Rodeo
Get started

WTW

Senior Director- Technology Governance and Regulatory Strategy

London
£150k – £170k/yr
Posted about 23 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Description

WTW is expanding its Technology Risk & Assurance (TRA) capability to strengthen technology governance, risk management, and regulatory readiness across the enterprise. TRA serves as an embedded risk and control function within Global Technology, partnering closely with management to support the effective identification, assessment, and management of technology risk while collaborating with Enterprise Risk Management and Internal Audit across WTW's three lines model.

This is a high-visibility role with direct exposure to the CIO, regulators, and senior technology leadership. The right person will be a builder who brings deep regulatory expertise, sharp governance instincts, and the credibility to influence how technology risk is managed across the firm.

This leader will help strengthen how the function's pillars work together, building more shared ownership across Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory.

This is a rare opportunity to join a function at the moment of transformation and leave a lasting mark on how technology risk is governed at a major global professional services firm. The function has CIO sponsorship, a clear mandate, and the organizational backing to execute. The leader will have real authority, real accountability, and a direct line to the decisions that matter.

The Role

  • Policy & Standards: Own the technology and cybersecurity risk policy architecture and lifecycle. Define, maintain, and evolve the control framework and standards across both domains. Ensure policies are right-sized, defensible, and benchmarked against peer practice and regulatory expectations.
  • Control Framework: Define and maintain the control taxonomy, library, and standards across technology and cybersecurity risk domains. Ensure the framework is designed for testability and aligned to regulatory requirements, partnering with the CISO organization on control ownership and testing.
  • Exception Management: Own the exception management process, connecting into the broader risk acceptance process where appropriate. Apply risk-based judgment to control deviations, inform policy updates based on emerging patterns, and maintain escalation authority for aging or high-risk exceptions.
  • Regulatory Engagement: Serve as the primary interface with regulators for all technology and cybersecurity examination activity across WTW's global regulatory footprint, spanning the Americas, Europe, the Middle East, and Asia-Pacific, including cyber-specific regulations such as the NYDFS Cybersecurity Regulation (23 NYCRR 500) and HIPAA.
  • Regulatory Obligations, Findings & Remediation: Maintain inventory of applicable technology and cybersecurity obligations across relevant jurisdictions and legal entities, ensuring they are traceable to policies, standards, controls, accountable owners, and evidence. Own the governance of regulatory findings, commitments, and supervisory actions from initial response through validated closure, with clear executive ownership, credible remediation plans, appropriate evidence standards, timely escalation of delivery risk, and transparent reporting to senior governance forums.
  • Cybersecurity Regulatory Alignment: Partner with the CISO organization to ensure cybersecurity regulatory obligations are reflected in policy, standards, and the control framework, and represent TRA in cybersecurity-focused regulatory exams and assessments.
  • Operating Model Definition: Define and drive adoption of a clear operating model for how the organization responds to technology and cybersecurity regulatory obligations, establishing well-defined roles, responsibilities, escalation paths, and review processes so response efforts are coordinated rather than ad hoc.
  • Cross-Pillar Collaboration: Play an integral role in reshaping how Technology Governance & Regulatory Strategy, Controls Assurance, and Risk Operations & Advisory operate together, helping evolve routines, workflows, and handoffs so the three pillars function as a more connected team.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What You Will Do In The First 90 Days

  • Establish examiner relationships and get current on open regulatory items, including cybersecurity-related exams
  • Assess the current operating model for technology and cybersecurity regulatory response, and begin clarifying roles, ownership, and escalation paths where they're unclear
  • Establish a working cadence with the CISO organization on cybersecurity policy and control alignment
  • Begin benchmarking the existing policy and control framework against regulatory expectations
  • Build working relationships with TRA peers and colleagues on shared workflows
  • Validate scope and priorities with the Head of Technology Risk & Assurance

Qualifications

What you'll bring

  • Deep regulatory relationships: Direct experience managing examiner relationships with regulators such as the Fed, SEC, NYDFS, or FCA, along with comparable regulatory bodies across other jurisdictions. Has sat across the table from regulators and knows how exams work.
  • Global regulatory breadth: Comfortable operating across a large, varied portfolio of regulatory and audit relationships spanning multiple countries and regulatory regimes simultaneously.
  • Policy and governance fluency: Has owned and evolved a control framework. Understands how to write policy that is both defensible to regulators and workable for technology teams.
  • DORA and international regulatory experience: Strong familiarity with DORA obligations and the broader EU regulatory landscape is a meaningful plus.
  • Cybersecurity regulatory fluency: Working knowledge of cybersecurity regulatory regimes (e.g., NYDFS Cybersecurity Regulation, HIPAA, and comparable regimes across EMEA and the Middle East) and how they intersect with technology risk governance.
  • Demonstrated regulatory exam experience: Has coordinated evidence and response cycles for technology or cybersecurity regulatory examinations. Understands the exam readiness and response lifecycle.
  • Senior and credible: Capable of representing the function externally and influencing technology leadership. Comfortable in front of regulators, auditors, and senior stakeholders.
  • Collaborative: Has helped bring functions with overlapping mandates closer together, not just coordinated around the edges. Brings a point of view on how teams should share ownership of common work.
  • Builder mindset: The right person wants to shape something and leave a mark, not inherit a finished model.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

What We Offer

Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.

We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.

Equal Opportunity Employer

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Technology Governance
Regulatory Strategy
Risk Management
Cybersecurity Policy
Control Framework Design
Regulatory Engagement
Exception Management
Compliance Monitoring
Stakeholder Management
Audit Coordination
DORA Compliance
NYDFS Regulation
HIPAA Compliance
Operating Model Definition
Enterprise Risk Management
Strategic Leadership

Location

London, England, United Kingdom

Sign up to applySee more jobs like this