Head of Cybersecurity Defense Operations
Manufacturers and Traders Trust Co
Apply to this jobThis role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week
Overview:
M&T Bank is seeking a strategic and transformational cybersecurity leader to serve as Head of Cyber Defense Operations. This role is accountable for leading the Bank's enterprise cyber defense capabilities, ensuring the continuous identification, protection, detection, response, and recovery from cybersecurity threats impacting the Bank's technology assets, customers, colleagues, and operations. The Cybersecurity Operations division serves as the focal point for M&T's 24x7x365 cyber defense mission and first-line cybersecurity response capabilities.
The Head of Cyber Defense Operations will oversee multiple cyber defense functions and will work in close partnership with Threat Intelligence, Threat Hunt and Detection Engineering teams to ensure a unified, intelligence-driven cyber defense mission across the enterprise. This leader will partner closely with Technology, Enterprise Risk, Compliance, Audit, Corporate Security, and executive leadership to strengthen the Bank's cyber resilience and operational readiness in an increasingly complex threat landscape. This leader plays a key role in executing enterprise-scale cybersecurity programs, contributes to the Bank's cybersecurity transformation initiatives, and leads managers and senior technical leaders across the cyber defense mission. Reporting to the Director of Cybersecurity Operations, the Senior Manager translates enterprise strategy into operational execution, ensuring the Bank's detection, response, and insider risk capabilities function as a single, integrated defense mission.
Primary Responsibilities:
- Operational leadership and execution of the Bank's Cyber Defense Operations strategy and roadmap, ensuring alignment with Cybersecurity, Technology, Operational Resilience, and enterprise risk management objectives..
- Provide strategic oversight and leadership for enterprise cyber defense capabilities, including security monitoring, threat detection, incident response, threat intelligence, threat hunting, insider threat, data loss prevention, and cyber defense engineering functions.
- Direct the operations and continuous maturation of the Cybersecurity Operations Center (CSOC), ensuring effective monitoring, triage, response, escalation, and containment of cybersecurity events across the enterprise.
- Lead strategic initiatives to modernize cyber defense operations through automation, advanced analytics, threat-informed defense methodologies, AI-enabled capabilities, and operational efficiencies while maintaining or improving security outcomes.
- Provide executive oversight of the Bank's Cybersecurity Incident Response Team (CIRT), ensuring effective preparedness, incident handling, recovery, after-action reviews, and continuous improvement of incident response processes.
- Serve as (or designate) the Cyber Incident Commander for high-severity/major incidents, directing cross-functional response and briefing the Director and executive stakeholders
- Champion automation and orchestration (SOAR, workflow tooling, scripting) across cyber defense operations to reduce manual effort and scale capabilities.
- Own operational performance and reporting for CSOC, Incident Response, and Insider Threat; contribute to enterprise-wide detection and response metrics in coordination with Threat Intelligence, Threat Hunting, and Detection Engineering.
- Provide strategic oversight of the Insider Threat and Data Loss Prevention (DLP) programs to reduce risks associated with unauthorized access, misuse of sensitive information, and data exfiltration.
- Establish, monitor, and report on key cyber defense metrics including alert volumes, detection coverage, response effectiveness, mean time to detect (MTTD), mean time to respond (MTTR), threat intelligence effectiveness, DLP investigations, insider threat investigations, and operational maturity.
- Support the evolution of integrated cyber defense capabilities through collaboration among Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Protection Engineering, CSOC, Incident Response, and Insider Threat teams.
- Partner with Cyber senior leadership to direct business and financial resources effectively based on risk assessments, threat landscape changes, and strategic priorities.
- Monitor and review the effectiveness of risk measurement strategies, updating procedures and controls in partnership with Technology Risk Management and Enterprise Risk teams while communicating cyber risk posture to senior leadership.
- Represent the organization in regulatory examinations, industry forums, audits, and cybersecurity engagements involving security operations, cyber resilience, and incident response practices.
- Create a strong workforce plan to meet business needs, including mentoring and coaching cybersecurity leaders, succession planning, workforce development, skills assessments, and cultivating a culture of accountability, innovation, resilience, and continuous learning.
- Exercise usual authority of a manager concerning staffing, performance appraisals, promotions, salary recommendations, performance management, and terminations.
- Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit findings together with any issues raised by regulators as applicable.
- Complete other related duties as assigned.
Scope of Responsibilities:
- Primary partners: Director of Cybersecurity Operations, Chief Information Security Officer (CISO), Chief Information Officer (CIO), Cybersecurity Leadership Team, Technology Directors, Enterprise Architecture, Technology Risk Management, Corporate Security, Legal, Compliance, Internal Audit, and Enterprise Resilience leaders
- Stakeholders: Regulators, Technology teams, Risk teams, Corporate Security, Business leaders, Audit partners, customers, and the Bank.
- Work is accomplished with minimal direction; strategizes team imperatives in alignment with Bank imperatives.
- Oversees 2 or more functions/teams or a department within Cybersecurity.
- This role may act as a lead Cybersecurity representative with Regulators.
- Accountable for developing and executing budget for functions/teams they oversee.
- This role manages one or more functions/teams/departments within Cybersecurity:
- Operations and Threat – proactively identify, analyze, and respond to cyber threats, ensuring the Bank's digital assets are secure and resilient against potential risks and attacks. Functions/teams may include Cybersecurity Operations Center (CSOC), Incident Response, Threat Intelligence, Threat Hunt, Threat Detection Engineering, SOAR, Insider Threat, Cyber Fusion Center Operations, Governance and Operation Metrics, and Operational Resilience & Crisis Response
Education and Experience Required:
- Bachelor's degree and a minimum of 9 years’ relevant work experience, or in lieu of a degree, a combined minimum of 13 years’ higher education and/or work experience.
- Demonstrated expert knowledge of Cybersecurity principles.
- Minimum of 8 years’ work experience in/with the specific cybersecurity function.
- Minimum 3 years’ managerial experience
Education and Experience Preferred:
- Experience leading enterprise Security Operations Center (SOC/CSOC) organizations within a large, highly regulated financial institution.
- Experience overseeing Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, Insider Threat, and Data Loss Prevention programs.
- Deep understanding of threat-informed defense methodologies, ransomware preparedness, and cyber resilience principles.
- Experience with SIEM, SOAR, EDR, NDR, threat intelligence platforms, and advanced cybersecurity analytics technologies.
- Experience supporting regulatory examinations, audit engagements, and cyber resilience reviews.
- Demonstrated success leading cybersecurity transformation initiatives involving automation, AI-enabled operations, and operational excellence.
- Proven ability to build and lead high-performing cybersecurity organizations through periods of growth, modernization, and change.
#LI-JB3 #Hybrid
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $167,600.00 - $279,400.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.Location
Buffalo, New York, United States of AmericaSummary
Lead enterprise cyber defense, overseeing SOC, incident response, threat intel, and automation.
Job title
Head of Cybersecurity Defense Operations
Experience level
9+ years
Minimum experience
9+ years exp
Industry
financial services
Location requirements
must be in Buffalo, NY; hybrid work allowed
Salary
$168k–$279k
Management role
Yes
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Buffalo, NY, USA