← Back to jobs

Technology Governance and Controls Specialist

Location
New York City, NY
Work type
Full Time
Posted
2026-08-25

Job description

Position Summary
The Technology Governance and Controls Specialist serves as a First Line of Defense (1LoD) control function within Technology. The role is responsible for the ownership, execution, and continuous improvement of the Bank's technology and cybersecurity governance and control framework. This position partners closely with technology teams to identify, assess, manage, monitor, and mitigate technology and cybersecurity risks while supporting compliance with regulatory requirements and adherence to internal policies, standards, procedures, and control objectives. The role drives a strong control culture through risk and control self-assessments, control testing, issue remediation, metrics reporting, governance activities, and regulatory readiness.

Key Responsibilities
Serve as a First Line of Defense (1LoD) technology risk and controls subject matter expert responsible for identifying, assessing, managing, monitoring, and mitigating technology and cybersecurity risks across infrastructure, applications, cloud services, data platforms, and third-party technology providers.
Own, maintain, and continuously enhance the Bank's Technology and Cybersecurity Risk and Control Framework in alignment with regulatory requirements, industry practices, and business objectives.
Coordinate and execute Risk and Control Self-Assessments (RCSA), including risk identification, control mapping, control testing, control effectiveness evaluations, issue identification, action plan development, remediation tracking, and reporting.
Partner with technology infrastructure, cybersecurity, application development, data, and business stakeholders to embed effective controls within processes, systems, projects, system changes, and operational activities.
Assess the design and operating effectiveness of technology and cybersecurity controls and drive timely remediation of identified gaps and control deficiencies.
Maintain and enhance technology and cybersecurity policies, standards, procedures, control inventories, and related governance documentation in the Bank's system of record.
Develop, monitor, analyze, and report Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), control performance measures, trends, and other technology risk metrics to management and governance committees.
Perform technology and cybersecurity risk assessments for significant projects, strategic initiatives, cloud implementations, new or modified systems, and third-party service providers to confirm that risks are identified and controls are appropriately designed and implemented.
Manage technology-related issues, action plans, audit findings, regulatory observations, and control deficiencies through validation, remediation, and closure.
Coordinate and support internal audits, external audits, regulatory examinations, and independent reviews performed by the Second Line of Defense, including walkthroughs, evidence production, management responses, and remediation activities.
Build and maintain effective working relationships across technology, cybersecurity, enterprise risk, compliance, audit, and business teams while reinforcing First Line accountability for risk ownership and control performance.
Prepare clear, accurate, and timely technology risk, cybersecurity risk, control, and governance reporting for senior management, oversight committees, and executive leadership.

Qualifications
10+ years of experience in Technology Risk, Information Security, IT Governance, Internal Controls, Technology Compliance, or related First Line of Defense functions, including experience with technology infrastructure and cybersecurity processes, risks, controls, and tools.
Bachelor's degree in computer science, information systems, cybersecurity, or a related technical discipline, or equivalent professional experience.
Strong technical understanding of technology and cybersecurity risks across cloud platforms, applications, databases, operating systems, networks, infrastructure, and security technologies.
Hands-on experience designing, evaluating, implementing, and maturing technology risk and control environments aligned with the NIST Cybersecurity Framework (NIST-CSF), NYDFS Part 500, GLBA, and other industry and regulatory frameworks, including NIST SP 800-53, FFIEC guidance, CIS Controls, COBIT, ITIL, SOX, SOC 2, PCI DSS, and the ISO/IEC 27000 series.
Experience coordinating and executing RCSA programs, control assessments and testing, issue management, remediation initiatives, governance reporting, and regulatory readiness activities.
Experience configuring and using Governance, Risk, and Compliance (GRC) platforms such as Archer or an equivalent solution.
Demonstrated experience managing and reporting technology and cybersecurity projects, action plans, risks, and control-related deliverables.
Relevant security, technology risk, or audit certifications such as CISSP, CISM, CISA, CRISC, CEH, or an equivalent certification are preferred.
Demonstrated ability to influence stakeholders, promote accountability for risk ownership and control effectiveness, manage competing priorities, and meet deadlines with minimal supervision.
Excellent analytical, documentation, presentation, verbal communication, and written communication skills.

Original source