Senior Director – Technology Governance & Regulatory Strategy

Willis Towers Watson

Northern (KY)

Hybrid

USD 204,000 - 231,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health and Welfare Benefits
Leave Benefits
Retirement Benefits

Job summary

Willis Towers Watson seeks a senior leader to shape technology risk governance across the enterprise. You will own policy architecture, risk controls, and regulatory engagements, influencing senior technology leadership and external regulators.

The role offers exposure to global regulatory exams, a large-scale risk program, and opportunities to align technology governance with regulatory expectations in a major professional services firm.

Qualifications

  • Direct experience managing regulator exami­nation relationships and regulatory inquiries.

Responsibilities

  • Own technology and cybersecurity risk policy architecture and lifecycle.
  • Define and maintain the control taxonomy, library, and standards.
  • Manage exception processes with risk-based judgement.
  • Serve as primary interface with regulators for exams and assessments.
  • Maintain inventory of obligations across jurisdictions and ensure traceability to policies.
  • Lead operating model definition for regulatory response and escalation paths.
  • Foster cross-pillar collaboration across governance, controls, and risk operations.

Skills

Regulatory relationships
Global regulatory breadth
Policy & governance fluency
DORA/regulatory exposure
Cybersecurity regulation knowledge
Regulatory exam experience
Senior credibility
Cross-functional collaboration
Builder mindset

Job description

Description

WTW is expanding its Technology Risk & Assurance (TRA) capability to strengthen technology governance, risk management, and regulatory readiness across the enterprise. TRA serves as an embedded risk and control function within Global Technology, partnering closely with management to support the effective identification, assessment, and management of technology risk while collaborating with Enterprise Risk Management and Internal Audit across WTW's three lines model.

This is a high-visibility role with direct exposure to the CIO, regulators, and senior technology leadership. The right person will be a builder who brings deep regulatory expertise, sharp governance instincts, and the credibility to influence how technology risk is managed across the firm.

This leader will help strengthen how the function's pillars work together, building more shared ownership across Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory.

WHAT YOU WILL OWN
  • Policy & Standards —Own the technology and cybersecurity risk policy architecture and lifecycle. Define, maintain, and evolve the control framework and standards across both domains. Ensure policies are right-sized, defensible, and benchmarked against peer practice and regulatory expectations.

  • Control Framework —Define and maintain the control taxonomy, library, and standards across technology and cybersecurity risk domains. Ensure the framework is designed for testability and aligned to regulatory requirements, partnering with the CISO organization on control ownership and testing.

  • Exception Management —Own the exception management process, connecting into the broader risk acceptance process where appropriate. Apply risk-based judgment to control deviations, inform policy updates based on emerging patterns, and maintain escalation authority for aging or high-risk exceptions.

  • Regulatory Engagement — Serve as the primary interface with regulators for all technology and cybersecurity examination activity across WTW's global regulatory footprint, spanning the Americas, Europe, the Middle East, and Asia-Pacific, including cyber-specific regulations such as the NYDFS Cybersecurity Regulation (23 NYCRR 500) and HIPAA.

  • Regulatory Obligations, Findings & Remediation — Maintain inventory of applicable technology and cybersecurity obligations across relevant jurisdictions and legal entities, ensuring they are traceable to policies, standards, controls, accountable owners, and evidence. Own the governance of regulatory findings, commitments, and supervisory actions from initial response through validated closure, with clear executive ownership, credible remediation plans, appropriate evidence standards, timely escalation of delivery risk, and transparent reporting to senior governance forums.

  • Cybersecurity Regulatory Alignment —Partner with the CISO organization to ensure cybersecurity regulatory obligations are reflected in policy, standards, and the control framework, and represent TRA in cybersecurity-focused regulatory exams and assessments.

  • Operating Model Definition —Define and drive adoption of a clear operating model for how the organization responds to technology and cybersecurity regulatory obligations, establishing well-defined roles, responsibilities, escalation paths, and review processes so response efforts are coordinated rather than ad hoc.

  • Cross-Pillar Collaboration —Play an integral role in reshaping how Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory operate together, helping evolve routines, workflows, and handoffs so the three pillars function as a more connected team.

WHAT YOU WILL DO IN THE FIRST 90 DAYS
  • Establish examiner relationships and get current on open regulatory items, including cybersecurity-related exams

  • Assess the current operating model for technology and cybersecurity regulatory response, and begin clarifying roles, ownership, and escalation paths where they're unclear

  • Establish a working cadence with the CISO organization on cybersecurity policy and control alignment

  • Begin benchmarking the existing policy and control framework against regulatory expectations

  • Build working relationships with TRA peers and colleagues on shared workflows

  • Validate scope and priorities with the Head of Technology Risk & Assurance

Qualifications
WHAT WE ARE LOOKING FOR
  • Deep regulatory relationships —Direct experience managing examiner relationships with regulators such as the Fed, SEC, NYDFS, or FCA, along with comparable regulatory bodies across other jurisdictions. Has sat across the table from regulators and knows how exams work.

  • Global regulatory breadth— Comfortable operating across a large, varied portfolio of regulatory and audit relationships spanning multiple countries and regulatory regimes simultaneously.

  • Policy and governance fluency —Has owned and evolved a control framework. Understands how to write policy that is both defensible to regulators and workable for technology teams.

