Senior Director – Technology Governance and Regulatory Strategy

WTWShort Hills, NJ
$204,000 - $231,000Remote

About The Position

WTW is expanding its Technology Risk & Assurance (TRA) capability to strengthen technology governance, risk management, and regulatory readiness across the enterprise. TRA serves as an embedded risk and control function within Global Technology, partnering closely with management to support the effective identification, assessment, and management of technology risk while collaborating with Enterprise Risk Management and Internal Audit across WTW's three lines model. This is a high-visibility role with direct exposure to the CIO, regulators, and senior technology leadership. The right person will be a builder who brings deep regulatory expertise, sharp governance instincts, and the credibility to influence how technology risk is managed across the firm. This leader will help strengthen how the function's pillars work together, building more shared ownership across Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory.

Requirements

  • Deep regulatory relationships — Direct experience managing examiner relationships with regulators such as the Fed, SEC, NYDFS, or FCA, along with comparable regulatory bodies across other jurisdictions. Has sat across the table from regulators and knows how exams work.
  • Global regulatory breadth — Comfortable operating across a large, varied portfolio of regulatory and audit relationships spanning multiple countries and regulatory regimes simultaneously.
  • Policy and governance fluency — Has owned and evolved a control framework. Understands how to write policy that is both defensible to regulators and workable for technology teams.
  • Cybersecurity regulatory fluency — Working knowledge of cybersecurity regulatory regimes (e.g., NYDFS Cybersecurity Regulation, HIPAA, and comparable regimes across EMEA and the Middle East) and how they intersect with technology risk governance.
  • Demonstrated regulatory exam experience — Has coordinated evidence and response cycles for technology or cybersecurity regulatory examinations. Understands the exam readiness and response lifecycle.
  • Senior and credible — Capable of representing the function externally and influencing technology leadership. Comfortable in front of regulators, auditors, and senior stakeholders.
  • Collaborative — Has helped bring functions with overlapping mandates closer together, not just coordinated around the edges. Brings a point of view on how teams should share ownership of common work.
  • Builder mindset — The right person wants to shape something and leave a mark, not inherit a finished model.

Nice To Haves

  • DORA and international regulatory experience — Strong familiarity with DORA obligations and the broader EU regulatory landscape is a meaningful plus.

Responsibilities

  • Own the technology and cybersecurity risk policy architecture and lifecycle. Define, maintain, and evolve the control framework and standards across both domains. Ensure policies are right-sized, defensible, and benchmarked against peer practice and regulatory expectations.
  • Define and maintain the control taxonomy, library, and standards across technology and cybersecurity risk domains. Ensure the framework is designed for testability and aligned to regulatory requirements, partnering with the CISO organization on control ownership and testing.
  • Own the exception management process, connecting into the broader risk acceptance process where appropriate. Apply risk-based judgment to control deviations, inform policy updates based on emerging patterns, and maintain escalation authority for aging or high-risk exceptions.
  • Serve as the primary interface with regulators for all technology and cybersecurity examination activity across WTW's global regulatory footprint, spanning the Americas, Europe, the Middle East, and Asia-Pacific, including cyber-specific regulations such as the NYDFS Cybersecurity Regulation (23 NYCRR 500) and HIPAA.
  • Maintain inventory of applicable technology and cybersecurity obligations across relevant jurisdictions and legal entities, ensuring they are traceable to policies, standards, controls, accountable owners, and evidence. Own the governance of regulatory findings, commitments, and supervisory actions from initial response through validated closure, with clear executive ownership, credible remediation plans, appropriate evidence standards, timely escalation of delivery risk, and transparent reporting to senior governance forums.
  • Partner with the CISO organization to ensure cybersecurity regulatory obligations are reflected in policy, standards, and the control framework, and represent TRA in cybersecurity-focused regulatory exams and assessments.
  • Define and drive adoption of a clear operating model for how the organization responds to technology and cybersecurity regulatory obligations, establishing well-defined roles, responsibilities, escalation paths, and review processes so response efforts are coordinated rather than ad hoc.
  • Play an integral role in reshaping how Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory operate together, helping evolve routines, workflows, and handoffs so the three pillars function as a more connected team.

Benefits

  • Medical (including prescription coverage), Dental, Vision, Health Savings Account, Commuter Account, Health Care and Dependent Care Flexible Spending Accounts, Group Accident, Group Critical Illness, Life Insurance, AD&D, Group Legal, Identify Theft Protection, Wellbeing Program and Work/Life Resources (including Employee Assistance Program)
  • Paid Holidays, Annual Paid Time Off (includes paid state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave), Paid Time Off
  • Contributory Pension Plan and Savings Plan (401k). All Level 38 and more senior roles may also be eligible for non-qualified Deferred Compensation and Deferred Savings Plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service