Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Cybersecurity Manager - Offensive Security image - Rise Careers
Job details

Cybersecurity Manager - Offensive Security

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.

Overview:   

Manages the activities and strategic priorities of one or multiple cybersecurity teams. Responsible for financial and human capital planning to ensure short- and long-term priorities support and protect the Bank from internal and external cybersecurity threats.

Primary Responsibilities:

  • Lead and manage the Offensive Security Operations team, including red teamers, penetration testers, and adversary emulation specialists.
  • Develop and execute the organization’s offensive security strategy aligned with risk management objectives and threat landscape insights.
  • Oversee planning and execution of red team operations, penetration testing campaigns, and purple team exercises across enterprise environments.
  • Coordinate cross-functional efforts with threat intelligence, blue team, and incident response teams to identify security gaps and drive remediation.
  • Provide technical and operational leadership in the design and execution of complex adversarial simulations, leveraging frameworks such as MITRE ATT&CK and NIST.
  • Prioritize work within function(s) of oversight and raise to senior leadership and finance to incorporate into financial plan.
  • Manage team performance, mentoring, career development, and resource allocation to support both tactical and strategic initiatives.
  • Present operational outcomes, risk findings, and mitigation strategies to senior leadership and stakeholders through well-crafted reports and briefings.
  • Manage initiatives to identify and implement new/updated methodologies that ensure a proactive stance against risks.
  • Interpret regulatory and compliance requirements, and partner with risk, legal, and engineering teams to ensure necessary controls are implemented.
  • May present in regulatory engagements to understand and address cybersecurity-related legal and regulatory requirements.
  • Create strong workforce plan to meet business needs, including (but not limited to) mentoring and coaching high potential team members, developing career paths and succession planning for key roles, identifying training needs and gaps, and establishing culture of knowledge sharing and collaboration.
  • Contribute to the delivery of the Bank-wide information security training and awareness program.
  • Collaborate with technology and business leaders to create program that meets Cybersecurity objectives and organization needs.
  • Exercise usual authority of a manager concerning staffing, performance appraisals, promotions, salary recommendations, performance management and terminations.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

  • Primary partners: CISO, Cybersecurity Directors and Senior Managers
  • Stakeholders: Technology team and the Bank
  • Work is accomplished with minimal direction; strategizes team goals based on Cybersecurity imperatives.
  • Oversees a minimum of 2 functions/teams within Cybersecurity.
  • This role may present to Regulators.
  • Accountable for informing and meeting budget for functions/teams they oversee.

Manager Responsibility:

Typically leads a team of 5-10 FTE

Education and Experience Required:

  • Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience
  • Demonstrated expert knowledge of Cybersecurity principles.
  • Minimum 6 years’ work experience in/with the specific cybersecurity function
  • Minimum 2 years’ managerial experience

Education and Experience Preferred:

  • Minimum of 6 years’ managerial experience
  • Proven ability to mentor and lead cybersecurity individual contributors.
  • Excellent communication
  • Excellent interpersonal skills
  • Ability to effectively articulate message to technical and business teams
  • Experience effectively influencing peers and leaders.
  • Experience prioritizing across competing priorities and quickly changing landscape.
  • Experience in a highly regulated industry environment.
  • Proficient understanding of financial services regulations, compliance requirements, and risk management practices.
  • Ability to translate business objectives into strategic cyber plans, programs, and initiatives.

 #LI-JB3 #Hybrid

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $130,795.52 - $217,992.53 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Buffalo, New York, United States of America

Average salary estimate

$174393.5 / YEARLY (est.)
min
max
$130795K
$217992K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Manager - Offensive Security, MTB

Are you ready to take the lead in protecting against cyber threats? M&T Bank is searching for a proactive and dynamic Cybersecurity Manager specializing in Offensive Security to join our innovative team in Buffalo, NY. In this pivotal role, you’ll manage and guide a talented group of cybersecurity professionals, including red teamers and penetration testers, as you develop and implement a robust offensive security strategy aligned with our organizational objectives. Your responsibilities will include overseeing red team operations and executing penetration testing campaigns to identify and address vulnerabilities across enterprise environments. Collaboration is key, and you’ll coordinate with various teams to enhance our protective measures and drive remediation efforts. We believe in nurturing talent, so you’ll have the opportunity to mentor team members while shaping their career paths. With a hybrid work schedule, you can enjoy flexibility, working remotely two days a week while still benefiting from collaborative in-person sessions at our Buffalo Tech Hub. If you’re passionate about cybersecurity and looking to make a significant impact in a role that combines leadership, strategic vision, and hands-on technical expertise, we want to hear from you!

