
Risk Process Technical Specialist
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Develop business requirements that drive the implementation or enhancement of technologies for centralized control assessment objectives, including vulnerability scanning, penetration testing, server compliance assessments, and static code analysis tools.
• Configure technologies for centralized control assessments.
• Create and document operational procedures for the technologies used in centralized control assessments.
• Identify, assess, and implement enhancements for processes and reporting; provide support to the vulnerability assessment team.
• Engage in discussions with vendors of centralized assessment technologies.
• Develop testing scripts for implementations or upgrades and record test results.
• Design and document technical compliance standards for Bank systems and infrastructure.
• Establish escalation procedures to monitor and address findings from centralized control assessments.
• Conduct research and training on industry trends; disseminate information to management and the Risk Process team.
• Contribute to the annual budgeting process.
• Manage relationships with Technology teams that support centralized assessment technologies.
• Lead, oversee, and mentor junior members of the Risk Process Team.
• Comply with the Company's risk and regulatory standards, policies, controls, and Risk Appetite.
• Identify risk-related issues that need to be escalated to management.
• Foster diversity and promote the M&T Bank brand.
• Uphold internal control standards and address internal/external audit points and relevant regulatory issues promptly.
• Perform additional related duties as assigned.
• An Associate degree with at least 7 years of relevant work experience, or, if lacking a degree, a combined minimum of 9 years of higher education and/or work experience, including at least 7 years of relevant work experience.
• Previous experience with vulnerability assessment tools.
• Strong customer service orientation.
• Exceptional written and verbal communication skills.
• Prior experience working independently and providing guidance to the team as necessary.
• Experience in generating, collecting, storing, and retaining audit data.
• Working knowledge of various scanning solutions and vulnerability risk management platforms.
• Familiarity with Cybersecurity standards.
• Experience in technical writing.
• Bachelor's degree is preferred.
• CISSP, CRISC, and/or other Cybersecurity domain-related industry-recognized certifications are preferred.
• Preferred proficiency in technical writing skills.
• Attention to detail is preferred.
• Previous experience with Incident Response is preferred.
• Familiarity with Vulnerability Risk Management lifecycle solutions (e.g., Archer VRM) is preferred.
• Working knowledge of eGRC is preferred.
• Remote work arrangement
Vitamin Angels
Mercury
Public Partnerships | PPL
BlueCross BlueShield of Tennessee
Get handpicked remote jobs straight to your inbox weekly.