1

Technology Risk Manager Jobs in Buffalo, NY (NOW HIRING)

The Insider Risk Team works cross-functionally to deter, identify, investigate and mitigate risks ... managing sensitive cases Strong candidates may also have * Experience working in the technology ...

Showing results 41-60

Technology Risk Manager information

See Buffalo, NY salary details

$49.9K

$108.1K

$164.7K

How much do technology risk manager jobs pay per year?

As of Sep 5, 2026, the average yearly pay for technology risk manager in Buffalo, NY is $108,060.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,200.00 and $125,000.00 per year, depending on experience, location, and employer.

What is a technology risk manager?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.

What are some common challenges technology risk managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are the key skills and qualifications needed to thrive as a technology risk manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities near Buffalo, NY are hiring for Technology Risk Manager jobs?

Cities near Buffalo, NY with the most Technology Risk Manager job openings:

Cybersecurity Senior Manager, Protection and Encryption Engineering

M&T Bank

Buffalo, NY • On-site

$107K - $145K/yr

Full-time

Posted 23 days ago


M&T Bank rating

7.8

Company rating: 7.8 out of 10

Based on 187 frontline employees who took The Breakroom Quiz

78th of 175 rated banks


Job description

Overview:
Manages the activities and strategic priorities of the Protection Engineering and Encryption Engineering Programs within Cybersecurity Infrastructure Engineering. Responsible for financial and human capital planning to ensure short- and long-term strategic efforts support and protect the Bank from internal and external cybersecurity threats.
Primary Responsibilities:
  • Drive the development and execution of comprehensive cybersecurity strategies for Web Application Firewall, Intrusion Prevention, and Encryption controls, ensuring alignment with overall cybersecurity vision and organizational needs.
  • Partner with Cyber senior leadership and Finance to direct business and financial resources effectively based on risk assessments and strategic priorities.
  • Monitor and review the effectiveness of risk measurement strategy, update assessments, and procedures in partnership with technology risk and enterprise risk teams and communicate risk status to senior management.
  • Lead strategic initiatives across Cybersecurity that drive automation, continuous improvement, and operational efficiencies, while maintaining or improving overall outcomes.
  • Establish and maintain incident response policies and procedures, ensuring they align with industry best practices and regulatory requirements.
  • Collaborate with engineering and architecture teams to select appropriate security technologies that align with overall technology roadmap and cybersecurity goals.
  • Leverage industry knowledge and expertise to inform best practices and policies, ensuring continued compliance with applicable laws and regulations.
  • May represent organization in industry forums and regulatory engagements to understand and address cybersecurity-related legal and regulatory requirements.
  • Create strong workforce plan to meet business needs, including (but not limited to) mentoring and coaching high potential team members, developing career paths and succession planning for key roles, identifying training needs and gaps, and establishing culture of knowledge sharing and collaboration.
  • Guide creation and maintenance of internal Cybersecurity training needs to deliver security awareness and training programs across the Bank.
  • Develop Cybersecurity strategy and programs that strategically meets the needs and addresses the challenges of the organization.
  • Partner with procurement and vendor management teams to assess vendor security controls, conduct due diligence, and negotiate appropriate security provisions in contracts.
  • Exercise usual authority of a manager concerning staffing, performance appraisals, promotions, salary recommendations, performance management, and terminations.
  • Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports belonging and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.
Scope of Responsibilities:
  • This role manages the following functions/teams within the Cybersecurity department: Protection Engineering, consisting of Web Application Firewall Engineers and Intrusion Prevention System Engineers and Encryption Engineering, consisting of an Encryption Manager and the Encryption Engineers that report to the Encryption Manager
  • Primary partners: CISO, CIO, Technology Directors, Cybersecurity Operations organization, Cybersecurity Infrastructure Engineering organization.
  • Stakeholders: Regulators, Technology team, and the Bank.
  • Work is accomplished with minimal direction; strategizes team imperatives in alignment with Bank imperatives.
  • This role may act as a lead Cybersecurity representative with Regulators.
  • Accountable for developing and executing budget for functions/teams they oversee.

Manager Responsibility:
Typically leads a team of 25 or more FTEs (directly leading managers, and indirectly individual contributors)
Education and Experience Required:
  • Bachelor's degree and a minimum of 9 years' relevant work experience, or in lieu of a degree, a combined minimum of 13 years' higher education and/or work experience.
  • Demonstrated expert knowledge of Cybersecurity principles.
  • Minimum of 8 years' work experience in/with the specific cybersecurity function.
  • Minimum 3 years' managerial experience
  • Expertise in Web Application Firewall and Intrusion Prevention System policy strategy and automation.
  • Expertise in SSL Certificate management, cipher management, and both symmetric and asymmetric encryption technologies and best practices.
  • Expertise in software engineering methodologies and general-purpose automation platforms

Education and Experience Preferred:
  • Eligibility to obtain a Top Secret/Sensitive Compartmented Information (TS/SCI) US Government Security Clearance.
  • Minimum of 5 years' managerial experience.
  • Proven ability to mentor and lead cybersecurity people leaders and teams of people.
  • Excellent communication skills.
  • Excellent interpersonal skills.
  • Proven ability to effectively convey message to technical and business leaders.
  • Experience effectively influencing senior leaders.
  • Proven experience strategically prioritizing across competing priorities and quickly changing landscape.
  • Experience in a highly regulated industry environment, including building and maintaining effective relationships with external stakeholders.
  • Advanced understanding of financial services regulations, compliance requirements, and risk management practices.
  • Experience translating a strategic business objective into strategic cyber plans, programs, and initiatives.
  • Expertise in Security Information and Event Management technologies and best practices.
  • Expertise in cybersecurity innovation and emerging technologies. .

#LI-JB3 #Hybrid
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $167,600.00 - $279,400.00 Annual (USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.
Location
Buffalo, New York, United States of America

What M&T Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom