Information Technology Governance Manager
TabaPay · Palo Alto, CA · 1 wk ago
HybridAccounting$150k–$160k/yrFull-time
About the Role
Lead the development, implementation, and enforcement of IT governance frameworks across a hybrid computing environment. Balance fast-paced fintech software deployments with the rigid security and compliance rules required for high-volume US payment systems. Ensure that all IT functions of the organization are continuously audit-ready with regard to US financial institution (FFIEC) audit requirements as well as Payment Card Industry (PCI) DSS requirements and System and Organization Controls (SOC) audit expectations.
Responsibilities
- US Regulatory Compliance & Audit Readiness
- Maintain continuous compliance with PCI-DSS v4.0 (Level 1), FFIEC guidelines, SOC 1/2, and GLBA.
- Act as the lead technical liaison for US regulatory exams (e.g., OCC, Federal Reserve, FDIC, state banking/money transmission regulators).
- Support regular internal audits and mock exams to identify and patch compliance gaps before official audits.
- Hybrid Environment Policy & Architecture Governance
- Adapt IT governance frameworks (COBIT 2019, NIST CSF, CIS) to fit both on-premise/co-located servers and AWS or other cloud environments.
- Govern strict data residency and sovereignty policies to keep sensitive US financial data isolated and compliant.
- Enforce unified change management and secure software development lifecycle (SDLC) rules across both cloud and on-prem assets.
- High-Volume Transaction Environment Documentation
- Identify and document technical risks or other concerns unique to high-throughput US payment rails (e.g., FedNow, ACH, Fedwire, and Real-Time Payments/RTP).
- Establish separate but integrated disaster recovery (DR) and business continuity (BCP) strategies for cloud systems and physical data centers.
- Facilitate vendor management processes for critical third-party IT-related vendors.
- Metrics, Reporting & Accountability
- Design and track Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for hybrid operational stability.
- Present formal risk posture and compliance updates monthly to the executive team and risk committees.
- Chair the hybrid change advisory board (CAB) to safely approve complex cross-environment code deployments.
Requirements
- Experience & Education
- Bachelor’s degree in Management Information Systems (MIS), Cybersecurity, Finance, or Computer Science.
- 5 to 7 years in IT governance, risk, or compliance (GRC) inside a US financial institution, regulated payment processor, or equivalent.
- At least 3 years of experience in an environment that processes high-volume US payment rails and card networks.
- Required Certifications (At least two preferred)
- CGEIT (Certified in the Governance of Enterprise IT)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
- Technical & Soft Skills
- Regulatory Expertise: Expert-level mastery of FFIEC handbooks, PCI-DSS, and US federal banking privacy laws.
- Hybrid Tech Literacy: Strong understanding of hybrid models (e.g., connecting on-prem database architecture with containerized cloud microservices).
- Communication: Ability to confidently bridge the gap between fast-moving DevOps engineers and conservative corporate bank attorneys.
Performance Success Metrics
- Flawless US Regulatory Audits: Zero material or critical findings from the FFIEC, OCC, or external accounting auditors.
- Unified Environment Controls: Successful deployment of governance policies that apply equally well to cloud infrastructure and physical servers.
- Safe Velocity: Maintenance of high-throughput payment uptimes without blocking the engineering department's agile sprint schedule.
Pay
The compensation for this position is $150,000 - $160,000. Base pay offered may vary depending on job-related knowledge, skills, and experience.
Benefits
- 100% employer-paid health care insurance including medical, dental, vision, and life insurance (for employee only).
- Employer 401K Matching.
- Generous and Flexible PTO.