Principal Cybersecurity Infrastructure Engineer
This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week
Overview:
Responsible for designing, implementing, and optimizing enterprise security architectures, platforms, and frameworks that protect the organization's users, applications, data, and cloud services. Leads the development and enhancement of Security Service Edge (SSE) capabilities including Web/Cloud Proxy, Data Loss Prevention (DLP), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Enterprise Browser. Solves highly complex cybersecurity challenges while aligning security outcomes with business objectives, regulatory requirements, and evolving threat landscapes. Acts as a knowledge resource and mentor for less experienced engineers across multiple cybersecurity disciplines. Completes day-to-day engineering support activities and strategic transformation initiatives.
Primary Responsibilities:
- Partner with senior engineers and leadership to define enterprise SSE, Zero Trust, and data protection strategies that reduce organizational risk while supporting business transformation, cloud adoption, hybrid work, and AI enablement initiatives.
- Lead architecture, engineering, configuration, and deployment of enterprise security platforms including Web/Cloud Proxy, CASB, DLP, ZTNA, Enterprise Browser, and other security controls supporting secure access and data protection.
- Define testing methodologies, validation frameworks, and security effectiveness metrics to ensure comprehensive assessment of data protection technologies across the organization.
- Lead deployment efforts for complex systems and technologies, coordinating with cross-functional teams and providing technical oversight to ensure successful implementation.
- Establish tuning standards, operational baselines, and best practices for data protection policies, cloud access governance, email protection controls, browser security, and Zero Trust enforcement mechanisms.
- Lead automation initiatives utilizing APIs, orchestration platforms, AI-driven capabilities, and security workflows to improve operational efficiency, accelerate response times, and reduce manual effort.
- Design and implement comprehensive data protection strategies to identify, classify, govern, monitor, and protect sensitive data across endpoints, cloud services, collaboration platforms, email, and SaaS applications.
- Architect and enhance Zero Trust Network Access solutions that replace legacy network-centric security models with identity, device, application, and risk-aware access controls.
- Collaborate with stakeholders across Cybersecurity, Technology, Legal, Risk, Compliance, Data Governance, and Business Units to integrate security controls seamlessly into business processes and digital transformation initiatives.
- Drive continuous improvement across security platforms and engineering teams by evaluating emerging technologies, threat intelligence, industry trends, and regulatory requirements to improve Cybersecurity effectiveness.
- Maintain strategic vendor relationships for key security technologies, providing oversight for issue resolution, product roadmaps, and operational optimization.
- Advise leadership on security technology investments, budget planning, platform rationalization, and future-state architecture decisions supporting enterprise security objectives.
- Lead adoption and governance of AI security capabilities, ensuring visibility, risk management, policy enforcement, and secure integration of AI applications and services throughout the enterprise.
- Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues requiring escalation to management.
- Promote an environment that supports belonging and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit findings together with any issues raised by external regulators, as applicable.
- Complete other related duties as assigned.
Scope of Responsibilities:
- Designs and implements security architectures incorporating Web/Cloud Proxy, Data Loss Prevention, Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Enterprise Browser, and related capabilities to secure user access to applications, internet resources, and organizational data regardless of location.
- Designs and implements enterprise data protection strategies and technologies to prevent unauthorized access, transmission, exposure, or loss of sensitive information across endpoints, cloud environments, SaaS platforms, collaboration tools, email, and AI applications.
- Architects and manages data classification, labeling, information protection, insider risk management, data lifecycle management, compliance, and governance capabilities.
- Develops and implements enterprise Zero Trust strategies focused on continuous verification, least privilege access, segmentation, identity-based security, device trust, and risk-adaptive access control models.
- Designs and implements security controls, governance frameworks, monitoring, and risk management practices for enterprise AI platforms and services, including AI application discovery, data protection, regulatory compliance, and AI risk visibility.
- Designs and implements security controls and architectures protecting cloud infrastructure, SaaS applications, cloud workloads, and enterprise data from cybersecurity threats and malicious activities.
- Partners with leaders within Cybersecurity, Technology, Data Governance, Risk Management, and Executive Leadership across the organization.
