Full-Time

Lead Application Security Engineer

Posted on 1/15/2025

M&T Bank

M&T Bank

10,001+ employees

Full-service banking for individuals and businesses

Financial Services

Compensation Overview

$110.6k - $184.4kAnnually

Senior

Buffalo, NY, USA

Hybrid work model requiring 3 days per week in the office.

Category
Cybersecurity
IT & Security
Required Skills
PHP
Python
JavaScript
Ruby
Java
C#
Scala
Data Analysis
Requirements
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity or applicable discipline and a minimum of 5 years of relevant work experience.
  • Demonstrable experience developing and maintaining automation for product security tasks and defect identification.
  • Advanced knowledge with industry standards and frameworks such as OWASP, ISO 27001, GDPR, PCI DSS, and NIST.
  • Advanced experience with security testing tools and techniques and fixing vulnerabilities.
  • Strong background in cybersecurity, manual code review, static/dynamic code analysis, threat modeling, bug bounty research and vulnerability management.
  • Experience with at least 2-3 of the following programming languages – Java, C#, JavaScript, Python, PHP, Ruby, Scala.
  • Hands-on experience with product security tools and exploit tools and methods.
  • Hands-on experience with product security testing tools such as SAST, DAST, IAST, SCA, and SBOM as well as experience with DevOps technologies such as CI/CD pipelines, repos, etc.
  • Excellent communication and leadership skills.
  • Capable of working on multiple projects of a complex nature.
  • Excellent problem-solving skills to assist in issue resolution.
  • Detail-oriented with excellent verbal and written communication skills, with prior experience presenting to the target audience.
  • Excellent organizational, teamwork, and time management skills.
  • Strong vertical thinking skills.
  • Experience recommending and implementing security solutions.
  • Experience driving project milestones and delivery dates.
  • Proven mentoring and leadership capabilities.
Responsibilities
  • Collaborate with cross-functional teams to integrate security measures into the software development process including conducting code reviews, secure code guidance, threat modeling.
  • Stay up to date on emerging threats and vulnerabilities, and proactively recommend security enhancements.
  • Partner with engineering teams and provide guidance and support to developers on secure coding practices and security best practices.
  • Mentor product security engineers and DevSecOps professionals to ensure a strong security posture across all software development and deployments.
  • Assist in the development of software security processes, configuration of tools, and management of solutions to tactically address software security vulnerabilities.
  • Build and support high quality security documentation for product security best practices.
  • Utilize product security scanning tools to track, analyze, and manage vulnerabilities.
  • Develop analytics to evaluate and enhance the effectiveness of the vulnerability management program including, tools, technologies, policies.
  • Communicate effectively with all levels of organizational leadership, conveying complex technical concepts in a clear and concise manner.
Desired Qualifications
  • Cyber security certifications in the domain of product security or penetration testing (such as GWAPT, GCPEN, OSCP, CSSLP, CCSP).
  • Proven experience in software development including architecture review & secure coding.
  • Familiarity with mobile security testing.
  • Strong understanding of mainframe, web product architectures, security protocols, and encryption.
  • Familiarity with cloud security principles and practices.
  • Experience running a bug bounty program.
  • Knowledge of Cloud platforms such as AWS, GCP, Azure, Oracle.

M&T Bank provides a variety of banking services to individuals, small businesses, and larger enterprises. Its offerings include mortgage assistance programs, personal and business checking accounts, and mobile banking solutions. The bank primarily operates in the Northeastern and Mid-Atlantic regions of the United States, emphasizing community engagement and a customer-focused approach. M&T Bank's business model is based on traditional banking services such as loans, deposits, and investment products, generating revenue through interest income and service fees. A key aspect that sets M&T Bank apart from its competitors is its commitment to community involvement, which includes allowing employees to volunteer and supporting local organizations. The recent merger with United Bank, N.A. has further expanded its services and market presence.

Company Stage

IPO

Total Funding

N/A

Headquarters

Buffalo, New York

Founded

1993

Simplify Jobs

Simplify's Take

What believers are saying

  • M&T Bank's $1.5 billion senior notes offering strengthens its financial position.
  • Decreased prime rate may attract more borrowers, increasing loan volume.
  • Shannon Lazare's appointment as New Jersey Regional President enhances local community engagement.

What critics are saying

  • Competition from fintechs could erode M&T Bank's market share among tech-savvy customers.
  • Integration challenges from the United Bank merger may disrupt operations.
  • Decreased prime rate could reduce interest income, impacting profitability.

What makes M&T Bank unique

  • M&T Bank emphasizes community engagement through its charitable foundation and volunteer programs.
  • The bank offers a wide range of traditional and digital banking services.
  • Recent merger with United Bank, N.A. expands M&T's market reach and service offerings.

Help us improve and share your feedback! Did you find this helpful?

Benefits

401(k) Company Match

401(k) Retirement Plan

Flexible Work Hours

Hybrid Work Options

Paid Vacation

Paid Holidays

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account