Senior Business Information Security Officer
Buffalo, NYFull-time$148k–$247kPosted Jul 29, 2026
Overview:
Responsible for serving as a trusted, strategic security advisor to senior and executive leaders in technology and business units. Builds strategic relationships with business unit leaders to align cybersecurity strategies with business objectives, ensuring that security measures support and enhance business operations. Manages risk by identifying vulnerabilities, influencing implementation of appropriate controls, and guiding compliance with relevant regulations.
Primary Responsibilities:
- Serve as the senior cybersecurity advisor to business units, providing direct counsel to Senior Executive Vice Presidents (SEVPs) and Executive Vice Presidents (EVPs) within business units inclusive of technology, client facing, and enterprise functions.
- Foster and maintain strategic relationships with business units to deliver security-by-design controls, ensuring cybersecurity practices are built into business unit initiatives for the entire lifecycle.
- Champion a culture of cybersecurity continuous improvement by maintaining current knowledge related to security threats, vulnerabilities and mitigations set forth to reduce the attack surface; circulate this knowledge appropriately across business units, including key actions to implement.
- Identify and document threats and vulnerabilities that may impact the business and address them regularly with business units by integrating findings into long-term strategic plans and risk management frameworks.
- Engage with executive business unit leaders and cross-functional teams to address systematic issues that cause obstacles or increased complexity, hindering efficient security controls within business units.
- Strategize with cybersecurity, technology, and business leaders to define key performance indicators and metrics aligning with business initiatives and deliver them to non-technical teams in terms that are accessible and comprehensible.
- Provide guidance and advocacy to business unit SEVPs and EVPs regarding the prioritization of business unit investments that impact cybersecurity while balancing business enablement capabilities.
- Advise business unit leadership on cybersecurity-related risk issues and influence actions to take in close partnership with Technology Risk Management and in support of the organizations wider risk management and compliance programs.
- Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
- Complete other related duties as assigned.
Scope of Responsibilities:
- Primary stakeholders: Technology and Business Line EVPs & SEVPs
- Primary partners: Cybersecurity people leaders, Technology EVPs and SVPs
- Work is accomplished with high degree of autonomy; strategizes business-unit specific imperatives in alignment with Bank imperatives.
- Subject matter expert of multiple Cybersecurity functions
Supervisory/Manager Responsibilities:
No supervisory responsibilities.
Education and Experience Required:
- Bachelor's degree and a minimum of 9 years’ relevant work experience, or in lieu of a degree, a combined minimum of 13 years’ higher education and/or work experience, including a minimum of 7 years’ relevant work experience in an operationally focused security practitioner role.
- Minimum of 5 years’ experience working with business leadership and enterprise projects.
Education and Experience Preferred:
- Minimum of 15 years of experience in cybersecurity, technology risk, and/ or business unit.
- Master’s degree in information assurance, computer science, business administration, or related field.
- Excellent communication and interpersonal skills; ability to effectively convey messages to technical and executive business leaders.
- Excellent ability to translate complex cybersecurity issues to business leader initiatives and strategies.
- Experience building strategic plans in partnership with senior leadership, third parties, project managers, technical and cybersecurity subject matter experts, and business subject matter experts.
- Strong understanding of cybersecurity technologies, their purpose, and their security requirements and data protection needs.
- Excellent understanding of threats, risk mitigations, and technical controls recommended by security leaders.
- Experience partnering with senior leaders to design solutions to meet business needs while delivering a strong cybersecurity posture.
- Excellent ability to influence bank-wide efforts through effective clear communication, leveraging program management principles, and escalating when necessary.
- Excellent ability to prioritize and deliver results across changing priorities and quickly changing landscape based on business and technology needs.
- Excellent ability to work effectively with unique teams and varying personalities and adapt leadership and influence styles to effectively reach mutually beneficial outcomes.
- Excellent knowledge of national and global cybersecurity policies, regulations, and security frameworks