Director, IT Governance, Risk, and Controls, Corporate

Perella Weinberg PartnersNew York, NY
1d$160,000 - $220,000

About The Position

Perella Weinberg Partners is actively seeking a Director, IT Governance, Risk, and Controls (GRC) to join our Corporate IT function in New York. Responsibilities: Lead comprehensive third-party and vendor risk assessments globally, including AI/ML applications, with focus on data protection, model bias, regulatory compliance (US and EU), and operational resilience across jurisdictions Initiate and manage third-party due diligence questionnaires (DDQs) and responses; reviewing and identifying third-party risks Provide responses to client inquiries regarding cybersecurity and technology governance practices Support IT SOX compliance, identify control gaps, and develop remediation plans Develop and maintain IT policies and procedural documentation; Identify and resolve inconsistencies between policies and procedures, ensuing compliance with multi-jurisdictional requirements Serve as a liaison for internal and external audits across global IT operations, coordinating evidence gathering and managing relationships with IT auditors Conduct IT risk identification and analysis across applications, network and infrastructure, and technology systems spanning US and European operations, maintaining global IT risk registers and executive dashboards Design, execute, and document control testing procedures to validate IT controls (ITGCs) globally, including AI-specific control frameworks for model development, deployment, and monitoring Develop and implement technology and AI governance frameworks, policies, and risk assessment procedures that comply with US regulations (SEC, FINRA) and European requirements (EU AI Act, GDPR, DORA,) Monitor emerging AI and technology regulations from US regulators (SEC, FINR) and European authorities (FCA, ACPR, and AMF) and assess impact on firm's technology operations Prepare and deliver comprehensive IT and AI risk reports for executive leadership, board committees, and regulatory audiences across US and European jurisdictions Own and prepare IT quarterly metric dashboard reporting Establish risk criteria and approval processes for business units adopting new AI tools, accounting for regional regulatory differences and cross-border data flow requirements Track AI tool inventory across the firm's global footprint, develop AI-specific KRIs, and coordinate with European data protection officers on AI-related data processing activities Partner with Legal, Compliance, and technology teams across regions to address regulatory requirements. Qualifications: Bachelor’s Degree in Computer Science, Information Management or related field. MS or MBA a plus 7-10 years of progressive experience in IT risk management, IT audit, or IT compliance, with minimum 5 years in financial services (preferably investment banking or asset management) Minimum 3-5 years of experience working in a global capacity supporting both US and European operations with demonstrated experience navigating European regulatory frameworks (GDPR, DORA, FCA, AMF) Strong knowledge of US regulatory requirements and expectations (SEC, FINRA, Reg S-P) AND European regulations (GDPR, DORA, MIFID II, EU AI Act), including European data protection laws and cross-border data transfer mechanisms Proven experience assessing risks associated with AI/ML technologies, generative AI tools, and emerging technology implementations in regulated environments Deep understanding of IT risk management frameworks and industry standards (ISO 27001, NIST, COBIT) with track record managing vendor risk assessment programs across multiple jurisdictions Strong understanding of AI/ML concepts, AI governance frameworks (NIST AI RMF, EU AI Act), and associated risks including model bias, data quality, explainability, and security vulnerabilities Experience supporting internal and external audit engagements in both US and European contexts, with expertise in control testing methodologies and SOX IT compliance Exceptional analytical and communication skills with ability to articulate complex risk concepts to technical and non-technical audiences across cultures; fluency in English required Professional certifications such as PMP, CISA, CRISC, CISM, CISSP, or CIPP/E preferred; Big Four audit or consulting background with international exposure a plus Experienced with metric collection and presentation, data analytics and reconciliation, and advanced Excel and PowerPoint skills; Macros and charting a strong plus Cultural sensitivity, collaborative approach, and proven ability to manage multiple priorities across time zones with flexibility to accommodate European schedules Self-motivated with strong project management capabilities; willingness to travel as needed Intellectual curiosity and adaptability to stay current with rapidly evolving AI technologies and global regulatory landscape Proficiency in French is considered an asset; bilingual candidates are strongly encouraged to apply The annualized base salary for this position is $160,000 - $220,000. About Perella Weinberg Partners Perella Weinberg Partners is a leading global independent advisory firm, providing strategic and financial advice to a broad client base, including corporations, institutions, governments, sovereign wealth funds, and the financial sponsor community. The Firm offers a wide range of advisory services to clients in the most active industry sectors and global markets. With approximately 600 employees, PWP currently maintains offices in New York, Houston, London, Calgary, Chicago, Denver, Los Angeles, Paris, Munich, and San Francisco. For more information on Perella Weinberg Partners, please visit: http://www.pwpartners.com. Perella Weinberg Partners is an Equal Employment Opportunity (EEO) employer. It is the policy of the Firm to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status. Perella Weinberg is a leading global independent advisory firm, providing strategic and financial advice to a broad client base, including corporations, financial sponsors, governments, and sovereign wealth funds. The Firm offers a wide range of advisory services to clients in some of the most active industry sectors and global markets. With approximately 700 employees, Perella Weinberg currently maintains offices in New York, London, Houston, Los Angeles, San Francisco, Paris, Chicago, Munich, Palm Beach, Denver, Calgary, and Greenwich. Perella Weinberg Partners is an Equal Employment Opportunity (EEO) employer. It is the policy of the Firm to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status.

