Lead Web Application Firewall Engineer
M&T Bank
_The Bank sponsors individuals for TN and H-1B transfers on a case by case basis. Please note that this position is not open to anyone on an F-1 student visa including those eligible for CPT/OPT or the Stem OPT extension._
_This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub._
**Overview:**
Responsible for designing, implementing, automating, and maintaining the Web Application Firewall (WAF) and Web Application and API Protection (WAAP) infrastructure and associated security policies to proactively protect and defend the M&T Bank network environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.
**Primary Responsibilities:**
+ Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources and develop proactive solutions to maintain or improve security posture.
+ Implement security policies to decrypt, inspect, protect, and defend web applications from external attack.
+ Work with application teams supporting the business to identify and fix issues related to Internet traffic flowing through the network perimeter security stack.
+ Support functions, systems, and processes critical to meet regulatory, legal, and risk mitigation requirements.
+ Lead testing efforts for systems and technology, coordinating with cross-functional teams and providing technical expertise in identifying and resolving issues.
+ Manage the automated deployment of security WAF and WAAP policies, ensuring smooth integration with existing infrastructure and minimal disruption.
+ Define and implement tuning methodologies for systems and technologies, using advanced analytical techniques to maximize efficiencies.
+ Develop and implement automation and orchestration of WAF and WAAP infrastructure to streamline security operations and response activities.
+ Lead collaboration efforts with Cybersecurity and Technology teams to effectively implement and maintain security solutions for the organization.
+ Lead improvement initiatives within Cybersecurity team, implementing best practices and optimizing processes to enhance security capabilities.
+ Actively partner with vendor to optimize security products and/or drive resolution of complex support issues.
+ Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
+ Promote an environment that supports diversity and reflects the M&T Bank brand.
+ Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
+ Complete other related duties as assigned.
**Scope of Responsibilities:**
+ Designs and implements security strategies, systems, policies, and procedures that proactively protect against cybersecurity threats and malicious activities targeting the Bank's systems and assets.
+ Partners primarily with individual contributors and leaders within Cybersecurity and Technology, occasionally senior leaders within Cybersecurity
+ Exercises judgement in selecting methods, techniques, and criteria in executing objectives. Exerts significant latitude in determining objective of assignment. Work is accomplished with limited direction.
+ Advanced ability to use multiple Cybersecurity tools, specific to function.
**Manager Responsibilities:**
No supervisory responsibilities.
**Education and Experience Required:**
+ Bachelor's degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experience
**Education and Experience Preferred:**
+ Advanced understanding of the security system development and infrastructure lifecycle and architecture, and systems design
+ Proven experience with the development and customization of tools utilized in assigned Cybersecurity function
+ Demonstrated ability to translate architecture into technical requirements
+ Proficient level of critical thinking and problem solving ability
+ Excellent communication and interpersonal skills
+ Experience partnering with leaders to design solutions to business needs
+ Proficient persuasive communication skills to gain buy-in of others
+ Strong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sources
+ Ability effectively serves in indirect leadership role
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $110,635.01 - $184,391.68 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.
**Location**
Buffalo, New York, United States of America
M&T Bank Corporation is an Equal Opportunity/Affirmative Action Employer, including disabilities and veterans.
Confirm your E-mail: Send Email
All Jobs from M&T Bank