Senior Director- Technology Governance and Regulatory Strategy
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-03
Listing for:
WTW
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Description
WTW is expanding its Technology Risk & Assurance (TRA) capability to strengthen technology governance, risk management, and regulatory readiness across the enterprise. TRA serves as an embedded risk and control function within Global Technology, partnering closely with management to support the effective identification, assessment, and management of technology risk while collaborating with Enterprise Risk Management and Internal Audit across WTW's three lines model.
This is a high-visibility role with direct exposure to the CIO, regulators, and senior technology leadership. The right person will be a builder who brings deep regulatory expertise, sharp governance instincts, and the credibility to influence how technology risk is managed across the firm.
This leader will help strengthen how the function's pillars work together, building more shared ownership across Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory.
This is a rare opportunity to join a function at the moment of transformation and leave a lasting mark on how technology risk is governed at a major global professional services firm. The function has CIO sponsorship, a clear mandate, and the organizational backing to execute. The leader will have real authority, real accountability, and a direct line to the decisions that matter.
The Role
● Policy & Standards — Own the technology and cybersecurity risk policy architecture and lifecycle. Define, maintain, and evolve the control framework and standards across both domains. Ensure policies are right-sized, defensible, and benchmarked against peer practice and regulatory expectations.
● Control Framework — Define and maintain the control taxonomy, library, and standards across technology and cybersecurity risk domains. Ensure the framework is designed for testability and aligned to regulatory requirements, partnering with the CISO organization on control ownership and testing.
● Exception Management — Own the exception management process, connecting into the broader risk acceptance process where appropriate. Apply risk-based judgment to control deviations, inform policy updates based on emerging patterns, and maintain escalation authority for aging or high-risk exceptions.
● Regulatory Engagement — Serve as the primary interface with regulators for all technology and cybersecurity examination activity across WTW's global regulatory footprint, spanning the Americas, Europe, the Middle East, and Asia-Pacific, including cyber-specific regulations such as the NYDFS Cybersecurity Regulation (23 NYCRR 500) and HIPAA.
● Regulatory Obligations, Findings & Remediation — Maintain inventory of applicable technology and cybersecurity obligations across relevant jurisdictions and legal entities, ensuring they are traceable to policies, standards, controls, accountable owners, and evidence. Own the governance of regulatory findings, commitments, and supervisory actions from initial response through validated closure, with clear executive ownership, credible remediation plans, appropriate evidence standards, timely escalation of delivery risk, and transparent reporting to senior governance forums.
● Cybersecurity Regulatory Alignment — Partner with the CISO organization to ensure cybersecurity regulatory obligations are reflected in policy, standards, and the control framework, and represent TRA in cybersecurity-focused regulatory exams and assessments.
● Operating Model Definition — Define and drive adoption of a clear operating model for how the organization responds to technology and cybersecurity regulatory obligations, establishing well-defined roles, responsibilities, escalation paths, and review processes so response efforts are coordinated rather than ad hoc.
● Cross-Pillar Collaboration — Play an integral role in reshaping how Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory operate together, helping evolve routines,…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×