{"id":1145256,"url":"https://alion.io/job/mt-bank-corporation-principal-first-line-risk-specialist-cybersecurity-and-ai-initiatives","title":"Principal First Line Risk Specialist - Cybersecurity and AI Initiatives","company":{"id":4312,"name":"M&T Bank Corporation","domain":"mtb.com","url":"https://alion.io/company/mtb","size_band":"1001-5000","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Workday","truth_index":{"grade":"B","score":83,"open_postings":61,"ghost_share":0,"stale_share":0.689,"repost_share":0,"time_to_fill_p50_days":33,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Buffalo, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":148300,"max":247100,"currency":"USD","period":"year","gross":null,"usd_annual":247100},"salary_estimate":null,"experience_years_min":13,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[],"status":"live","first_seen_at":"2026-09-23T14:41:47Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T00:48:04Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week\nOverview: \nLeads risk analysis and governance activities for emerging Cybersecurity and Artificial Intelligence (AI) initiatives, influencing the design of risk frameworks, controls, and standards that support evolving technologies. Provides expert guidance to senior leadership, engineering, and architecture teams to proactively identify, assess, and mitigate technology risks while ensuring alignment with regulatory expectations and organizational objectives.\nPrimary Responsibilities:\nDevelop and implement risk frameworks, controls, and standards supporting Cybersecurity and AI engineering capabilities, ensuring comprehensive coverage of emerging technologies.\nAct as a first line of risk advisor to engineering, architecture, and security teams, proactively identifying risks, control gaps, and opportunities to strengthen governance.\nLead the assessment of emerging technology trends, regulatory guidance, and industry developments to ensure organizational readiness and compliance.\nDesign, enhance, and implement risk management processes, procedures, and standards that support new and evolving Cybersecurity and AI initiatives.\nPartner directly with the Chief Information Security Officer (CISO), senior technology leaders, engineers, and architects to evaluate strategic initiatives and provide risk-informed recommendations.\nDrive the identification, development, and implementation of new controls to address emerging risks and strengthen the organization's risk posture.\nLead and support audit activities, regulatory examinations, and risk assessments, ensuring timely remediation of findings and sustainable control improvements.\nCollaborate across Technology, Cybersecurity, AI, Enterprise Risk, Internal Audit, and Regulatory Affairs functions to align practices with business objectives and regulatory expectations.\nMonitor and assess evolving threat landscapes and emerging technology risks, integrating advanced risk management methodologies to address changing business and regulatory requirements.\nPrepare and present complex risk assessments, control evaluations, and recommendations to senior leadership and executive stakeholders.\nUnderstand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Identify risk-related issues requiring escalation to management.\nPromote an environment that supports belonging and reflects the Company's values and culture.\nMaintain internal control standards, including timely implementation of internal and external audit recommendations together with any issues raised by regulators as applicable.\nComplete other related duties as assigned.\nScope of Responsibilities:\nThis position works closely with the CISO, senior engineering and architecture leaders, Cybersecurity leadership, Technology and Cybersecurity Risk leadership, Enterprise Risk, Internal Audit, Regulatory Affairs, and other senior stakeholders across the organization.\nServes as a key risk partner for Cybersecurity and AI engineering initiatives, applying significant judgment and expertise to identify emerging risks, evaluate control effectiveness, and recommend strategic solutions.\nExercises substantial independence in determining approaches to risk management, control design, and governance activities for emerging technologies, while collaborating with executive stakeholders on critical decisions.\nMay represent the organization during regulatory examinations, audits, and governance reviews related to Cybersecurity, AI, and emerging technology risk management.\nFunctions as a subject matter expert on Cybersecurity and AI risk, advising leadership on industry trends, regulatory developments, control design, and risk mitigation strategies.\nSupervisory/Managerial Responsibilities:\nNo supervisory responsibilities.\nEducation and Experience Required:\nBachelor's degree and a minimum of 9 years’ relevant work experience, or in lieu of a degree, a combined minimum of 13 years’ higher education and/or work experience\nDemonstrated expert knowledge of Technology and Cybersecurity risk principles\nMinimum of 8 years' relevant work experience in and/or with the specific risk area and/or business unit\nEducation and Experience Preferred:\nMaster's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field\nApplicable certification align to function or domain such as Certified in Risk and Information Systems Control (CRISC®), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP)\nExperience supporting Cybersecurity, AI, and emerging technology initiatives, including risk assessments, governance, and control design.\nProven ability to identify control gaps, develop new controls, and implement risk mitigation strategies within a first line of risk environment.\nExperience developing processes, procedures, standards, and risk frameworks that support cybersecurity programs, AI adoption, and evolving technology capabilities.\nStrong understanding of emerging technology trends, cybersecurity risks, and regulatory guidance related to AI and information security.\nExperience partnering directly with senior leaders, engineering and architecture teams, and executive stakeholders, including the CISO, to provide risk-informed recommendations and influence strategic decision-making.\nExperience supporting audits, regulatory examinations, and control reviews, with a demonstrated ability to proactively identify risks, drive remediation efforts, and communicate effectively with both technical and business audiences.\nM&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $148,300.00 - $247,100.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.Location\nBuffalo, New York, United States of America","description_format":"text","description_chars":6151,"description_truncated":false,"requirements":{"experience_years_min":13,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Financial Services","Wealth Management"],"lifecycle":[{"event":"open","at":"2026-09-23T14:41:47Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":0,"expected_fill_days":33,"reasons":["conf:4","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-09-24T05:45:00Z"},"pay":{"stated_usd_annual":247100,"is_top_pay":true},"html_url":"https://alion.io/job/mt-bank-corporation-principal-first-line-risk-specialist-cybersecurity-and-ai-initiatives","json_url":"https://alion.io/job/mt-bank-corporation-principal-first-line-risk-specialist-cybersecurity-and-ai-initiatives.json","meta":{"generated_at":"2026-09-24T06:47:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}