Full-Time

Cybersecurity Regulatory Lead

Information Security

Updated on 8/23/2026

Deadline 12/31/26
Banco Bilbao Vizcaya Argentaria

Banco Bilbao Vizcaya Argentaria

Global banking and financial services

Compensation Overview

$185k - $200k/yr

+ Discretionary bonus

No H1B Sponsorship

New York, NY, USA

Hybrid

Hybrid work arrangement in the New York office.

Bachelor's

Category
IT & Security (1)
Legal & Compliance (1)
Required Skills
Incident Response
Cybersecurity
Vulnerability Analysis
Requirements
  • A bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field is required.
  • At least 7 years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines is required, preferably within banking or financial services.
  • Experience managing or supporting regulatory examinations, supervisory reviews, internal audits, external audits, or independent cybersecurity assessments in a highly regulated environment is required.
  • Experience coordinating internal audit engagements where Information Security is in scope is required.
  • Experience supporting cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity is required.
  • Strong understanding of the United States financial-services regulatory environment and cybersecurity expectations applicable to banks, broker-dealers, financial institutions, and critical financial infrastructure is required.
  • Ability to understand and challenge cybersecurity controls across identity and access management, privileged access, vulnerability management, security monitoring, incident response, network security, data protection, cloud security, third-party security, secure development, and technology resilience is required.
  • Ability to prepare regulatory responses, audit materials, executive summaries, management presentations, and concise risk assessments is required.
  • Ability to influence outcomes across Cybersecurity, Engineering, Technology, Risk, Compliance, Legal, Audit, and senior management without direct reporting authority is required.
  • Ability to manage multiple concurrent regulatory and audit engagements while maintaining quality, deadlines, governance, and documentation is required.
  • Ability to operate effectively in a global, multinational, and multicultural financial institution with continuous interaction across regions, time zones, and functional areas is required.
Responsibilities
  • Lead and coordinate cybersecurity regulatory engagements for BBVA Corporate & Investment Banking USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities.
  • Serve as the primary Information Security coordination point to ensure regulatory responses, evidence, and presentations are accurate, complete, and timely.
  • Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to translate evolving cybersecurity regulatory requirements into actionable expectations.
  • Coordinate Information Security internal audit engagements, including preparation, evidence collection, walkthroughs, responses, and remediation tracking.
  • Support regulatory attestations, control assessments, and framework maturity reviews using evidence-based validation.
  • Perform control mapping and gap assessments across regulatory requirements, internal policies, and security controls.
  • Develop regulatory readiness capabilities such as evidence repositories, control mappings, regulatory inventories, and reusable documentation.
  • Own and support the maintenance, periodic review, and enhancement of Information Security policies and procedures for BBVA Corporate & Investment Banking USA.
  • Coordinate adherence to BBVA Group Information Security policies and standards within the United States Corporate & Investment Banking environment.
  • Track and manage regulatory and audit findings, management actions, and remediation commitments through timely and sustainable closure.
  • Partner with control owners to embed regulatory requirements into effective and sustainable cybersecurity controls.
  • Review and challenge the quality and defensibility of regulatory and audit evidence and management responses before submission.
  • Identify recurring themes across engagements and recommend improvements to strengthen the cybersecurity control environment.
  • Prepare management reporting and executive updates on examinations, audit status, control maturity, and remediation progress.
  • Support interactions with regulators, auditors, and independent assessors, including walkthroughs, interviews, and control demonstrations.
Desired Qualifications
  • Relevant professional certifications such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Certified Information Systems Auditor, or equivalent cybersecurity, risk, or audit credentials are preferred.
  • Prior experience within a First Line of Defense cybersecurity or technology organization is strongly preferred, particularly involving interaction with regulators, Internal Audit, Compliance, or independent risk functions.
  • Spanish proficiency is a plus.
Banco Bilbao Vizcaya Argentaria

Banco Bilbao Vizcaya Argentaria

View

Banco Bilbao Vizcaya Argentaria, commonly known as BBVA, is a multinational financial services group offering retail, commercial and corporate banking. It provides accounts, payments, lending, mortgages, investment products and financial guidance for individuals and businesses, alongside services for institutional clients. BBVA combines physical banking networks with digital channels and operates across multiple international markets. Its business spans everyday financial needs, business financing, wealth management and transaction services within the regulated banking industry. Its workforce combines specialist delivery, customer support and business operations.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A