The IT and cybersecurity regulatory response lead is accountable for executing the company’s second-line IT SOX/MAR program. This role partners closely with first-line IT control owners, second-line controllership partners, and third-line IT auditors, requiring strong communication, presentation, and stakeholder management skills. The role also requires strong project management capabilities to coordinate both transformational and operational work across multiple team members.
What you’ll do:
Own and manage the second-line IT SOX/MAR program through direct individual contribution and serving as a people leader for junior second-line IT SOX/MAR team members.
Serve as the primary accountable stakeholder for building an integrated program that jointly addresses IT SOX/MAR requirements and state cybersecurity regulations, including New York DFS Part 500, California Consumer Privacy Act Article 9, and the Wisconsin Insurance Data Security Law.
Represent IT SOX/MAR and cybersecurity regulatory requirements in IT GRC and cybersecurity efforts to build an automated continuous controls assurance program leveraging a unified data platform and the organization’s GRC solution, ServiceNow.
Develop relationships with and provide guidance to first-line IT teams who manage in-scope applications and infrastructure.
Articulate technical positions and reach consensus with third-line auditors on IT SOX/MAR topics such as scoping rationale, control coverage, and IT process conclusions in areas with findings, with increasing responsibility to support similar activities across other cybersecurity and regulatory compliance programs.
Identify and navigate dependencies between the business process/accounting components of the IT SOX/MAR program and the IT program components, including segregation of duties governance, IT application scoping, and risks related to interfaces between in-scope systems.
Automate and improve IT SOX/MAR processes, with evolving program needs expected to include future system development and data engineering capabilities.
What You’ll Bring to the Role:
Bachelor’s degree in MIS, Accounting, Business, or a related field, or equivalent relevant experience.
Minimum 8–12 years of experience in information systems, systems audit, IT controls, or a related technology risk and compliance discipline. Including preferred 6–8 years of experience in technology risk, IT audit, or regulatory compliance within a public accounting, consulting, or professional services environment.
Technical understanding of IT SOX/MAR program design.
Experience building or enhancing regulatory compliance programs; financial services industry experience is a plus.
1–2 years of people leadership experience.
Excellent relationship management, influence, communication, negotiation, and professional judgment skills.
Proven ability to independently identify and resolve critical and complex issues through effective problem-solving skills.
Ability to operate effectively in ambiguous situations and bring structure to complex work.
Skills you will have
Compliance: Applies knowledge of the organization's standards, policies, processes, and procedures to ensure that regulatory requirements are met and compliance is maintained.
Cross Functional Partnering & Planning: Facilitates collaboration, communication, coordination, and planning with individuals and teams from different functions within the organization, and who have different areas of expertise, to achieve common goals.
Process Improvement: Assesses the current processes and impact to analyze, design, and manage potential improvement areas for more efficient, effective workflow.
Engineering Expertise & Practices: Applies specialized experiences in different facets of engineering, including data, applications, cyber, systems, operations, product, security, and testing, along with technical aptitude to adapt new expertise as they become relevant through an understanding of underlying engineering principles.
Strategic Vision & Planning: Develops, defines, and executes strategic vision for the team and business function they manage with an understanding of the enterprise’s goals as a people manager; defines business planning, strategy formulation, and management engine to support strategic vision.
Analytical Thinking: Organizes and compares various aspects of a situation to comprehend and identify key or underlying complex issues through the use of quantitative data and analysis; leverages strong business acumen, problem solving, and interpersonal skills to think critically about situations from multiple perspectives and consistently seeks ways to improve processes.
Risk Optimization: Aligns residual risk to risk tolerance while considering internal and external factors as well as cost/benefits of available options.
Coaching & Mentoring: Develops others by providing actionable, constructive feedback through the lens of technical expertise and offers guidance to others on how to leverage, prioritize, and develop skills to achieve one's goals and objectives.
Compensation Range:
Pay Range - Start:
$118,960.00
Pay Range - End:
$178,440.00
Geographic Specific Pay Structure:
Structure 110:
$130,880.00 USD - $196,320.00 USD
Structure 115:
$136,800.00 USD - $205,200.00 USD
We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.
Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!
Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.
Analytical Thinking (NM) - Advanced, Customer Centricity (NM) - Advanced, Strategic Thinking (NM) - Advanced, Process Improvement (NM) - Intermediate, Cross Functional Partnering & Planning (NM) - Advanced, Compliance (NM) - Intermediate, Remediation Planning (NM) - Advanced, Risk Management Strategy (NM) - Intermediate, Coaching & Mentoring (NM) - Advanced, Adaptive Communication (NM) - Intermediate, Business Application (NM) - Intermediate, Engineering Expertise & Practices (NM) - Advanced, Negotiation & Managing Objection (NM) - Intermediate, Data Security (NM) - Advanced, Strategic Vision & Planning (NM) - Intermediate, Risk Assessment & Identification (NM) - Advanced, Risk Mitigation (NM) - Advanced, Risk Governance (NM) - Advanced, Learning Agility & Critical Thinking (NM) - Advanced, Scenario Planning (NM) - Intermediate, Technology Integration (NM) - Intermediate, Risk Consulting (NM) - Intermediate, Risk Optimization (NM) - Intermediate
We’re excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.
-
Flexible work schedules
-
Concierge service
-
Comprehensive benefits
-
Employee resource groups