Requirements

  • Bachelor’s Degree in Computer Science, Information Management or related field. MS or MBA a plus
  • 7-10 years of progressive experience in IT risk management, IT audit, or IT compliance, with minimum 5 years in financial services (preferably investment banking or asset management)
  • Minimum 3-5 years of experience working in a global capacity supporting both US and European operations with demonstrated experience navigating European regulatory frameworks (GDPR, DORA, FCA, AMF)
  • Strong knowledge of US regulatory requirements and expectations (SEC, FINRA, Reg S-P) AND European regulations (GDPR, DORA, MIFID II, EU AI Act), including European data protection laws and cross-border data transfer mechanisms
  • Proven experience assessing risks associated with AI/ML technologies, generative AI tools, and emerging technology implementations in regulated environments
  • Deep understanding of IT risk management frameworks and industry standards (ISO 27001, NIST, COBIT) with track record managing vendor risk assessment programs across multiple jurisdictions
  • Strong understanding of AI/ML concepts, AI governance frameworks (NIST AI RMF, EU AI Act), and associated risks including model bias, data quality, explainability, and security vulnerabilities
  • Experience supporting internal and external audit engagements in both US and European contexts, with expertise in control testing methodologies and SOX IT compliance
  • Exceptional analytical and communication skills with ability to articulate complex risk concepts to technical and non-technical audiences across cultures; fluency in English required
  • Experienced with metric collection and presentation, data analytics and reconciliation, and advanced Excel and PowerPoint skills; Macros and charting a strong plus
  • Cultural sensitivity, collaborative approach, and proven ability to manage multiple priorities across time zones with flexibility to accommodate European schedules
  • Self-motivated with strong project management capabilities; willingness to travel as needed
  • Intellectual curiosity and adaptability to stay current with rapidly evolving AI technologies and global regulatory landscape

Nice To Haves

  • MS or MBA a plus
  • Professional certifications such as PMP, CISA, CRISC, CISM, CISSP, or CIPP/E preferred; Big Four audit or consulting background with international exposure a plus
  • Macros and charting a strong plus
  • Proficiency in French is considered an asset; bilingual candidates are strongly encouraged to apply

Responsibilities

  • Lead comprehensive third-party and vendor risk assessments globally, including AI/ML applications, with focus on data protection, model bias, regulatory compliance (US and EU), and operational resilience across jurisdictions
  • Initiate and manage third-party due diligence questionnaires (DDQs) and responses; reviewing and identifying third-party risks
  • Provide responses to client inquiries regarding cybersecurity and technology governance practices
  • Support IT SOX compliance, identify control gaps, and develop remediation plans
  • Develop and maintain IT policies and procedural documentation; Identify and resolve inconsistencies between policies and procedures, ensuing compliance with multi-jurisdictional requirements
  • Serve as a liaison for internal and external audits across global IT operations, coordinating evidence gathering and managing relationships with IT auditors
  • Conduct IT risk identification and analysis across applications, network and infrastructure, and technology systems spanning US and European operations, maintaining global IT risk registers and executive dashboards
  • Design, execute, and document control testing procedures to validate IT controls (ITGCs) globally, including AI-specific control frameworks for model development, deployment, and monitoring
  • Develop and implement technology and AI governance frameworks, policies, and risk assessment procedures that comply with US regulations (SEC, FINRA) and European requirements (EU AI Act, GDPR, DORA,)
  • Monitor emerging AI and technology regulations from US regulators (SEC, FINR) and European authorities (FCA, ACPR, and AMF) and assess impact on firm's technology operations
  • Prepare and deliver comprehensive IT and AI risk reports for executive leadership, board committees, and regulatory audiences across US and European jurisdictions
  • Own and prepare IT quarterly metric dashboard reporting
  • Establish risk criteria and approval processes for business units adopting new AI tools, accounting for regional regulatory differences and cross-border data flow requirements
  • Track AI tool inventory across the firm's global footprint, develop AI-specific KRIs, and coordinate with European data protection officers on AI-related data processing activities
  • Partner with Legal, Compliance, and technology teams across regions to address regulatory requirements.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service