Technology Governance and Controls Specialist

IDBNY

New York (NY)

Hybrid

USD 160,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Annual bonus
Medical insurance
Dental insurance
Vision plan
Retirement plan
Paid time off
Parental leave
Tuition reimbursement

Job summary

IDB New York (IDBNY) is seeking a Technology Governance and Controls Specialist to serve as a 1LoD control authority within Technology. You will own, execute, and continually improve the bank’s technology and cybersecurity governance framework while partnering with technology teams to identify, assess, and mitigate risks across infrastructure, cloud services, and data platforms.

The role drives control culture through risk assessments, control testing, issue remediation, and regulatory

Qualifications

  • Experience in technology risk, information security, IT governance, or internal controls.
  • Experience with cloud platforms, databases, networks, and security technologies.
  • Familiarity with NIST-CSF, NYDFS Part 500, GLBA, and related frameworks.

Responsibilities

  • Identify, assess, monitor, and mitigate technology and cybersecurity risks.
  • Own and enhance the Technology and Cybersecurity Risk and Control Framework.
  • Conduct RCSA activities including control mapping, testing, and remediation tracking.
  • Embed controls within processes, systems, and projects across the organization.
  • Lead risk and control reporting to management and governance committees.

Skills

1LoD technology risk
Governance
Risk assessment
Regulatory compliance
Stakeholder influence

Education

Bachelor’s degree in CS/IS/Cybersecurity

Tools

Archer or equivalent GRC

Job description

Technology Governance and Controls Specialist

Corporate Job Level: VP | New York, NY | Full-Time

Position Summary

The Technology Governance and Controls Specialist serves as a First Line of Defense (1LoD) control function within Technology. The role is responsible for the ownership, execution, and continuous improvement of the Bank’s technology and cybersecurity governance and control framework. This position partners closely with technology teams to identify, assess, manage, monitor, and mitigate technology and cybersecurity risks while supporting compliance with regulatory requirements and adherence to internal policies, standards, procedures, and control objectives. The role drives a strong control culture through risk and control self-assessments, control testing, issue remediation, metrics reporting, governance activities, and regulatory readiness.

Key Responsibilities
  • Serve as a First Line of Defense (1LoD) technology risk and controls subject matter expert responsible for identifying, assessing, managing, monitoring, and mitigating technology and cybersecurity risks across infrastructure, applications, cloud services, data platforms, and third-party technology providers.
  • Own, maintain, and continuously enhance the Bank’s Technology and Cybersecurity Risk and Control Framework in alignment with regulatory requirements, industry practices, and business objectives.
  • Coordinate and execute Risk and Control Self-Assessments (RCSA), including risk identification, control mapping, control testing, control effectiveness evaluations, issue identification, action plan development, remediation tracking, and reporting.
  • Partner with technology infrastructure, cybersecurity, application development, data, and business stakeholders to embed effective controls within processes, systems, projects, system changes, and operational activities.
  • Assess the design and operating effectiveness of technology and cybersecurity controls and drive timely remediation of identified gaps and control deficiencies.
  • Maintain and enhance technology and cybersecurity policies, standards, procedures, control inventories, and related governance documentation in the Bank’s system of record.
  • Develop, monitor, analyze, and report Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), control performance measures, trends, and other technology risk metrics to management and governance committees.
  • Perform technology and cybersecurity risk assessments for significant projects, strategic initiatives, cloud implementations, new or modified systems, and third-party service providers to confirm that risks are identified and controls are appropriately designed and implemented.
  • Manage technology-related issues, action plans, audit findings, regulatory observations, and control deficiencies through validation, remediation, and closure.
  • Coordinate and support internal audits, external audits, regulatory examinations, and independent reviews performed by the Second Line of Defense, including walkthroughs, evidence production, management responses, and remediation activities.
  • Build and maintain effective working relationships across technology, cybersecurity, enterprise risk, compliance, audit, and business teams while reinforcing First Line accountability for risk ownership and control performance.
  • Prepare clear, accurate, and timely technology risk, cybersecurity risk, control, and governance reporting for senior management, oversight committees, and executive leadership.
Qualifications
  • 10+ years of experience in Technology Risk, Information Security, IT Governance, Internal Controls, Technology Compliance, or related First Line of Defense functions, including experience with technology infrastructure and cybersecurity processes, risks, controls, and tools.
  • Bachelor’s degree in computer science, information systems, cybersecurity, or a related technical discipline, or equivalent professional experience.
  • Strong technical understanding of technology and cybersecurity risks across cloud platforms, applications, databases, operating systems, networks, infrastructure, and security technologies.
  • Hands-on experience designing, evaluating, implementing, and maturing technology risk and control environments aligned with the NIST Cybersecurity Framework (NIST-CSF), NYDFS Part 500, GLBA, and other industry and regulatory frameworks, including NIST SP 800-53, FFIEC guidance, CIS Controls, COBIT, ITIL, SOX, SOC 2, PCI DSS, and the ISO/IEC 27000 series.
  • Experience coordinating and executing RCSA programs, control assessments and testing, issue management, remediation initiatives, governance reporting, and regulatory readiness activities.
  • Experience configuring and using Governance, Risk, and Compliance (GRC) platforms such as Archer or an equivalent solution.
  • Demonstrated experience managing and reporting technology and cybersecurity projects, action plans, risks, and control-related deliverables.
  • Relevant security, technology risk, or audit certifications such as CISSP, CISM, CISA, CRISC, CEH, or an equivalent certification are preferred.
  • Demonstrated ability to influence stakeholders, promote accountability for risk ownership and control effectiveness, manage competing priorities, and meet deadlines with minimal supervision.
  • Excellent analytical, documentation, presentation, verbal communication, and written communication skills.

