Director, Wealth Technology Control Manager
We are seeking a future team member for this role to join our First Line Risk and Control team in NYC, NY.
Role Overview
The Wealth Technology Control Manager is accountable for the design, effectiveness, and continuous improvement of the technology control environment across BNY’s Wealth Management Engineering organization. As a senior first‑line leader, the director works closely with engineering, architecture, cybersecurity, Technology Risk, Compliance, and Internal Audit to ensure controls are embedded throughout the Software Development Lifecycle (SDLC), aligned with regulatory expectations, and supported by a culture of ownership and continuous improvement. The director provides clear, evidence‑based narratives to senior stakeholders, shapes the overall risk posture of Wealth Engineering, and ensures the control environment supports secure and resilient client experiences.
Role Responsibilities
- Partner with product and platform owners, architects, cybersecurity and engineering teams to perform detailed risk assessments and communicate clear findings and recommendations to governance forums.
- Assess and manage technology risks across platforms, applications, data, cloud services and third‑party integrations, identifying emerging threats, evaluating their potential impact, and defining robust mitigation strategies.
- Interpret and enforce BNY policies, standards and regulatory requirements, maintaining an informed understanding of Wealth Engineering’s architecture, operating model and cloud design principles to ensure correct control application and alignment.
- Construct, maintain and narrate technology control dashboards and key indicators for Wealth Engineering, presenting concise insights and risk themes to senior leadership and governance committees.
- Produce quarterly Technology Risk and Control Assessments for Wealth Engineering, providing a comprehensive view of risk posture, control effectiveness, resilience performance and alignment to enterprise and regulatory frameworks.
- Prioritize remediation of known risks, audit findings and control gaps, ensuring engineering teams perform thorough root‑cause analysis and implement changes that strengthen long‑term control effectiveness.
- Provide SME guidance on control design across SDLC, DevSecOps, identity and access management, secrets management, cloud security, vulnerability management, configuration management and operational resilience, strengthening risk awareness across engineering teams.
- Develop and maintain metrics, KRIs, KPIs and control health reporting, using data and trend analysis to support narratives, highlight areas of concern and guide strategic remediation activity.
- Oversee defect, vulnerability and control break management, providing trend analysis, explaining any breaches of SLA and improving structural processes to reduce recurrence and ageing items.
- Lead the issue‑management and policy deviation process, clearly articulating control weaknesses, providing business and technical justification, defining remediation plans and setting appropriate timelines before approval.
- Oversee Identity and Access Management controls for Wealth Engineering, ensuring standard tools and processes are used for attestations, provisioning, revocation, segregation of duties and secrets governance, and escalating any deviations where effectiveness is insufficient.
- Represent Wealth Engineering in all Line 1 and Line 2 Technology Risk engagements, demonstrating a clear understanding of the control environment and ensuring alignment to enterprise expectations and regulatory standards.
- Lead major control uplift and risk‑reduction initiatives such as cloud control enhancements, secure SDLC improvements, resilience strengthening and control automation, setting strategy, coordinating delivery and presenting progress to senior governance groups.
Experience Required
- Strong background in technology or engineering supported by a detailed understanding of modern software development, cloud‑native patterns and platform operations.
- Minimum of twelve to fifteen years of experience in technology risk, controls, cybersecurity or engineering leadership within a regulated financial services environment.
- Demonstrated expertise in performing and leading complex risk assessments that cover SDLC and DevSecOps practices, identity and access management, change and configuration management, vendor integrations, cloud patterns, vulnerability management and operational resilience.
- Strong understanding of regulatory standards relevant to Wealth and banking technology such as NIST CSF, ISO 27001 and ISO 27002, SOX, PCI and GDPR and the implications of these standards for modern engineering environments.
- Practical experience implementing and operating controls across cloud platforms, microservices, APIs, Kubernetes, CI/CD pipelines and secure software supply‑chain tooling, with strong communication skills to translate complex control concepts into clear and actionable guidance for senior stakeholders.
Compensation and Benefits
Base salary is expected to be between $130,000 and $210,000 per year at the commencement of employment. The salary is determined on an individualized basis and may include commission earnings, discretionary bonuses, short‑ and long‑term incentive packages, and company‑sponsored benefit programs. Benefit offerings include medical, dental, vision and basic life insurance, a 401(k) plan, paid vacation and sick time, and paid volunteer time. The position is at‑will.
BNY is an Equal Employment Opportunity/Affirmative Action Employer – Underrepresented racial and ethnic groups / Females / Individuals with Disabilities / Protected Veterans.