Head of Technology Risk, Governance, and Controls
Core
Own the strategy and oversight of first-line technology risk, governance, and controls to ensure system integrity and regulatory compliance for S&P Global.
Role type
Head of Technology Risk, Governance, and Controls
Builds
Secure, scalable, resilient technology products and services
Domain
Enterprise Technology Risk Management & Internal Controls
Deliverable
production ML models | dashboards & analysis | infrastructure
Required skills
Technology risk management, Internal controls implementation, People management, Stakeholder relationship management, Complex risk communication, Global environment navigation, Analytical problem-solving, Technology risk frameworks (NIST CSF, ISO 27001, COBIT, SOX ITGC), Emerging tech risk (AI/ML)
Preferred skills
None stated
Technologies
NIST CSF, ISO 27001, COBIT, SOX ITGC
Responsibilities
Lead technology risk and governance strategy, Own SOX controls and annual testing, Scale first-line of defense to mitigate technology risk, Operationalize enterprise risk framework within technology, Establish and track KPIs/KRIs for technology risk, Collaborate on enterprise risk appetite and taxonomy, Lead risk assessments and partner with Internal Audit, Drive culture of risk awareness and continuous improvement, Own first-line management of third-party and cloud provider risks, Design and operate the technology control environment, Embed first-line risk management for AI, Strengthen operational resilience and continuity, Map regulatory obligations into the control environment
Seniority
Senior, hands-on IC with people management