Senior Technology Governance & Control Analyst

TowneBank

Suffolk (VA)

On-site

USD 95,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

TowneBank is seeking a Senior Technology Governance & Control Analyst to independently develop and evaluate the bank's technology governance and control framework across IT, security, program management, and business units.

The role leads governance initiatives, performs first-line control testing, and assesses control design and operating effectiveness, driving risk-based improvements with cross-functional partnerships.

Qualifications

  • Five or more years of progressively responsible experience in technology governance and technology control structures.
  • Experience with control design, implementation, testing, and remediation within IT risk, information security, internal controls, or controls programs.
  • Strong policy and procedure writing skills; translate regulatory, audit, and tech requirements into clear operational guidance.

Responsibilities

  • Lead governance frameworks, policies, standards, and procedures; align with regulatory expectations and risk appetite.
  • Design, implement, and refine preventive, detective, and corrective controls across technology processes; document objectives, risk statements, and evidence requirements.
  • Plan and execute first-line testing of key technology controls; develop testing scripts, sampling, plans, and evidence standards.
  • Map technology risks and controls to FFIEC, NIST CSF, NIST SP 800-53, COBIT, ISO 27001 and internal policies; advise on remediation.
  • Support audits and examinations; prepare evidence packages and control inventories; assist in remediation tracking.
  • Develop governance metrics and dashboards showing testing results and remediation progress; ensure compliance with AML/BSA requirements.

Skills

IT governance
Policy writing
Stakeholder influence
Communication

Education

Bachelor's degree in IT/IS/Cybersecurity/Business Admin/Risk Mgmt

Tools

ServiceNow IRM/GRC
GRC platforms
Microsoft Office

Job description

Senior Technology Governance & Control Analyst

The Senior Technology Governance & Control Analyst is a senior individual contributor responsible for developing, maintaining, and independently evaluating TowneBank's technology governance and control structure. Serving as a first line of defense (1LOD) subject-matter resource, this role provides governance and control guidance across Information Technology, Information Security, Project Management, application owners, and business units. The analyst translates regulatory requirements, industry frameworks, risk considerations, and organizational policies into practical governance frameworks, standards, procedures, control designs, and testing programs.

Operating with a high degree of independence, the analyst leads assigned governance and control initiatives, performs first-line control testing, evaluates the design and operating effectiveness of technology controls, identifies systemic gaps, and recommends risk-based improvements. The role influences outcomes through technical expertise, analysis, and cross-functional partnership and does not include direct people-management responsibilities.

The good-faith compensation range for this role is expected to be $95,000.00 to $120,000.00 annually based on the role, market, internal equity, and candidate qualifications.