Frequently Asked Questions (FAQs) for Cybersecurity Manager - Offensive Security Role at MTB
What are the main responsibilities of a Cybersecurity Manager - Offensive Security at M&T Bank?

As a Cybersecurity Manager specializing in Offensive Security at M&T Bank, your primary responsibilities include leading the Offensive Security Operations team, developing and executing offensive security strategies in alignment with risk management objectives, overseeing red team operations, and coordinating with cross-functional teams to remediate security gaps. You will also present findings to senior leadership and manage team performance and development.

Join Rise to see the full answer
What qualifications are required for the Cybersecurity Manager - Offensive Security position at M&T Bank?

To qualify for the Cybersecurity Manager - Offensive Security position at M&T Bank, candidates should have a Bachelor's degree and at least 7 years of relevant work experience, including a minimum of 6 years in a cybersecurity function and at least 2 years in a managerial role. A strong understanding of cybersecurity principles is essential, alongside excellent communication and leadership skills.

Join Rise to see the full answer
How does the Cybersecurity Manager - Offensive Security role support M&T Bank's cybersecurity objectives?

The Cybersecurity Manager - Offensive Security role supports M&T Bank's cybersecurity objectives by leading the Offensive Security Operations team to proactively identify and address vulnerabilities. By collaborating with other departments, managing testing campaigns, and mentoring team members, you'll enhance the organization's overall security posture and ensure compliance with regulatory standards.

Join Rise to see the full answer
What is the work environment for the Cybersecurity Manager - Offensive Security at M&T Bank?

The work environment for the Cybersecurity Manager - Offensive Security at M&T Bank is hybrid, allowing you to work remotely two days a week while also providing opportunities for in-person collaboration at our Buffalo Tech Hub. This setup promotes flexibility and teamwork, enabling you to effectively lead your team while fulfilling responsibilities.

Join Rise to see the full answer
What skills are vital for success as a Cybersecurity Manager - Offensive Security at M&T Bank?

Success as a Cybersecurity Manager - Offensive Security at M&T Bank requires a combination of technical and soft skills. It’s crucial to have an expert knowledge of cybersecurity principles, strong communication skills to articulate technical information, and the ability to lead and mentor a team. Being able to manage competing priorities while influencing stakeholders across the organization is also vital.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Manager - Offensive Security
How do you approach developing an offensive security strategy?

When developing an offensive security strategy, I assess the current threat landscape and align the strategy with the organization's risk management objectives. It involves collaborating with various teams to understand vulnerabilities and planning red team operations that simulate real-world attacks.

Join Rise to see the full answer
What experience do you have leading a cybersecurity team?

In my previous role, I managed a team of cybersecurity professionals where I focused on fostering a collaborative environment. I implemented regular training and mentoring programs to ensure each team member could grow their skills and contribute to our strategic goals.

Join Rise to see the full answer
Can you describe a successful penetration testing campaign you led?

I led a penetration testing campaign that newly targeted critical infrastructure. We effectively identified numerous vulnerabilities, developed a comprehensive report outlining our findings, and worked closely with the engineering team to remediate them promptly, significantly enhancing the organization's security.

Join Rise to see the full answer
How do you ensure compliance with regulatory requirements in your cybersecurity strategy?

I actively monitor regulatory changes and partner with legal and compliance teams to ensure our cybersecurity policies and strategies align with any new requirements. Regular audits and compliance checks also help us stay ahead of potential discrepancies.

Join Rise to see the full answer
What frameworks do you utilize for offensive security simulations?

I frequently utilize frameworks such as MITRE ATT&CK and NIST to design offensive security simulations. These frameworks provide structured methodologies that help mimic real-world attack scenarios and assess the effectiveness of security controls.

Join Rise to see the full answer
How do you manage competing priorities in cybersecurity projects?

I prioritize tasks based on their impact on the organization's security posture and compliance needs. Effective communication with stakeholders and team members is essential so that everyone understands the critical points and timelines.

