Lead Cybersecurity Engineer - SIEM
Remote, USA
This role offers a hybrid work schedule; offering the flexibility to work from home two days a week, while providing the opportunity for in-person collaboration. May be considered for remote
At M&T Tech, we’re a team of makers, doers, and builders, working to create the most advanced technology solutions in banking. We’re not your stereotypical suit and tie bankers: we’re an innovative team of leading tech experts, pushing boundaries, and taking risks. We’re building an agile team of the most skilled and creative workers to solve complex problems, architect solutions, write high-performance software, and chart our new path, all to make the lives of our customers, and the communities that we serve, better. Join us and be part of something new as we build tomorrow’s bank, today.
Overview:
We are seeking a highly skilled and experienced Senior SIEM Engineer to join M&T Bank as a key member of our Security Engineering team. As a Senior SIEM Engineer, you will be responsible for leading the design, implementation, and management of our Security Information and Event Management (SIEM) infrastructure. You will play a critical role in protecting the Bank's assets, ensuring the confidentiality, integrity, and availability of our systems, and detecting and responding to potential security threats. This is a senior-level position that requires exceptional technical expertise, strong leadership skills, and a deep understanding of SIEM technologies and best practices.
Primary Responsibilities:
Lead the design and architecture of the bank's SIEM infrastructure, ensuring its effectiveness, scalability, and alignment with industry standards and regulatory requirements
Implement, configure, and optimize SIEM solutions to collect, correlate, and analyze security event data from various sources, such as network devices, servers, applications, and endpoints
Develop and maintain SIEM use cases, correlation rules, alerts, and reports to identify and prioritize security incidents and potential threats
Collaborate with other Cybersecurity and Security Engineering teams to investigate and resolve complex security incidents, conducting root cause analysis and recommending remediation actions
Stay up to date with the latest security threats, vulnerabilities, and industry trends, and proactively assess their potential impact on the bank's SIEM infrastructure
Lead SIEM-related projects, including system upgrades, enhancements, and integration with other security tools and technologies
Provide guidance and mentorship to junior SIEM engineers, promoting knowledge sharing and skill development within the team
Collaborate with internal stakeholders, such as IT operations, compliance, and risk management, to ensure the Bank's security posture is in line with industry standards and regulatory requirements
Participate in incident response exercises, tabletop simulations, and other security-related drills to enhance the bank's incident response capabilities
Responsibilities may include infrastructure architecture and design, research and development of new or expanded systems, creation of technology standards and policies, thorough analysis of user requirements and operational constraints, unit test and system integration, and user acceptance testing
Regularly and independently interact with business partners of varying associate and management levels to ensure clarity of the problem/opportunity and elicit business requirements
Coordinate vendor interactions and/or vendor resources as needed
Seek to expand knowledge and understanding of Financial Services trends, practices, and technologies on a continuous basis
Follow and promote use of industry best practices, standards and procedures
Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite. Identify risk-related issues needing escalation to management.
Promote an environment that supports diversity and reflects the M&T Bank brand
Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable
Complete other related duties as assigned
Education and Experience Required:
Combined minimum of 8 years’ higher education and/or work experience in systems design, management and/or architecture
Strong understanding of the system development and infrastructure lifecycle and architecture, vendor best practices, IT Service Management, and systems design
In-depth knowledge of SIEM technologies (e.g., Splunk, IBM QRadar, Sumo Logic, Securonix), including design, implementation, and administration
Strong understanding of security principles, threat landscape, and incident response methodologies
Experience with scripting and programming languages (e.g., Python, PowerShell) for automating security tasks and developing SIEM use cases
Familiarity with regulatory standards (e.g., PCI DSS, GDPR, SOX) and their impact on security controls within the banking sector
Proficient in analyzing security logs, network traffic, and system events to identify and respond to security incidents
Education and Experience Preferred:
Bachelor’s Degree in Computer Science or Computer Engineering
Minimum of 8 years’ professional experience in a technical engineering position involving infrastructure design technologies, data management and interchange, system design and/or development for complex applications
Professional certifications in information security and SIEM technologies, such as CISSP, GIAC, or Splunk certifications, are highly desirable
Ability to translate complex business and functional requirements into structured high quality implementations using any variety of industry standard approaches
Advanced technical skills
Advanced analytical skills
Advanced troubleshooting skills
Advanced problem-solving skills
Verifiable knowledge and advanced expertise in industry and/or vendor technologies
Able to meet with clients of varying levels to gather, document, and analyze system specifications and requirements, work closely with integrators, developers, and testers in the fast-paced environment
Ability to work independently and collaboratively with others in team environment
Ability to use effective facilitation skills and techniques to elicit and review requirements from a diverse range of stakeholders and group size
Understanding of how the people, processes and technology within an organization interact in relationships and patterns to create a feasible solution on projects of medium to high complexity
Excellent written and verbal communication skills
Effective influencing skills
Process-oriented
Logical thinker
Strong knowledge of server/client and virtual technologies
Ability to complete complex tasks with minimal supervision
Adaptable
Able to learn quickly in a rapid pace environment
We support our team members with generous benefits.
Competitive compensation
Health, welfare, and retirement benefits
401(k) match at 5%
Work-life balance and flexible work arrangements
Banking Officers start with 25 days PTO plus 12 paid holidays
40 hours paid volunteer hours per year
Much more. For details, see: M&T Benefits Overview
About M&T
M&T Bank is a Top 20 US bank holding company and one of the best performing and financial stable regional banks in the country, we offer our technology employees a wide range of performance-based career development opportunities. We have a strong commitment to our customers and the communities we serve, and we continue to grow with a focus on the future. So, when looking to advance your career, look to M&T. Grow with us.
#LI-JB3
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $110,635.01 - $184,391.68 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation. The range listed above corresponds to our national pay range for this role. The specific pay range applicable to you may vary based on your location.LocationAbilene, Kansas, United States of America ApplyJob Profile
Hybrid work schedule Not fully remote
Benefits/PerksCareer development Competitive compensation Flexible work from home Hybrid work Hybrid work schedule In-person collaboration Market-informed pay
Tasks- Collaborate on security incidents
- Coordinate vendor interactions
- Develop SIEM use cases
- Identify risk-related issues
- Implement and optimize SIEM solutions
- Lead SIEM design
- Mentor junior engineers
- Participate in incident response exercises
Agile Analytical Audit Collaboration Communication Compliance Cybersecurity Data Management Facilitation Financial Services GDPR Guidance Incident Response Infrastructure Architecture Integration IT Service Management Leadership Mentorship PCI DSS PowerShell Problem-solving Programming languages Python Regulatory Compliance Regulatory requirements Regulatory standards Risk Management Root Cause Analysis Security Controls Security information and event management SIEM Systems Design Technology solutions Technology Standards Troubleshooting Verbal Verbal communication
EducationBachelor Business Computer Science Cybersecurity Engineering Higher Education Technology
Certifications TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9