Senior Director, Enterprise Control Framework
About the role
Ethos is seeking a seasoned Director, Enterprise Control Framework to join our Compliance department as a senior leader. This person will own the design, documentation, and ongoing health of the company’s non-financial control framework - the single authoritative map of how Ethos’s regulatory and operational obligations translate into controls, who owns those controls, and how they are evidenced. This is not a Sarbanes-Oxley or internal-controls-over-financial-reporting role; financial reporting controls sit elsewhere. Instead, you will build and sustain the control architecture covering operational risk, including compliance, across the enterprise.
You will be the connective tissue between the obligations Ethos is held to and the day-to-day controls our first-line teams actually operate. You will also partner closely with our Compliance Risk Management (“CRM”) team, who independently monitor and test the controls you define. You design and document, CRM tests. Success in this role looks like a control framework that is complete, accurately mapped, understood by its owners, and critically, evergreen: never more than a change cycle behind the business or the regulatory landscape. You will start hands-on and are expected to build and lead a small team as the framework scales. Importantly, the candidate must be risk-minded, be a team player, confident in determining acceptable risk, and think creatively to always find solutions.
Duties and Responsibilities:
Own the enterprise non-financial control framework end to end, including:
Risk and control mapping:map each obligation to the risks it creates and the first-line controls that mitigate them; surface gaps, redundancies, and orphaned controls
Control documentation: write clear, testable control descriptions including control owner, frequency, control type (preventive/detective, manual/automated), and required evidence
Taxonomy and standards: define and enforce a common control taxonomy, rating scale, and documentation standard used consistently across the company
Coverage assessment : identify where obligations are uncontrolled or under-controlled and drive remediation with first-line owners
Keep the framework evergreen, including:
Establish the triggers and cadence that force the framework to update: regulatory change, product launches, new state or carrier approvals, system migrations, organizational change, and audit or exam findings
Run periodic control owner attestation and framework refresh cycles
Partner with the CRM team so that every material change lands as a concrete control change rather than a memo
Retire and consolidate controls that become obsolete
Partner with the Compliance Risk Management team, including:
Hand off controls in a state that is ready to test: clearly scoped, with defined control owner, evidence, and testable pass/fail criteria
Maintain clear separation of duties between control design and independent control testing
Translate CRM testing results and control failures back into framework and control design improvements
Align the control framework to CRM’s inherent and residual risk assessment methodology so ratings stay consistent across programs
Build and lead the function. Operate as a hands-on player-coach initially, then hire, develop, and manage a control framework analyst as scope grows
Act as thought leader on control design and control framework governance across Ethos, influencing senior first-line and second-line stakeholders
Support internal and third party audits, market conduct exams, regulatory requests, carrier requests, and data calls by producing the control mapping and documentation those reviews require
Assist in drafting and updating compliance policies and procedures so that policy, procedure, and control documentation remain mutually consistent
Provide general compliance support, as needed, across the team and company
Qualifications and Skills:
12+ years of relevant Compliance, controls, risk, or audit experience, including significant experience in insurance or another highly regulated financial services industry
Demonstrated ownership of a control framework or risk and control inventory at enterprise scale - you have built or substantially rebuilt one, not only maintained an existing one
Deep expertise in control design and documentation: writing controls that are specific, testable, and genuinely operable by the teams that own them
Strong command of risk and control taxonomies, and control rating frameworks
Experience partnering with an independent testing or monitoring function, and comfort with the separation of duties that requires
Strong governance background, including experience presenting to risk and compliance committees and to executive leadership
Strong understanding of regulatory change management and how regulatory change translates into control change
Hands-on experience documenting and maintaining controls within GRC tooling administered by a partner team
Exceptional written and verbal communication skills - clear, precise documentation is the core product of this role
Persuasive communicator and thought leader, able to hold senior stakeholders to a documentation and evidence standard without becoming a blocker
Experience hiring, developing, and managing a small team, or clear readiness to do so
Possess sound and practical business judgment, and confidence in determining acceptable risk
Ability to multi-task and work independently or with cross-functional teams, while adapting quickly to ambiguous and rapidly changing environments
Exceptional attention to detail, with a high tolerance for structure and rigor
Ability to work in a fast-paced environment and manage multiple deadlines
#LI-Hybrid
#LI-KP2