×
Register Here to Apply for Jobs or Post Jobs. X

Director of Technology Risk & Controls

Job in Hamilton Township, Mercer County, New Jersey, USA
Listing for: Rockefeller Capital Management
Full Time position
Listed on 2026-07-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Project Manager
Salary/Wage Range or Industry Benchmark: 225000 - 275000 USD Yearly USD 225000.00 275000.00 YEAR
Job Description & How to Apply Below

Position

The Director of Technology Risk & Controls will serve as the first-line owner of Technology risk and controls across Rockefeller Capital Management. This role has enterprise-wide accountability for identifying, assessing, and managing technology risks, while enabling innovation and facilitating governance in areas like artificial intelligence (AI), automation, and other emerging technologies. The role ensures that effective risk management practices and controls are embedded into day-to-day technology delivery, supporting the firm’s fiduciary obligations, protecting client trust, and safeguarding the stability, resilience, and integrity of Rockefeller’s technology platforms.

This leader will play a pivotal role in shaping and executing the firm’s technology risk and control strategy in close partnership with key stakeholders.

Responsibilities
  • Serve as the first-line owner for all technology risk and controls across the firm’s Technology domains — engineering, cloud infrastructure, data platforms, networks, end-user devices, and digital products — with direct accountability for the end-to-end RCSA lifecycle (risk identification, control design, testing, issue tracking, and reporting), operating within the firm’s defined risk appetite and tolerance thresholds and fostering a risk-aware culture across all Technology teams.
  • Lead technology risk governance, including oversight of enterprise control frameworks, governance structures, and decision rights across Technology; develop and maintain a structured hierarchy of IT policies, standards, and procedures across key control domains (IAM, data protection, change management, SDLC, and vendor oversight); and implement consistent controls across engineering, infrastructure, and data platforms, including application and process-level controls supporting financial, operational, and regulatory requirements.
  • Serve as the central coordination point for all Technology-related regulatory exams and internal/external audits, managing the full audit lifecycle including evidence collection, walkthroughs, and issue remediation; own first-line compliance monitoring and regulatory reporting for the Technology organization, including control-effectiveness measurement and risk trend and scenario analysis.
  • Establish and execute first-line risk governance for technology and information security controls — including vulnerability management, patching, endpoint security, network security, and data protection — setting control requirements, monitoring effectiveness, and challenging Information Security and Engineering teams to ensure risks are continuously identified, prioritized, remediated, and monitored in accordance with firm standards and regulatory expectations.
  • Manage first-line risk governance for AI, automation, and other emerging technologies, ensuring robust controls and responsible AI practices are embedded throughout implementation life cycles and strong data governance is enforced; assess and manage technology and data risks associated with third-party platforms, vendors, and strategic partnerships to ensure external services meet the firm’s risk and compliance standards.
  • Partner with the Technology team to define and embed risk and control requirements and assurance gates throughout the full software development and delivery lifecycle — from requirements and design through secure development, testing, deployment, and ongoing operations — independently verifying adherence and ensuring risk controls are operationalized in day-to-day technology processes.
  • Oversee first-line technology incident management — cyber and operational — setting escalation and reporting standards, monitoring that incidents are contained and remediated by Security Operations and Production teams, and coordinating response, reporting, and post-incident review in close partnership with Enterprise Risk, Compliance, Legal, and other control functions.
  • Maintain a comprehensive, forward-looking view of the firm’s technology risk posture; define and maintain the technology risk metrics framework including KRIs, KPIs, and control-effectiveness measures; and produce executive and board-level…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary