US Cyber Regulatory CRI Profile Program Manager
Hybrid - Buffalo NY (Local candidates only)
6+ Months
Role Description
• Broad understanding of cybersecurity across Security Operations, engineering, technology, controls, and tooling, with the ability to translate technical topics into clear regulatory and executive-level messaging.
• Strong knowledge of IT (preferably cybersecurity) governance, risk management, and compliance, including experience assessing cyber regulatory compliance and supporting regulatory exams and inquiries.
• Demonstrated program management capability, with end-to-end ownership of time-bound, non-discretionary regulatory deliverables (e.g., CRI Profile assessment, GLBA reporting, NYDFS attestation support), including planning, execution, quality control, and submission readiness.
• Proven ability to develop and maintain repeatable, auditable operating models by documenting processes and building program artifacts (procedures, templates, guidance, training materials, trackers, and evidence repositories).
• Ability to analyze and interpret cybersecurity risk and control metrics (KPI/KRI/KCI), identify data discrepancies, drive root-cause analysis with stakeholders, and track remediation actions through to closure.
• Strong stakeholder management skills, including the ability to coordinate across 1LOD, 2LOD, CCO Tech, Group Cybersecurity, technology teams, control owners, and non-US ITSOs to deliver outcomes on schedule.
• Excellent written and verbal communication skills, with the ability to produce clear, concise, well-evidenced materials fit for senior management, the Board of Directors, and regulatory bodies.
• Ability to lead through influence, prioritize effectively across competing deadlines, and coordinate the tasking of others (including contractors or virtual team resources when required).
• Ability to provide responsive support for ad hoc regulatory requests, including rapid evidence gathering and issue resolution with appropriate sensitivity to the US regulatory environment.
• Proficiency with Microsoft tools (Word, Excel, PowerPoint, SharePoint, Power BI, Teams) and collaboration platforms (e.g., Confluence) to manage workspaces, reporting, and regulatory artifacts.
• Strong attention to detail and a continuous improvement mindset, proactively identifying opportunities to reduce cycle time, stakeholder friction, and execution risk year over year