We are seeking a future team member for the role of Director, Technology Controls Management Framework to join our Engineering Control Services team. This role is located in Pittsburgh, PA with consideration also given to candidates located in Lake Mary, FL
Position Summary
The Director, Technology Controls Management Framework is responsible for the stewardship, evolution, and continuous improvement of the Technology Controls Management Framework across the Technology organization.
Partnering with leaders across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, Enterprise Risk, Internal Audit, and enterprise governance functions, this role establishes the methodologies, governance practices, and engineering principles that enable technology controls to be designed, implemented, measured, and continuously improved in a consistent, risk-based manner.
While accountability for the design and operation of individual technology controls remains within the respective technology organizations, this role is responsible for defining the framework within which those controls are developed. This includes establishing common methodologies, governance standards, control design principles, measurement practices, and alignment with recognized industry frameworks to ensure Technology maintains a coherent, sustainable, and auditable control environment.
This is a highly collaborative leadership role requiring strong influence, systems thinking, and the ability to drive enterprise-wide consistency without direct ownership of the underlying technology organizations.
In this role, you’ll make an impact in the following ways:
- Technology Controls Management Framework: Lead the evolution and maturity of the Technology Controls Management Framework, including governance model, taxonomy, lifecycle, and methodologies, while ensuring traceability across Technology risks, policies, standards, controls, evidence, testing, and control effectiveness measures. Maintain a framework that is practical, scalable, and responsive to evolving business, regulatory, and technology risk requirements.
- Policy & Standards Governance:Â Author and govern centrally owned Technology policies, standards, methodologies, and supporting documentation, and provide oversight across Infrastructure, Cybersecurity, Data, Software Engineering, Artificial Intelligence, and other Technology organizations. Ensure policies and standards translate into well-designed, measurable, and operationally effective controls.
- Control Design & Engineering: Define enterprise expectations and minimum engineering standards for Technology control design, including automation, evidence, ownership, monitoring, testability, and measurable outcomes. Lead governance reviews of new and modified controls and drive simplification, standardization, and continuous improvement across the Technology control environment.
- Control Effectiveness & Measurement: Establish methodologies and standards for measuring Technology control effectiveness, including KPIs, KCIs, KRIs, evidence collection, monitoring, testing, and control health reporting. Advance automation, observability, and data-driven measurement to improve control performance and reduce operational overhead.
- Industry Alignment & Continuous Improvement: Align the Technology Controls Management Framework to leading industry frameworks including COBIT, NIST, ISO 27001, and other applicable standards. Conduct benchmarking and recommend strategic enhancements to strengthen the maturity, consistency, and effectiveness of the Technology control environment.
- Governance Leadership & Partnership: Build strong partnerships with Technology leadership, Enterprise Risk, Compliance, Internal Audit, and enterprise governance organizations. Provide expertise on Technology governance, controls methodology, and control design, while supporting audit and regulatory responses through collaboration and practical problem solving.
Â
To be successful in this role, we’re seeking the following:
Required Qualifications / Experience
- 10+ years of progressively responsible experience in Technology Governance, Technology Risk, Information Security Governance, Controls Management, Operational Risk, or related disciplines.
- Demonstrated experience designing, implementing, or maturing enterprise governance or controls frameworks.
- Experience working within large, complex, highly regulated organizations.
- Strong understanding of Technology controls across infrastructure, cybersecurity, software engineering, cloud platforms, data, and emerging technologies.
- Experience working with Internal Audit, Enterprise Risk, regulators, and senior Technology leadership.
Â
Preferred Qualifications
- Experience with COBIT, NIST Cybersecurity Framework, ISO 27001, ITIL, or comparable governance frameworks.
- Experience developing governance policies, standards, or enterprise methodologies.
- Professional certifications such as CGEIT, CRISC, CISA, CISSP, or equivalent.
Â
Â
At BNY, our culture speaks for itself, check out the latest BNY news at BNY Newsroom & BNY LinkedIn
 Here’s a few of our recent awards:
- America’s Most Innovative Companies, Fortune, 2025
- World’s Most Admired Companies, Fortune 2025
- “Most Just Companies”, Just Capital and CNBC, 2025
Our Benefits and Rewards:
BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life’s journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.
BNY is an Equal Employment Opportunity/Affirmative Action Employer - Underrepresented racial and ethnic groups/Females/Individuals with Disabilities/Protected Veterans.
BNY assesses market data to ensure a competitive compensation package for our employees. The expected base salary for this position when employment commences can be found in the Job Info section at the bottom of the posting.Â
Base salary offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. Base salary is only part of the total rewards package, which may include eligibility for an annual discretionary incentive award. Subject to the terms and conditions of the applicable plans then in effect, eligible employees may enroll in a 401(k) plan as well as participate in Company-sponsored medical, dental, vision, and basic life insurance plans for the employee and the employee’s eligible dependents. Eligible employees also may receive other benefits (including various paid time off benefits, such as vacation and sick time), dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment.
If hired, the employee will be in an “at will” position and the Company reserves the right to modify base salary (as well as any other discretionary payments or compensation programs) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
Learn more about this Employer on their Career Site
