Director, Technology Controls Management Framework

BNY MellonPittsburgh, PA
Hybrid

About The Position

At BNY, our culture allows us to run our company better and enables employees’ growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide. Recognized as a top destination for innovators, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary. We are seeking a future team member for the role of Director, Technology Controls Management Framework to join our Engineering Control Services team. This role is located in Pittsburgh, PA with consideration also given to candidates located in Lake Mary, FL Position Summary The Director, Technology Controls Management Framework is responsible for the stewardship, evolution, and continuous improvement of the Technology Controls Management Framework across the Technology organization. Partnering with leaders across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, Enterprise Risk, Internal Audit, and enterprise governance functions, this role establishes the methodologies, governance practices, and engineering principles that enable technology controls to be designed, implemented, measured, and continuously improved in a consistent, risk-based manner. While accountability for the design and operation of individual technology controls remains within the respective technology organizations, this role is responsible for defining the framework within which those controls are developed. This includes establishing common methodologies, governance standards, control design principles, measurement practices, and alignment with recognized industry frameworks to ensure Technology maintains a coherent, sustainable, and auditable control environment. This is a highly collaborative leadership role requiring strong influence, systems thinking, and the ability to drive enterprise-wide consistency without direct ownership of the underlying technology organizations.

Requirements

  • 10+ years of progressively responsible experience in Technology Governance, Technology Risk, Information Security Governance, Controls Management, Operational Risk, or related disciplines.
  • Demonstrated experience designing, implementing, or maturing enterprise governance or controls frameworks.
  • Experience working within large, complex, highly regulated organizations.
  • Strong understanding of Technology controls across infrastructure, cybersecurity, software engineering, cloud platforms, data, and emerging technologies.
  • Experience working with Internal Audit, Enterprise Risk, regulators, and senior Technology leadership.

Nice To Haves

  • Experience with COBIT, NIST Cybersecurity Framework, ISO 27001, ITIL, or comparable governance frameworks.
  • Experience developing governance policies, standards, or enterprise methodologies.
  • Professional certifications such as CGEIT, CRISC, CISA, CISSP, or equivalent.

Responsibilities

  • Lead the evolution and maturity of the Technology Controls Management Framework, including governance model, taxonomy, lifecycle, and methodologies, while ensuring traceability across Technology risks, policies, standards, controls, evidence, testing, and control effectiveness measures.
  • Maintain a framework that is practical, scalable, and responsive to evolving business, regulatory, and technology risk requirements.
  • Author and govern centrally owned Technology policies, standards, methodologies, and supporting documentation, and provide oversight across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, and other Technology organizations.
  • Ensure policies and standards translate into well-designed, measurable, and operationally effective controls.
  • Define enterprise expectations and minimum engineering standards for Technology control design, including automation, evidence, ownership, monitoring, testability, and measurable outcomes.
  • Lead governance reviews of new and modified controls and drive simplification, standardization, and continuous improvement across the Technology control environment.
  • Establish methodologies and standards for measuring Technology control effectiveness, including KPIs, KCIs, KRIs, evidence collection, monitoring, testing, and control health reporting.
  • Advance automation, observability, and data-driven measurement to improve control performance and reduce operational overhead.
  • Align the Technology Controls Management Framework to leading industry frameworks including COBIT, NIST, ISO 27001, and other applicable standards.
  • Conduct benchmarking and recommend strategic enhancements to strengthen the maturity, consistency, and effectiveness of the Technology control environment.
  • Build strong partnerships with Technology leadership, Enterprise Risk, Compliance, Internal Audit, and enterprise governance organizations.
  • Provide expertise on Technology governance, controls methodology, and control design, while supporting audit and regulatory responses through collaboration and practical problem solving.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service