← Back to search
I

Technology Governance and Controls Specialist

IDBNY

$160,000 - $180,000 / year

1114 Avenue of the Americas, NYC, NY, 10036Full-timeOn-siteExpert
Apply

Sign up to Quick Apply with your profile.

Description

Technology Governance and Controls Specialist

Corporate Job Level: VP  |  New York, NY  |  Full-Time

 

Position Summary

The Technology Governance and Controls Specialist serves as a First Line of Defense (1LoD) control function within Technology. The role is responsible for the ownership, execution, and continuous improvement of the Bank's technology and cybersecurity governance and control framework. This position partners closely with technology teams to identify, assess, manage, monitor, and mitigate technology and cybersecurity risks while supporting compliance with regulatory requirements and adherence to internal policies, standards, procedures, and control objectives. The role drives a strong control culture through risk and control self-assessments, control testing, issue remediation, metrics reporting, governance activities, and regulatory readiness.

Key Responsibilities

  • Serve as a First Line of Defense (1LoD) technology risk and controls subject matter expert responsible for identifying, assessing, managing, monitoring, and mitigating technology and cybersecurity risks across infrastructure, applications, cloud services, data platforms, and third-party technology providers.
  • Own, maintain, and continuously enhance the Bank's Technology and Cybersecurity Risk and Control Framework in alignment with regulatory requirements, industry practices, and business objectives.
  • Coordinate and execute Risk and Control Self-Assessments (RCSA), including risk identification, control mapping, control testing, control effectiveness evaluations, issue identification, action plan development, remediation tracking, and reporting.
  • Partner with technology infrastructure, cybersecurity, application development, data, and business stakeholders to embed effective controls within processes, systems, projects, system changes, and operational activities.
  • Assess the design and operating effectiveness of technology and cybersecurity controls and drive timely remediation of identified gaps and control deficiencies.
  • Maintain and enhance technology and cybersecurity policies, standards, procedures, control inventories, and related governance documentation in the Bank's system of record.
  • Develop, monitor, analyze, and report Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), control performance measures, trends, and other technology risk metrics to management and governance committees.
  • Perform technology and cybersecurity risk assessments for significant projects, strategic initiatives, cloud implementations, new or modified systems, and third-party service providers to confirm that risks are identified and controls are appropriately designed and implemented.
  • Manage technology-related issues, action plans, audit findings, regulatory observations, and control deficiencies through validation, remediation, and closure.
  • Coordinate and support internal audits, external audits, regulatory examinations, and independent reviews performed by the Second Line of Defense, including walkthroughs, evidence production, management responses, and remediation activities.
  • Build and maintain effective working relationships across technology, cybersecurity, enterprise risk, compliance, audit, and business teams while reinforcing First Line accountability for risk ownership and control performance.
  • Prepare clear, accurate, and timely technology risk, cybersecurity risk, control, and governance reporting for senior management, oversight committees, and executive leadership.

Qualifications

  • 10+ years of experience in Technology Risk, Information Security, IT Governance, Internal Controls, Technology Compliance, or related First Line of Defense functions, including experience with technology infrastructure and cybersecurity processes, risks, controls, and tools.
  • Bachelor's degree in computer science, information systems, cybersecurity, or a related technical discipline, or equivalent professional experience.
  • Strong technical understanding of technology and cybersecurity risks across cloud platforms, applications, databases, operating systems, networks, infrastructure, and security technologies.
  • Hands-on experience designing, evaluating, implementing, and maturing technology risk and control environments aligned with the NIST Cybersecurity Framework (NIST-CSF), NYDFS Part 500, GLBA, and other industry and regulatory frameworks, including NIST SP 800-53, FFIEC guidance, CIS Controls, COBIT, ITIL, SOX, SOC 2, PCI DSS, and the ISO/IEC 27000 series.
  • Experience coordinating and executing RCSA programs, control assessments and testing, issue management, remediation initiatives, governance reporting, and regulatory readiness activities.
  • Experience configuring and using Governance, Risk, and Compliance (GRC) platforms such as Archer or an equivalent solution.
  • Demonstrated experience managing and reporting technology and cybersecurity projects, action plans, risks, and control-related deliverables.
  • Relevant security, technology risk, or audit certifications such as CISSP, CISM, CISA, CRISC, CEH, or an equivalent certification are preferred.
  • Demonstrated ability to influence stakeholders, promote accountability for risk ownership and control effectiveness, manage competing priorities, and meet deadlines with minimal supervision.
  • Excellent analytical, documentation, presentation, verbal communication, and written communication skills.

Compensation
The expected annual salary for this position is between $160,000 and $180,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as an individual’s skills and experience. In addition to base salary, our total rewards package also includes eligibility for an annual bonus, medical, pharmacy, dental, and vision plans, life and disability insurance, employee wellness program, retirement and savings plans with employer contributions, generous holiday and paid time off schedules, parental leave, and tuition reimbursement.
Additional Information
The Bank Will Make Reasonable Accommodations To The Following Employees To Allow Them To Perform The Essential Functions Of Their Position, Except Where Doing So Would Result In Undue Hardship To The Bank

  • Those with a known mental or physical disability.
  • Pregnant individuals and/or individuals with pregnancy or childbirth-related medical conditions.
  • Victims of domestic violence, sex offenses or stalking.
  • Employees with religious observance and practice obligations.

Any employee who believes he or she needs an accommodation for any of the above reasons should contact their supervisor or a member of Human Resources to request such an accommodation. In each case, the Bank will engage in a good faith written or oral dialogue concerning the individual’s accommodation needs; potential accommodations that may address the individual’s accommodation needs, including alternatives to a requested accommodation; and the difficulties that such potential accommodations may pose for the employer.
The Bank retains the ultimate discretion to choose the appropriate reasonable accommodation. Upon reaching a final determination at the conclusion of the cooperative dialogue, the Bank will provide the requesting individual with a written final determination identifying any accommodation granted or denied. In addition, the Bank will maintain any information regarding the employee’s request and status in the strictest confidence, except as requested by the employee, as required on a need-to-know basis or as otherwise required by law.
Disclaimer
The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.
All your information will be kept confidential according to EEO guidelines.
We are operating on a Hybrid schedule.
NO AGENCIES PLEASE.
IDB BANK, INCLUDING ITS SUBSIDIARIES AND DIVISIONS, PROVIDES EQUAL EMPLOYMENT OPPORTUNITIES TO ALL EMPLOYEES AND APPLICANTS FOR EMPLOYMENT WITHOUT REGARD TO RACE, COLOR, RELIGION, SEX, SEXUAL ORIENTATION, NATIONAL ORIGIN, AGE, DISABILITY, GENETIC STATUS, CITIZENSHIP STATUS, MARITAL STATUS, MILITARY OR VETERAN STATUS, CURRENT UNEMPLOYMENT OR ANY OTHER LEGALLY PROTECTED CATEGORY IN ACCORDANCE WITH APPLICABLE FEDERAL, STATE AND LOCAL LAW. NOTHING IN THIS SITE CONSTITUTES A PROMISE OR OFFER OF EMPLOYMENT.
Kindly review our Privacy Notice and GLBA Consumer Privacy Notice.