We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Technology Governance & Control Analyst

TowneBank
6005 Harbour View Boulevard (Show on map)
Sep 14, 2026
Description

Primary Purpose:

The Senior Technology Governance & Control Analyst is a senior individual contributor responsible for developing, maintaining, and independently evaluating TowneBank's technology governance and control structure. Serving as a first line of defense (1LOD) subject-matter resource, this role provides governance and control guidance across Information Technology, Information Security, Project Management, application owners, and business units. The analyst translates regulatory requirements, industry frameworks, risk considerations, and organizational policies into practical governance frameworks, standards, procedures, control designs, and testing programs.

Operating with a high degree of independence, the analyst leads assigned governance and control initiatives, performs first-line control testing, evaluates the design and operating effectiveness of technology controls, identifies systemic gaps, and recommends risk-based improvements. The role influences outcomes through technical expertise, analysis, and cross-functional partnership and does not include direct people-management responsibilities.

The good-faith compensation range for this role is expected to be $95,000.00 to $120,000.00 annually based on the role, market, internal equity, and candidate qualifications.

Essential Responsibilities:

Governance, Policy & Procedure Management



  • Lead the development, maintenance, and periodic review of technology governance frameworks, policies, standards, procedures, and operational guidelines.
  • Evaluate governance documents for alignment with regulatory expectations, recognized industry frameworks, TowneBank's risk appetite, and organizational objectives.
  • Serve as a subject-matter resource to technology and business stakeholders on governance requirements, control expectations, policy interpretation, and documentation standards.
  • Maintain the governance document inventory, version control, approval workflows, ownership records, and evidence of required reviews.
  • Translate regulatory, risk, audit, and examination requirements into sustainable technology governance practices and operational procedures.


Control Design & Implementation



  • Lead the design, documentation, implementation, and ongoing refinement of preventive, detective, and corrective controls across technology processes.
  • Develop complete control documentation, including control objectives, risk statements, control descriptions, procedures, frequency, ownership, evidence requirements, systems of record, and escalation criteria.
  • Assess whether control design appropriately addresses identified technology risks and recommend enhancements when gaps or inefficiencies are identified.
  • Partner with control owners and technology teams to embed controls into operational processes while maintaining clear accountability and sustainable evidence practices.
  • Provide governance and control expertise for change management, the software development lifecycle, access management, vendor management, asset management, disaster recovery, data governance, and technology operations.


First Line Control Testing & Assurance



  • Independently plan and execute risk-based first-line testing of key technology controls to assess design and operating effectiveness.
  • Develop and maintain control testing scripts, sampling approaches, test plans, evidence standards, and documentation that support repeatable and defensible conclusions.
  • Evaluate the completeness, accuracy, relevance, and reliability of evidence supporting control execution.
  • Analyze control deficiencies, procedural gaps, recurring exceptions, and broader control-environment themes to determine risk and root cause.
  • Document clear testing conclusions and communicate findings, risk implications, and recommended corrective actions to control owners and leadership.
  • Evaluate remediation plans, validate completed corrective actions, perform follow-up testing, and track issues through sustainable closure.


Risk & Compliance Support



  • Lead or provide subject-matter expertise for assigned technology risk assessments, control evaluations, and risk and control self-assessments (RCSAs).
  • Map technology risks and controls to applicable FFIEC guidance, the NIST Cybersecurity Framework, NIST SP 800-53, COBIT, ISO 27001, and internal policies and standards.
  • Evaluate the completeness and consistency of control mappings and identify opportunities to reduce gaps, duplication, or unsupported risk coverage.
  • Advise control owners on risk treatment, control enhancements, mitigation planning, and sustainable remediation approaches.


Audit & Examination Readiness



  • Support internal audit engagements, external audits, and regulatory examinations.
  • Prepare evidence packages, control inventories, and documentation repositories.
  • Assist in responding to auditor and examiner requests.
  • Maintain current documentation demonstrating control effectiveness.
  • Support management action plan development and remediation tracking.


Reporting & Metrics



  • Develop governance metrics and control performance reporting.
  • Produce dashboards showing:


    • Control effectiveness
    • Testing results
    • Issue status
    • Policy review status
    • Remediation progress



  • Adheres to applicable federal laws, rules, and regulations including those related to Anti-Money Laundering (AML) and the Bank Secrecy Act (BSA).
  • Performs other duties as required or assigned which are reasonably within the scope of the duties in this job classification.


Minimum Required Skills & Competencies:

Education



  • Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Business Administration, Risk Management, or related field.


Experience



  • Five or more years of progressively responsible experience in technology governance and technology control structures, including direct experience with control design, implementation, documentation, testing, and issue remediation. Related experience in IT risk management, information security governance, internal controls, compliance, internal audit, or technology operations may complement-but not replace-substantive technology governance and control experience.


Knowledge & Skills



  • Advanced knowledge of technology governance operating models, technology control structures, and IT General Controls (ITGCs).
  • Demonstrated ability to design, document, implement, test, and improve controls across complex technology processes.
  • Strong knowledge of policy, standard, and procedure development and the relationship between governance requirements and operational execution.
  • Knowledge of technology risk assessment, control mapping, first-line testing, issue management, and remediation validation methodologies.
  • Ability to interpret regulatory and audit requirements and apply them to technology governance and control practices.
  • Ability to independently lead complex assignments, exercise sound judgment, manage competing priorities, and influence outcomes without direct authority.
  • Strong written and verbal communication skills, including the ability to explain complex governance and control matters to technical and nontechnical audiences.


Experience with:



  • ServiceNow IRM/GRC
  • Governance, Risk & Compliance platforms
  • Microsoft Office Suite
  • Risk and control documentation
  • Control testing and evidence collection


Desired Skills & Competencies:



  • Experience serving as a senior individual contributor or subject-matter expert for a technology governance, IT risk, or technology controls program.
  • Demonstrated experience establishing or maturing a technology governance framework and control structure across multiple technology domains.
  • Strong policy and procedure writing skills, with the ability to translate regulatory, audit, and technical requirements into clear operational guidance.
  • Experience performing risk assessments, control testing, evidence validation, and remediation follow-up in a regulated environment.
  • Working knowledge of technology control frameworks and standards, including FFIEC guidance, the NIST Cybersecurity Framework, NIST SP 800-53, COBIT, or ISO 27001.
  • Experience preparing documentation and evidence for internal audits, external audits, or regulatory examinations.
  • Strong written and verbal communication skills, including the ability to present findings and recommendations clearly to technical teams, business partners, management, and governance committees.
  • Demonstrated ability to lead complex work independently, provide constructive feedback, build collaborative relationships, and influence control owners and senior stakeholders without direct supervisory authority.
  • Experience using ServiceNow IRM/GRC or a comparable governance, risk, and compliance platform is preferred.
  • Experience in banking, financial services, or another highly regulated industry is preferred.


Physical Requirements:



  • Express or exchange ideas by means of the spoken word via email and verbally.
  • Exert up to 10 pounds of force occasionally, use your arms and legs, and sit most of the time.
  • Have close visual acuity to perform activities such as analyzing data, viewing a computer terminal, reading, and preparing documentation.
  • Not substantially exposed to adverse environmental conditions.
  • The physical demands described here are representative of those that must be met by an employee to successfully perform the essential responsibilities of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform essential responsibilities.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Applied = 0

(web-665cd84569-cxqqm)