  • DORA and international regulatory experience —Strong familiarity with DORA obligations and the broader EU regulatory landscape is a meaningful plus.

  • Cybersecurity regulatory fluency —Working knowledge of cybersecurity regulatory regimes (e.g., NYDFS Cybersecurity Regulation, HIPAA, and comparable regimes across EMEA and the Middle East) and how they intersect with technology risk governance.

  • Demonstrated regulatory exam experience —Has coordinated evidence and response cycles for technology or cybersecurity regulatory examinations. Understands the exam readiness and response lifecycle.

  • Senior and credible —Capable of representing the function externally and influencing technology leadership. Comfortable in front of regulators, auditors, and senior stakeholders.

  • Collaborative —Has helped bring functions with overlapping mandates closer together, not just coordinated around the edges. Brings a point of view on how teams should share ownership of common work.

  • Builder mindset —The right person wants to shape something and leave a mark, not inherit a finished model.

HOW THIS ROLE LEADS

This role is expected to set clear direction and build trust with regulators, auditors, and technology and cybersecurity leadership; lead inclusively across a broad network of partners spanning Control Functions, Technology, Cybersecurity, and Operational Resilience; and continuously sharpen the function's practice as regulatory and cybersecurity expectations evolve.

WHY THIS ROLE

This is a rare opportunity to join a function at the moment of transformation and leave a lasting mark on how technology risk is governed at a major global professional services firm. The function has CIO

This position can be based in a major U.S. Market and is open to remote/virtual work.

This position will remain posted for a minimum of three business days from the date posted or until sufficient/appropriate candidate slate has been identified.

Compensation and Benefits

Benefits information for this position are being included in accordance with requirements of various state/local pay transparency legislation. Please note that salaries may vary for different individuals in the same role based on several factors, including but not limited to location of the role, individual competencies, education/professional certifications, qualifications/experience, performance in the role and potential for revenue generation (Producer roles only).

Compensation

The salary compensation range being offered for this role is $204,000 to $231,000.

This role is also eligible for an annual short-term incentive bonus.

Company Benefits:

WTW provides a competitive benefit package which includes the following (eligibility requirements apply):

  • Health and Welfare Benefits:Medical (including prescription coverage), Dental, Vision, Health Savings Account, Commuter Account, Health Care and Dependent Care Flexible Spending Accounts, Group Accident, Group Critical Illness, Life Insurance, AD&D, Group Legal, Identify Theft Protection, Wellbeing Program and Work/Life Resources (including Employee Assistance Program)
  • Leave Benefits:Paid Holidays, Annual Paid Time Off (includes paid state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave),
  • Retirement Benefits:Contributory Pension Plan and Savings Plan (401k). All Level 38 and more senior roles may also be eligible for non-qualified Deferred Compensation and Deferred Savings Plans

Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles County Fair Chance Ordinance for Employers, we will consider for employment qualified applicants with arrest and conviction records.

EOE, including disability/vets
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director – Technology Governance and Regulatory Strategy
Senior Director – Technology Governance and Regulatory Strategy

Willis Towers Watson • Short Hills (NJ), Northern (KY)

Hybrid
USD 204,000 - 231,000
Health and welfare benefits
Paid time off
Retirement plan (401k)
Global Client Advocate
Global Client Advocate

Willis Towers Watson • Glen Allen (VA)

Hybrid
USD 300,000 - 350,000
Health and Welfare Benefits
Paid Holidays & PTO
401(k) Savings Plan
Senior Security Solutions Consultant - Cyber Risk and Strategy
Senior Security Solutions Consultant - Cyber Risk and Strategy

World Wide Technology • New Home (MO)

Hybrid
USD 147,000 - 185,000
Health and Wellbeing
401k Plan with Company Matching
Paid Time Off
+4
Lead Technology Architect
Lead Technology Architect

Willis Towers Watson • Chicago (IL), Northern (KY)

Hybrid
USD 160,000 - 210,000
Health benefits
Dental & Vision options
401k plan
Senior Application Security Engineer
Senior Application Security Engineer

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 116,000 - 145,000
Health and Wellbeing
401k with Company Matching
Paid Time Off
+2
Principal Cybersecurity Architect – Identity, IAM & Zero Trust
Principal Cybersecurity Architect – Identity, IAM & Zero Trust

World Wide Technology • Maryland Heights (MO)

On-site
USD 150,000 - 226,000
Health benefits
401(k) with company matching
Paid time off
+1
Cyber Risk Director
Cyber Risk Director

Candidate Experience site • New York (NY)

Hybrid
USD 250,000 - 280,000
Health Insurance
Hybrid Environment
401(k) Savings Plan
+1
Principal Cybersecurity Architect – Identity, IAM & Zero Trust
Principal Cybersecurity Architect – Identity, IAM & Zero Trust

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 160,000 - 200,000
Health & Wellness benefits
Profit Sharing
401k with company matching
+2
Senior Application Security Engineer
Senior Application Security Engineer

World Wide Technology • Maryland Heights (MO)

On-site
USD 116,000 - 145,000
Health insurance
401k with company matching
Paid time off
+3
WAF Engineering Lead
WAF Engineering Lead

WTW • New York (NY)

On-site
USD 120,000 - 160,000
Health benefits
Pension plan
401(k)