BNY

Director, Technology Controls Management Framework

BNY  •  Pittsburgh, PA (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are seeking a future team member for the role of Director, Technology Controls Management Framework to join our Engineering Control Services team. This role is located in Pittsburgh, PA with consideration also given to candidates located in Lake Mary, FL

The Director, Technology Controls Management Framework is responsible for the stewardship, evolution, and continuous improvement of the Technology Controls Management Framework across the Technology organization.

Partnering with leaders across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, Enterprise Risk, Internal Audit, and enterprise governance functions, this role establishes the methodologies, governance practices, and engineering principles that enable technology controls to be designed, implemented, measured, and continuously improved in a consistent, risk-based manner.

While accountability for the design and operation of individual technology controls remains within the respective technology organizations, this role is responsible for defining the framework within which those controls are developed. This includes establishing common methodologies, governance standards, control design principles, measurement practices, and alignment with recognized industry frameworks to ensure Technology maintains a coherent, sustainable, and auditable control environment.

This is a highly collaborative leadership role requiring strong influence, systems thinking, and the ability to drive enterprise-wide consistency without direct ownership of the underlying technology organizations.

In this role, you’ll make an impact in the following ways:

  • Technology Controls Management Framework: Lead the evolution and maturity of the Technology Controls Management Framework, including governance model, taxonomy, lifecycle, and methodologies, while ensuring traceability across Technology risks, policies, standards, controls, evidence, testing, and control effectiveness measures. Maintain a framework that is practical, scalable, and responsive to evolving business, regulatory, and technology risk requirements.
  • Policy & Standards Governance: Author and govern centrally owned Technology policies, standards, methodologies, and supporting documentation, and provide oversight across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, and other Technology organizations. Ensure policies and standards translate into well-designed, measurable, and operationally effective controls.
  • Control Design & Engineering: Define enterprise expectations and minimum engineering standards for Technology control design, including automation, evidence, ownership, monitoring, testability, and measurable outcomes. Lead governance reviews of new and modified controls and drive simplification, standardization, and continuous improvement across the Technology control environment.
  • Control Effectiveness & Measurement: Establish methodologies and standards for measuring Technology control effectiveness, including KPIs, KCIs, KRIs, evidence collection, monitoring, testing, and control health reporting. Advance automation, observability, and data-driven measurement to improve control performance and reduce operational overhead.
  • Industry Alignment & Continuous Improvement: Align the Technology Controls Management Framework to leading industry frameworks including COBIT, NIST, ISO 27001, and other applicable standards. Conduct benchmarking and recommend strategic enhancements to strengthen the maturity, consistency, and effectiveness of the Technology control environment.
  • Governance Leadership & Partnership: Build strong partnerships with Technology leadership, Enterprise Risk, Compliance, Internal Audit, and enterprise governance organizations. Provide expertise on Technology governance, controls methodology, and control design, while supporting audit and regulatory responses through collaboration and practical problem solving.

To be successful in this role, we’re seeking the following:

Required Qualifications / Experience

  • 10+ years of progressively responsible experience in Technology Governance, Technology Risk, Information Security Governance, Controls Management, Operational Risk, or related disciplines.
  • Demonstrated experience designing, implementing, or maturing enterprise governance or controls frameworks.
  • Experience working within large, complex, highly regulated organizations.
  • Strong understanding of Technology controls across infrastructure, cybersecurity, software engineering, cloud platforms, data, and emerging technologies.
  • Experience working with Internal Audit, Enterprise Risk, regulators, and senior Technology leadership.

Preferred Qualifications

  • Experience with COBIT, NIST Cybersecurity Framework, ISO 27001, ITIL, or comparable governance frameworks.
  • Experience developing governance policies, standards, or enterprise methodologies.
  • Professional certifications such as CGEIT, CRISC, CISA, CISSP, or equivalent.
BNY

About BNY

We help make money work for the world — managing it, moving it and keeping it safe. As a leading global financial services company at the center of the world’s financial system, we touch nearly 20% of the world’s investable assets. Today we help over 90% of Fortune 100 companies and nearly all the top 100 banks globally access the money they need. For more than 240 years we have partnered alongside our clients to create solutions that benefit businesses, communities and people everywhere.

Follow BNY on Instagram & X: @BNYglobal

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
New York, NY
Year Founded
1784
Website
bny.com
Social Media