Cybersecurity Regulatory Lead
$185,000–$200,000 year
On-siteNew York, United States
Job Summary
Lead and coordinate cybersecurity regulatory engagements for BBVA CIB USA, including examinations, supervisory reviews, regulatory inquiries, and follow-up activities. Partner across Cybersecurity, Technology, Risk, Compliance, Legal, Internal Audit, and business stakeholders to support regulatory and assurance activities, translating evolving cybersecurity regulatory requirements into actionable expectations. Coordinate internal audit engagements involving Information Security, including preparation, evidence collection, walkthroughs, responses, and remediation tracking, while supporting regulatory attestations, control assessments, and framework maturity reviews. Maintain oversight of cybersecurity compliance and control maturity by performing control mapping and gap assessments, developing regulatory readiness capabilities, and ensuring alignment with applicable regulations and industry frameworks. Own the maintenance and enhancement of Information Security policies and procedures, track and manage regulatory findings for timely closure, and prepare concise management reporting on examination status and remediation progress.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field
- 7+ years of progressive professional experience in cybersecurity, technology risk, information security risk management, regulatory engagement, IT audit, cybersecurity assurance, or related disciplines
- Experience managing or supporting regulatory examinations, supervisory reviews, internal audits, external audits, or independent cybersecurity assessments within a highly regulated environment
- Experience coordinating internal audit engagements where Information Security is in scope, including supporting cybersecurity control assessments, attestations, and evidence-based demonstrations of compliance and control maturity across the following regulations and frameworks: 23 NYCRR Part 500 SEC cybersecurity requirements NFA cybersecurity requirements FFIEC Guidelines DORA (Digital Operational Resilience Act) SWIFT Customer Security Controls Framework (CSCF) FedLine security requirements...
- Strong understanding of the U.S. financial-services regulatory environment and the cybersecurity expectations applicable to banks, broker-dealers, financial institutions, and critical financial infrastructure
- Ability to understand and challenge cybersecurity controls across areas such as identity and access management, privileged access, vulnerability management, security monitoring, incident response, network security, data protection, cloud security, third-party security, secure development, and technology resilience
- Excellent written and verbal communication skills, with demonstrated ability to prepare regulatory responses, audit materials, executive summaries, management presentations, and concise risk assessments
- Strong stakeholder-management skills and demonstrated ability to influence outcomes across Cybersecurity, Engineering, Technology, Risk, Compliance, Legal, Audit, and senior management without direct reporting authority
- Ability to manage multiple concurrent regulatory and audit engagements while maintaining strong attention to quality, deadlines, governance, and documentation
- Employment eligibility to work with BBVA in the U.S.
Desired Qualifications
- Relevant professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent cybersecurity, risk, or audit credentials
- Prior experience within a First Line of Defense cybersecurity or technology organization
- Spanish proficiency
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.