At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Overall Purpose The Director, Technical Policy Program Oversight, will support the Cybersecurity and Technology Risk Oversight Center of Excellence (CTRO-COE) Program within the Second Line of Defense (2LOD). This role is responsible for overseeing the 2LOD Policy Program. Essential Functions Center of Excellence Operations Define and operationalize the enterprise second-line policy oversight strategy, establishing a scalable center-of-excellence model that standardizes governance, accountability, and execution across cybersecurity and technology risk domains. Drive integration of first- and second-line policy oversight activities to ensure consistent risk interpretation, control expectations, and enterprise-wide coverage. Establish executive-level reporting and metrics that provide transparency into policy health, adoption, exceptions, and emerging risk themes. Lead continuous improvement initiatives to mature the 2LOD policy governance framework, incorporating lessons learned, regulatory developments, and industry leading practices. Policy Program Facilitation, Architecture & Oversight Own the end-to-end enterprise lifecycle governance for all technology and security policies, establishing standards for drafting, review, approval, exception management, publication, and attestation. Architect and maintain a cohesive, risk-aligned policy framework that clearly delineates policies, standards, procedures, and technical controls across lines of defense. Provide strategic direction to ensure policy content reflects evolving regulatory requirements and industry frameworks, including PCI DSS, NIST 800-53a, SIG, FFIEC handbooks, SSAE No.18, GLBA, NYDFS, and FCRA. Establish governance forums and decision-making structures to ensure appropriate challenge, approval authority, and accountability at the executive level. Oversee policy rationalization efforts to eliminate redundancy, resolve ambiguity, and enhance clarity and enforceability across the enterprise. Control Framework Mapping & Harmonization Sponsor and govern a centralized enterprise control catalog that maps policy requirements to regulatory and industry frameworks, ensuring traceability and audit defensibility. Drive harmonization across overlapping regulatory frameworks to reduce complexity and streamline control expectations for first-line execution. Provide strategic oversight of control alignment efforts, ensuring consistency between documented requirements, implemented controls, and risk assessments. Technical Subject Matter Collaboration Provide executive-level oversight and strategic direction in partnership with domain leaders across cybersecurity and technology functions including Cloud, IAM, DevSecOps, and Threat Management. Translate emerging technical, regulatory, and business risks into forward-looking policy strategy and governance enhancements. Oversee second-line assessments focused on policy design adequacy and alignment with operational execution, escalating systemic issues to senior leadership as appropriate. Evaluate new technologies, strategic initiatives, and business ventures for policy impact and ensure proactive governance adaptation. Advisory & Partnership Serve as a senior trusted advisor to first-line executives and functional leaders, providing balanced challenge and credible oversight while enabling strategic business outcomes. Influence enterprise risk governance by collaborating with Enterprise Risk, Operational Risk, Enterprise Compliance, Technology & Security Risk, and Legal to ensure an integrated and consistent approach to policy oversight. Establish clear accountability frameworks that reinforce first-line ownership of risk and control execution. Represent the 2LOD policy program in executive forums, regulatory discussions, and enterprise governance committees as needed. The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director
Number of Employees
501-1,000 employees