Technical Policy Program Director

Early Warning®New York, NY
$221,000 - $276,000Hybrid

About The Position

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Overall Purpose The Director, Technical Policy Program Oversight, will support the Cybersecurity and Technology Risk Oversight Center of Excellence (CTRO-COE) Program within the Second Line of Defense (2LOD). This role is responsible for overseeing the 2LOD Policy Program.

Requirements

  • Education and/or experience typically obtained through completion of a Bachelor’s degree or equivalent.
  • Minimum of 10+ years of governance, risk and compliance management experience, preferably in financial services or other highly regulated industries.
  • Familiarity with frameworks, regulations, and standards, including but not limited to: Cyber Risk Institute Profile, ISO Standards, PCI DSS, NIST 800-53a, SIG, Federal Financial Examination Council (FFIEC) handbooks, Service Organization Controls in accordance with SSAE No.18, GLBA, NYDFS, and FCRA.
  • Required certification in one of CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent or ability to sit for one of the certifications within the first 12 months of hire.
  • Exceptional communication skills with ability to synthesize and present complex risk issues clearly and persuasively.
  • Creative problem solver who also demonstrates strong attention to detail and efficiency.
  • Ability to drive change in a dynamic business environment.
  • Strong relationship building skills.
  • Excellent organizational, analytical and project management skills.
  • Background and drug screen.

Nice To Haves

  • Multiple certifications in any of the following: CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent.
  • Experience with security-related technologies including Identity and Access Management tools, single-sign-on technologies, and technology systems.
  • Cybersecurity and technology consulting or advisory background at a top firm (Deloitte, PwC, Accenture, or equivalent).
  • Additional related education and/or experience preferred.

Responsibilities

  • Center of Excellence Operations Define and operationalize the enterprise second-line policy oversight strategy, establishing a scalable center-of-excellence model that standardizes governance, accountability, and execution across cybersecurity and technology risk domains.
  • Drive integration of first- and second-line policy oversight activities to ensure consistent risk interpretation, control expectations, and enterprise-wide coverage.
  • Establish executive-level reporting and metrics that provide transparency into policy health, adoption, exceptions, and emerging risk themes.
  • Lead continuous improvement initiatives to mature the 2LOD policy governance framework, incorporating lessons learned, regulatory developments, and industry leading practices.
  • Policy Program Facilitation, Architecture & Oversight Own the end-to-end enterprise lifecycle governance for all technology and security policies, establishing standards for drafting, review, approval, exception management, publication, and attestation.
  • Architect and maintain a cohesive, risk-aligned policy framework that clearly delineates policies, standards, procedures, and technical controls across lines of defense.
  • Provide strategic direction to ensure policy content reflects evolving regulatory requirements and industry frameworks, including PCI DSS, NIST 800-53a, SIG, FFIEC handbooks, SSAE No.18, GLBA, NYDFS, and FCRA.
  • Establish governance forums and decision-making structures to ensure appropriate challenge, approval authority, and accountability at the executive level.
  • Oversee policy rationalization efforts to eliminate redundancy, resolve ambiguity, and enhance clarity and enforceability across the enterprise.
  • Control Framework Mapping & Harmonization Sponsor and govern a centralized enterprise control catalog that maps policy requirements to regulatory and industry frameworks, ensuring traceability and audit defensibility.
  • Drive harmonization across overlapping regulatory frameworks to reduce complexity and streamline control expectations for first-line execution.
  • Provide strategic oversight of control alignment efforts, ensuring consistency between documented requirements, implemented controls, and risk assessments.
  • Technical Subject Matter Collaboration Provide executive-level oversight and strategic direction in partnership with domain leaders across cybersecurity and technology functions including Cloud, IAM, DevSecOps, and Threat Management.
  • Translate emerging technical, regulatory, and business risks into forward-looking policy strategy and governance enhancements.
  • Oversee second-line assessments focused on policy design adequacy and alignment with operational execution, escalating systemic issues to senior leadership as appropriate.
  • Evaluate new technologies, strategic initiatives, and business ventures for policy impact and ensure proactive governance adaptation.
  • Advisory & Partnership Serve as a senior trusted advisor to first-line executives and functional leaders, providing balanced challenge and credible oversight while enabling strategic business outcomes.
  • Influence enterprise risk governance by collaborating with Enterprise Risk, Operational Risk, Enterprise Compliance, Technology & Security Risk, and Legal to ensure an integrated and consistent approach to policy oversight.
  • Establish clear accountability frameworks that reinforce first-line ownership of risk and control execution.
  • Represent the 2LOD policy program in executive forums, regulatory discussions, and enterprise governance committees as needed.

Benefits

  • Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service