- Exercises judgment in selecting methods, technologies, architectural patterns, and implementation approaches to achieve strategic security objectives. Operates with significant autonomy and serves as a trusted technical advisor on complex enterprise security initiatives.
- Recognized subject matter expert across multiple cybersecurity domains including SSE, Data Protection, Zero Trust Architecture, Cloud Security, and AI Security
Manager Responsibilities:
No supervisory responsibilities
Education and Experience Required:
- Bachelor's degree and a minimum of 7 years’ relevant work experience, or in lieu of a degree, a combined minimum of 11 years’ higher education and/or work experience
- Advanced understanding of Security Service Edge (SSE), Secure Web Gateway (SWG), CASB, ZTNA, Enterprise Browser, Data Protection, and Zero Trust Architecture principles.
- Expertise in designing enterprise-scale cloud security architectures across hybrid and multi-cloud environments.
- Expert knowledge of security architecture, infrastructure lifecycle management, vendor best practices, and enterprise systems design.
- Excellent ability to translate business, regulatory, and operational requirements into scalable security solutions and technical implementations.
- Advanced level of critical thinking, risk analysis, and problem solving.
- Excellent communication and interpersonal skills, effectively articulating complex technical concepts to executive, technical, risk, audit, and business audiences.
- Experience partnering with senior leaders to design and implement strategic cybersecurity solutions that support business objectives.
- Experience effectively collaborating with and influencing peers, stakeholders, and executive leadership.
- Demonstrated proficiency in cross-functional collaboration, decision-making, and organizational change management.
- Ability to effectively serve in an indirect leadership role while driving enterprise-wide security initiatives.
Education and Experience Preferred:
- Advanced ability to analyze large datasets, security telemetry, and operational metrics to identify trends and drive informed decision-making.
- Experience securing AI platforms, generative AI applications, and AI-enabled business processes using governance, monitoring, and AI security solutions.
- Develop and maintain multi-year technology roadmaps and strategic plans for assigned security platforms, ensuring alignment with enterprise architecture, cybersecurity strategy, and business priorities
- Design and implement security controls supporting regulatory and compliance requirements including NYS DFS, GLBA, FFIEC guidance, data privacy obligations, and internal risk management standards.
- Industry certifications such as CISSP, CCSP, GIAC, Microsoft Security Certifications, or equivalent preferred.
Location
Buffalo, New York, United States of AmericaRecommended Jobs
Bartender
Saint Denis is the newest wine bar concept by Golden Age Hospitality, the group behind The Nines, Bar Bianchi, Elvis, Deux Chats, Le Dive, Acme, and The Happiest Hour is slated to open this September…
Director of Student Support Services (TRIO)
Bargaining Unit: OPAP Grade: VII Salary: Exempt Application Deadline: Open Until Filled Position Overview: The Director of Student Services (trio) is a highly responsible administra…
Remote Client Support Representative - Travel
We are seeking a Remote Client Support Representative – Travel to assist clients throughout their travel journey. In this fully remote role, you will serve as a key point of contact for travelers, pr…
Senior eDiscovery Analytics Lead
Job Description Job Description Senior eDiscovery Analytics Lead Employment Type: Full-Time, Experienced Department: Legal As a Senior eDiscovery Analytics Lead for Contact Government Se…
FSO - Tech Cons - Platforms - P&C Insurance - Guidewire Digital - Technical Consultant - Manager
Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career where…
CRM & Digital Marketing Solution Architect
CRM & Digital Marketing Solution Architect PMOUNTJP00001238 ~ Hourly pay: $90/hr ~ Worksite: Leading digital streaming network (New York, NY 10036 - Onsite) ~ W2 Employment, Group Medical, Dent…
Part-Time Security Guard, Anna Gonzalez Apartments Supportive Housing
Job Description Job Description Who We Are: CAMBA is a community of staff, volunteers, clients, donors, neighbors and partners who work together to build an inclusive New York City, where all ch…
Business Development Representative - Industrial Sector
At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are…
Application Support
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our c…