Join Rise to see the full answer
How do you foster a culture of collaboration and knowledge sharing in your team?

Fostering collaboration begins with creating an open environment where team members feel valued. I encourage regular knowledge-sharing sessions where individuals can present on topics they are passionate about, enabling us to learn from one another and build stronger teamwork.

Join Rise to see the full answer
What leadership style do you believe is most effective in cybersecurity?

I believe in a transformational leadership style that focuses on inspiring and motivating team members. This approach not only fosters innovation and creativity but also empowers individuals to take ownership of their work.

Join Rise to see the full answer
What steps do you take when identifying security gaps during red team operations?

Identifying security gaps involves systematic testing and analysis. During red team operations, I gather data through various methods, analyze the outcomes for vulnerabilities, and present actionable recommendations to close those gaps effectively.

Join Rise to see the full answer
How do you stay current with emerging cybersecurity threats?

Staying updated on emerging cybersecurity threats requires ongoing education. I frequent industry webinars, read cybersecurity research reports, and participate in professional networks. This consistent engagement ensures that I can adapt our strategies to counteract evolving threats.

Join Rise to see the full answer
Similar Jobs
Posted 12 days ago

Seeking a Business Risk Team Lead at M&T Bank to lead risk initiatives and promote established compliance standards in our Buffalo office.

As a Senior Treasury Portfolio Manager at M&T Bank, you will lead strategic initiatives in managing the Derivatives Portfolio and MSR Hedging, driving teamwork and communication across the organization.

Photo of the Rise User
Posted 6 days ago

Join a high-performing team at Thomson Reuters as an Application Support Analyst, responsible for supporting and improving digital applications.

Photo of the Rise User
PMHCC Hybrid Philadelphia, PA
Posted 13 days ago

Lead the technology strategy and innovation at the City of Philadelphia as the Chief Information Officer.

Photo of the Rise User
Posted 10 days ago
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings

Join Apple's Marcom IT Team as a Render Systems Engineer, driving the setup and support for innovative marketing technology solutions.

Job Details Hybrid No location specified
Posted yesterday

Astor & Sanders Corporation is looking for a System Administrator III to oversee and enhance systems operations in Bethesda, MD.

Photo of the Rise User

We are looking for a skilled Application Owner for Salesforce Sales Cloud to take charge of platform development and elevate our services.

Photo of the Rise User
ServiceNow Remote Salarpuria Sattva Knowledge City Knowledge City, Unit II, 17 to 10 Floor Survey No. 83/1, Serilingampally Mandal, Hyderabad, Telangana, India
Posted 12 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

Join ServiceNow as a Senior ServiceNow Developer, leading the charge in IT Service Management enhancements with AI integration.

Photo of the Rise User
Spirit Airlines Hybrid Dania Beach, Florida, United States
Posted 12 days ago

Join Spirit Airlines as a Sr Admin for ITOC, where you'll play a vital role in ensuring the performance of our technical environments.

Join a pioneering pharmaceutical company as a Senior Manager of IT Operations and Security to make a tangible impact on patient care.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Fast-Paced
Growth & Learning
Medical Insurance
Dental Insurance
401K Matching
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Flex-Friendly
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 8, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed IT Support Engineer at Level AI
Photo of the Rise User
Someone from OH, Dayton just viewed Customer Content Specialist at Cision
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed Senior Corporate Communications Manager at Bumble Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at Workday
Photo of the Rise User
Someone from OH, Cincinnati just viewed Financial Planning and Analysis Lead at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Operations at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Strategic Finance Analyst, Corporate at Benchling
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Project Finance at Apex Clean Energy
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst, Acceptance FP&A at Visa
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior FP&A Analyst, Sales at GitLab
Photo of the Rise User
Someone from OH, Cincinnati just viewed FP&A Analyst at Lithic
Photo of the Rise User
15 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Westerville just viewed Summer Internship - Public Health Data Science at Cotiviti
V
Someone from OH, Cincinnati just viewed Part-Time Executive/Personal Assistant at VirtuHire
Photo of the Rise User
Someone from OH, Chillicothe just viewed Area Manager at The Hemp Co by Curaleaf at Curaleaf
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP, B2B/Integrated Marketing at TEGNA Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director, Marketing and GTM Strategy at Aspen Dental
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Vice President, JLLIPT Marketing at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Forum Health
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Beacon