Technical Policy Program Director

Early Warning ServicesNew York City, NY
Hybrid

About The Position

The Technical Policy Program Director will support the Cybersecurity and Technology Risk Oversight Center of Excellence (CTRO-COE) Program within the Second Line of Defense (2LOD). This role is responsible for overseeing the 2LOD Policy Program. The role defines and operationalizes the enterprise second-line policy oversight strategy, establishing a scalable center-of-excellence model that standardizes governance, accountability, and execution across cybersecurity and technology risk domains. It drives integration of first- and second-line policy oversight activities to ensure consistent risk interpretation, control expectations, and enterprise-wide coverage. The role also establishes executive-level reporting and metrics that provide transparency into policy health, adoption, exceptions, and emerging risk themes, and leads continuous improvement initiatives to mature the 2LOD policy governance framework, incorporating lessons learned, regulatory developments, and industry leading practices.

Requirements

  • Bachelor’s degree or equivalent.
  • 15+ years of governance, risk and compliance management experience, preferably in financial services or other highly regulated industries.
  • Familiarity with frameworks, regulations, and standards, including but not limited to: Cyber Risk Institute Profile, ISO Standards, PCI DSS, NIST 800-53a, SIG, Federal Financial Examination Council (FFIEC) handbooks, Service Organization Controls in accordance with SSAE No.18, GLBA, NYDFS, and FCRA.
  • Required certification in one of CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent or ability to sit for one of the certifications within the first 12 months of hire.
  • Exceptional communication skills with ability to synthesize and present complex risk issues clearly and persuasively.
  • Creative problem solver who also demonstrates strong attention to detail and efficiency.
  • Ability to drive change in a dynamic business environment.
  • Strong relationship building skills.
  • Excellent organizational, analytical and project management skills.
  • Background and drug screen.

Nice To Haves

  • Multiple certifications in any of the following: CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent.
  • Experience with security-related technologies including Identity and Access Management tools, single-sign-on technologies, and technology systems.
  • Cybersecurity and technology consulting or advisory background at a top firm (Deloitte, PwC, Accenture, or equivalent).
  • Additional related education and/or experience preferred.

Responsibilities

  • Define and operationalize the enterprise second-line policy oversight strategy, establishing a scalable center-of-excellence model that standardizes governance, accountability, and execution across cybersecurity and technology risk domains.
  • Drive integration of first- and second-line policy oversight activities to ensure consistent risk interpretation, control expectations, and enterprise-wide coverage.
  • Establish executive-level reporting and metrics that provide transparency into policy health, adoption, exceptions, and emerging risk themes.
  • Lead continuous improvement initiatives to mature the 2LOD policy governance framework, incorporating lessons learned, regulatory developments, and industry leading practices.
  • Own the end-to-end enterprise lifecycle governance for all technology and security policies, establishing standards for drafting, review, approval, exception management, publication, and attestation.
  • Architect and maintain a cohesive, risk-aligned policy framework that clearly delineates policies, standards, procedures, and technical controls across lines of defense.
  • Provide strategic direction to ensure policy content reflects evolving regulatory requirements and industry frameworks, including PCI DSS, NIST 800-53a, SIG, FFIEC handbooks, SSAE No.18, GLBA, NYDFS, and FCRA.
  • Establish governance forums and decision-making structures to ensure appropriate challenge, approval authority, and accountability at the executive level.
  • Oversee policy rationalization efforts to eliminate redundancy, resolve ambiguity, and enhance clarity and enforceability across the enterprise.
  • Sponsor and govern a centralized enterprise control catalog that maps policy requirements to regulatory and industry frameworks, ensuring traceability and audit defensibility.
  • Drive harmonization across overlapping regulatory frameworks to reduce complexity and streamline control expectations for first-line execution.
  • Provide strategic oversight of control alignment efforts, ensuring consistency between documented requirements, implemented controls, and risk assessments.
  • Provide executive-level oversight and strategic direction in partnership with domain leaders across cybersecurity and technology functions including Cloud, IAM, DevSecOps, and Threat Management.
  • Translate emerging technical, regulatory, and business risks into forward-looking policy strategy and governance enhancements.
  • Oversee second-line assessments focused on policy design adequacy and alignment with operational execution, escalating systemic issues to senior leadership as appropriate.
  • Evaluate new technologies, strategic initiatives, and business ventures for policy impact and ensure proactive governance adaptation.
  • Serve as a senior trusted advisor to first-line executives and functional leaders, providing balanced challenge and credible oversight while enabling strategic business outcomes.
  • Influence enterprise risk governance by collaborating with Enterprise Risk, Operational Risk, Enterprise Compliance, Technology & Security Risk, and Legal to ensure an integrated and consistent approach to policy oversight.
  • Establish clear accountability frameworks that reinforce first-line ownership of risk and control execution.
  • Represent the 2LOD policy program in executive forums, regulatory discussions, and enterprise governance committees as needed.

Benefits

  • Competitive medical (PPO/HDHP), dental, and vision plans
  • Company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees
  • 11 paid company holidays
  • Paid volunteer day
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service