Compensation
The expected annual salary for this position is between $160,000 and $180,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as an individual’s skills and experience. In addition to base salary, our total rewards package also includes eligibility for an annual bonus, medical, pharmacy, dental, and vision plans, life and disability insurance, employee wellness program, retirement and savings plans with employer contributions, generous holiday and paid time off schedules, parental leave, and tuition reimbursement.
Additional Information
The Bank Will Make Reasonable Accommodations To The Following Employees To Allow Them To Perform The Essential Functions Of Their Position, Except Where Doing So Would Result In Undue Hardship To The Bank

  • Those with a known mental or physical disability.
  • Pregnant individuals and/or individuals with pregnancy or childbirth-related medical conditions.
  • Victims of domestic violence, sex offenses or stalking.
  • Employees with religious observance and practice obligations.

Any employee who believes he or she needs an accommodation for any of the above reasons should contact their supervisor or a member of Human Resources to request such an accommodation. In each case, the Bank will engage in a good faith written or oral dialogue concerning the individual’s accommodation needs; potential accommodations that may address the individual’s accommodation needs, including alternatives to a requested accommodation; and the difficulties that such potential accommodations may pose for the employer.
The Bank retains the ultimate discretion to choose the appropriate reasonable accommodation. Upon reaching a final determination at the conclusion of the cooperative dialogue, the Bank will provide the requesting individual with a written final determination identifying any accommodation granted or denied. In addition, the Bank will maintain any information regarding the employee’s request and status in the strictest confidence, except as requested by the employee, as required on a need-to-know basis or as otherwise required by law.
Disclaimer
The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.
All your information will be kept confidential according to EEO guidelines.
_ We are operating on a Hybrid schedule. _
Kindly review our Privacy Notice and GLBA Consumer Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Governance and Controls Specialist
Technology Governance and Controls Specialist

IDB Bank • New York (NY)

Hybrid
USD 160,000 - 180,000
Technology Governance and Controls Specialist
Technology Governance and Controls Specialist

IDBNY • New York

Hybrid
USD 160,000 - 180,000
Annual bonus
Medical & dental
Retirement plan
+2
Technology and Information Security Risk Specialist
Technology and Information Security Risk Specialist

IDBNY • New York

Hybrid
USD 160,000 - 180,000
Annual bonus
Medical coverage
Dental & vision
Technology and Information Security Risk Specialist
Technology and Information Security Risk Specialist

IDB Bank • New York (NY)

Hybrid
USD 160,000 - 180,000
Hybrid schedule
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Senior Technology Risk Analyst
Senior Technology Risk Analyst

Provident Bank • Woodbridge Township (NJ)

On-site
USD 70,000 - 100,000
Paid time-off (PTO)
Health and Wellness benefits
401(k) Retirement Plan
+2
Principal Technology and Cybersecurity Risk & Controls Specialist
Principal Technology and Cybersecurity Risk & Controls Specialist

M&T Bank • Buffalo (NY)

Hybrid
USD 124,000 - 206,000
Head of IT Audit
Head of IT Audit

IDBNY • New York

Hybrid
USD 200,000 - 250,000
Annual bonus eligibility
Health insurance
Retirement plan
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens Bank • Johnston (RI)

Hybrid
USD 90,000 - 120,000
Director, Wealth Technology Control Manager
Director, Wealth Technology Control Manager

BNY Mellon • New York (NY)

On-site
USD 130,000 - 210,000