Governance, Policy & Procedure Management
  • Lead the development, maintenance, and periodic review of technology governance frameworks, policies, standards, procedures, and operational guidelines.
  • Evaluate governance documents for alignment with regulatory expectations, recognized industry frameworks, TowneBank's risk appetite, and organizational objectives.
  • Serve as a subject-matter resource to technology and business stakeholders on governance requirements, control expectations, policy interpretation, and documentation standards.
  • Maintain the governance document inventory, version control, approval workflows, ownership records, and evidence of required reviews.
  • Translate regulatory, risk, audit, and examination requirements into sustainable technology governance practices and operational procedures.
Control Design & Implementation
  • Lead the design, documentation, implementation, and ongoing refinement of preventive, detective, and corrective controls across technology processes.
  • Develop complete control documentation, including control objectives, risk statements, control descriptions, procedures, frequency, ownership, evidence requirements, systems of record, and escalation criteria.
  • Assess whether control design appropriately addresses identified technology risks and recommend enhancements when gaps or inefficiencies are identified.
  • Partner with control owners and technology teams to embed controls into operational processes while maintaining clear accountability and sustainable evidence practices.
  • Provide governance and control expertise for change management, the software development lifecycle, access management, vendor management, asset management, disaster recovery, data governance, and technology operations.
First Line Control Testing & Assurance
  • Independently plan and execute risk-based first-line testing of key technology controls to assess design and operating effectiveness.
  • Develop and maintain control testing scripts, sampling approaches, test plans, evidence standards, and documentation that support repeatable and defensible conclusions.
  • Evaluate the completeness, accuracy, relevance, and reliability of evidence supporting control execution.
  • Analyze control deficiencies, procedural gaps, recurring exceptions, and broader control‑environment themes to determine risk and root cause.
  • Document clear testing conclusions and communicate findings, risk implications, and recommended corrective actions to control owners and leadership.
  • Evaluate remediation plans, validate completed corrective actions, perform follow‑up testing, and track issues through sustainable closure.
Risk & Compliance Support
  • Lead or provide subject‑matter expertise for assigned technology risk assessments, control evaluations, and risk and control self‑assessments (RCSAs).
  • Map technology risks and controls to applicable FFIEC guidance, the NIST Cybersecurity Framework, NIST SP 800‑53, COBIT, ISO 27001, and internal policies and standards.
  • Evaluate the completeness and consistency of control mappings and identify opportunities to reduce gaps, duplication, or unsupported risk coverage.
  • Advise control owners on risk treatment, control enhancements, mitigation planning, and sustainable remediation approaches.
Audit & Examination Readiness
  • Support internal audit engagements, external audits, and regulatory examinations.
  • Prepare evidence packages, control inventories, and documentation repositories.
  • Assist in responding to auditor and examiner requests.
  • Support management action plan development and remediation tracking.
Reporting & Metrics
  • Develop governance metrics and control performance reporting.
  • Produce dashboards showing:
  • Testing results
  • Remediation progress
  • Adheres to applicable federal laws, rules, and regulations including those related to Anti‑Money Laundering (AML) and the Bank Secrecy Act (BSA).
  • Performs other duties as required or assigned which are reasonably within the scope of the duties in this job classification.
Minimum Required Skills & Competencies:
Education
  • Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Business Administration, Risk Management, or related field.
Experience
  • Five or more years of progressively responsible experience in technology governance and technology control structures, including direct experience with control design, implementation, documentation, testing, and issue remediation. Related experience in IT risk management, information security governance, internal controls, compliance, internal audit, or technology operations may complement-but not replace-substantive technology governance and control experience.
Knowledge & Skills
  • Advanced knowledge of technology governance operating models, technology control structures, and IT General Controls (ITGCs).
  • Demonstrated ability to design, document, implement, test, and improve controls across complex technology processes.
  • Strong knowledge of policy, standard, and procedure development and the relationship between governance requirements and operational execution.
  • Knowledge of technology risk assessment, control mapping, first‑line testing, issue management, and remediation validation methodologies.
  • Ability to interpret regulatory and audit requirements and apply them to technology governance and control practices.
  • Ability to independently lead complex assignments, exercise sound judgment, manage competing priorities, and influence outcomes without direct authority.
  • Strong written and verbal communication skills, including the ability to explain complex governance and control matters to technical and nontechnical audiences.
Experience with:
  • ServiceNow IRM/GRC
  • Governance, Risk & Compliance platforms
  • Microsoft Office Suite
  • Risk and control documentation
  • Control testing and evidence collection
Desired Skills & Competencies:
  • Experience serving as a senior individual contributor or subject‑matter expert for a technology governance, IT risk, or technology controls program.
  • Demonstrated experience establishing or maturing a technology governance framework and control structure across multiple technology domains.
  • Strong policy and procedure writing skills, with the ability to translate regulatory, audit, and technical requirements into clear operational guidance.
  • Experience performing risk assessments, control testing, evidence validation, and remediation follow‑up in a regulated environment.
  • Working knowledge of technology control frameworks and standards, including FFIEC guidance, the NIST Cybersecurity Framework, NIST SP 800‑53, COBIT, or ISO 27001.
  • Experience preparing documentation and evidence for internal audits, external audits, or regulatory examinations.
  • Strong written and verbal communication skills, including the ability to present findings and recommendations clearly to technical teams, business partners, management, and governance committees.
  • Demonstrated ability to lead complex work independently, provide constructive feedback, build collaborative relationships, and influence control owners and senior stakeholders without direct supervisory authority.
  • Experience using ServiceNow IRM/GRC or a comparable governance, risk, and compliance platform is preferred.
  • Experience in banking, financial services, or another highly regulated industry is preferred.
Physical Requirements:
  • Express or exchange ideas by means of the spoken word via email and verbally.
  • Exert up to 10 pounds of force occasionally, use your arms and legs, and sit most of the time.
  • Have close visual acuity to perform activities such as analyzing data, viewing a computer terminal, reading, and preparing documentation.
  • Not substantially exposed to adverse environmental conditions.
  • The physical demands described here are representative of those that must be met by an employee to successfully perform the essential responsibilities .

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Senior Technology Risk Analyst
Senior Technology Risk Analyst

Provident Bank • Woodbridge Township (NJ)

On-site
USD 70,000 - 100,000
Paid time-off (PTO)
Health and Wellness benefits
401(k) Retirement Plan
+2
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens Bank • Johnston (RI)

Hybrid
USD 90,000 - 120,000
Technology Governance and Controls Specialist
Technology Governance and Controls Specialist

IDB Bank • New York (NY)

Hybrid
USD 160,000 - 180,000
Technology Governance and Controls Specialist
Technology Governance and Controls Specialist

IDBNY • New York (NY)

Hybrid
USD 160,000 - 180,000
Annual bonus
Medical & dental
Retirement plan
+2
Compliance Assurance Analyst
Compliance Assurance Analyst

TowneBank • Suffolk (VA)

On-site
USD 58,000 - 75,000
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens • Johnston (RI)

Hybrid
USD 80,000 - 120,000
Career growth opportunities
Collaborative work environment
Director of Technology (46086)
Director of Technology (46086)

FlagshipKansas • Overland Park (KS)

On-site
USD 150,000 - 210,000
Director of Technology (46086)
Director of Technology (46086)

Landmark National Bank • Overland Park (KS)

On-site
USD 150,000 - 210,000
Corporate Compliance Assurance Manager
Corporate Compliance Assurance Manager

TowneBank • Suffolk (VA)

On-site
USD 95,000 - 120,000