business transformation, cloud adoption, hybrid work, and AI enablement initiatives. • Lead architecture, engineering, configuration, and deployment of enterprise security platforms including Web/Cloud Proxy, CASB, DLP, ZTNA, Enterprise Browser, and other security controls supporting secure access and data protection. • Define testing methodologies, validation frameworks, and security effectiveness metrics to ensure comprehensive assessment of data protection technologies across the organization. • Lead deployment efforts for complex systems and technologies, coordinating with cross-functional teams and providing technical oversight to ensure successful implementation. • Establish tuning standards, operational baselines, and best practices for data protection policies, cloud access governance, email protection controls, browser security, and Zero Trust enforcement mechanisms. • Lead automation initiatives utilizing APIs, orchestration platforms, AI-driven capabilities, and security workflows to improve operational efficiency, accelerate response times, and reduce manual effort. • Design and implement comprehensive data protection strategies to identify, classify, govern, monitor, and protect sensitive data across endpoints, cloud services, collaboration platforms, email, and SaaS applications. • Architect and enhance Zero Trust Network Access solutions that replace legacy network-centric security models with identity, device, application, and risk-aware access controls. • Collaborate with stakeholders across Cybersecurity, Technology, Legal, Risk, Compliance, Data Governance, and Business Units to integrate security controls seamlessly into business processes and digital transformation initiatives. • Drive continuous improvement across security platforms and engineering teams by evaluating emerging technologies, threat intelligence, industry trends, and regulatory requirements to improve Cybersecurity effectiveness. • Maintain strategic vendor relationships for key security technologies, providing oversight for issue resolution, product roadmaps, and operational optimization. • Advise leadership on security technology investments, budget planning, platform rationalization, and future-state architecture decisions supporting enterprise security objectives. • Lead adoption and governance of AI security capabilities, ensuring visibility, risk management, policy enforcement, and secure integration of AI applications and services throughout the enterprise. • Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues requiring escalation to management. • Promote an environment that supports belonging and reflects the M&T Bank brand. • Maintain M&T internal control standards, including timely implementation of internal and external audit findings together with any issues raised by external regulators, as applicable. • Complete other related duties as assigned.

Scope of Responsibilities: • Designs and implements security architectures incorporating Web/Cloud Proxy, Data Loss Prevention, Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Enterprise Browser, and related capabilities to secure user access to applications, internet resources, and organizational data regardless of location. • Designs and implements enterprise data protection strategies and technologies to prevent unauthorized access, transmission, exposure, or loss of sensitive information across endpoints, cloud environments, SaaS platforms, collaboration tools, email, and AI applications. • Architects and manages data classification, labeling, information protection, insider risk management, data lifecycle management, compliance, and governance capabilities. • Develops and implements enterprise Zero Trust strategies focused on continuous verification, least privilege access, segmentation, identity-based security, device trust, and risk-adaptive access control models. • Designs and implements security controls, governance frameworks, monitoring, and risk management practices for enterprise AI platforms and services, including AI application discovery, data protection, regulatory compliance, and AI risk visibility. • Designs and implements security controls and architectures protecting cloud infrastructure, SaaS applications, cloud workloads, and enterprise data from cybersecurity threats and malicious activities. • Partners with leaders within Cybersecurity, Technology, Data Governance, Risk Management, and Executive Leadership across the organization. • Exercises judgment in selecting methods, technologies, architectural patterns, and implementation approaches to achieve strategic security objective

Salary insight

The midpoint of this range ($186k) is about 56% above the median disclosed salary for Buffalo roles listed on ForgeApply ($119k across 275 jobs).

See full DevOps / SRE salary data for Buffalo

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this M&T Bank role before you apply.

Tailor my resume for this job

Similar jobs

More like this: DevOps & SRE Jobs · DevOps & SRE Jobs in Buffalo · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)