Associate Principal, Operational Risk Management, IT & Security

OCC•Chicago, IL
•$106,808 - $120,000•Hybrid

About The Position

The Options Clearing Corporation (OCC) is the world's largest equity derivatives clearing organization. Founded in 1973, OCC is dedicated to promoting stability and market integrity by delivering clearing and settlement services for options, futures and securities lending transactions. As a Systemically Important Financial Market Utility (SIFMU), OCC operates under the jurisdiction of the U.S. Securities and Exchange Commission (SEC), the U.S. Commodity Futures Trading Commission (CFTC), and the Board of Governors of the Federal Reserve System. OCC has more than 100 clearing members and provides central counterparty (CCP) clearing and settlement services to 19 exchanges and trading platforms. More information about OCC is available at www.theocc.com.

Requirements

  • Bachelor’s degree in computer science, information systems, business information technology, or related and three (3) years of experience as an operational risk management associate, security intern, project manager, or related
  • Work experience with executing risk identification, analysis, and enterprise risk assessments to verify consistency and reliability with NIST and COBIT frameworks and align with regulatory requirements by leveraging RSA Archer, JIRA, and ServiceNow.
  • Work experience developing Artificial Intelligence governance assessment protocols encompassing onboarding risk analysis, control gap evaluations, and continuous monitoring, and creating AI risk registers aligned to NIST AI Risk Management Framework using RSA Archer, JIRA, and ServiceNow.
  • Work experience auditing technology programs utilizing Distributed Ledger Technology (DLT), assessing functional and non-functional requirements traceability, vendor entitlement configurations against contractual obligations, and architectural integration risks of DLT into existing clearing and settlement environments using SpiraTest, SailPoint, and RSA Archer.
  • Work experience administering and reviewing Identity and Access Management (IAM) controls and access governance processes, including Role-Based Access Control (RBAC), user access reviews, entitlement reviews, least-privilege controls, and group-based access policies, using IAM tools such as Microsoft Active Directory, ManageEngine ADManager Plus, and Microsoft 365 Admin Center.

Responsibilities

  • Provide critical support to the Director of Operational Risk to evaluate IT and Security risks by assisting with risk assessments and applying aspects of the risk management framework across the process, risk, and control universe.
  • Collaborate with IT, Security, TPRM, Legal, Compliance, and Internal Audit to ensure that ORM contributes to strengthening the overall effective management of IT and Security risk across the organization.
  • Lead the OCC’s risk identification and assessment process (Risk Intake) for IT, Security and business risks, and verify the consistency and reliability of the associated frameworks and systems.
  • Drive adherence to methodologies, guidance, and standards applicable to risk identification and assessment frameworks.
  • Maintain risk inventories, taxonomies, and other elements supporting IT & Security risk management and compliance activities.
  • Lead and execute the IT and Security risk assessment process, while aligning to the risk and control universe, and regulatory requirements and expectations.
  • Execute risk identification, analysis, and enterprise risk assessments to verify consistency and reliability with NIST and COBIT frameworks and align with regulatory requirements by leveraging RSA Archer, JIRA, and ServiceNow.
  • Develop Artificial Intelligence governance assessment protocols encompassing onboarding risk analysis, control gap evaluations, and continuous monitoring, and create AI risk registers aligned to NIST AI Risk Management Framework using RSA Archer, JIRA, and ServiceNow.
  • Audit technology program utilizing Distributed Ledger Technology (DLT), assessing functional and non-functional requirements traceability, vendor entitlement configurations against contractual obligations, and architectural integration risks of DLT into existing clearing and settlement environments using SpiraTest, SailPoint, and RSA Archer.
  • Administer and review Identity and Access Management (IAM) controls and access governance processes, including Role-Based Access Control (RBAC), user access reviews, entitlement reviews, least-privilege controls, and group-based access policies, using IAM tools such as Microsoft Active Directory, ManageEngine ADManager Plus, and Microsoft 365 Admin Center.
  • Communicate results of risk assessments to governance committees, business owners, and various levels of leadership.
  • Collaborate on the enhancement and maintenance of ORM program methodologies, policies, procedures, and job aides, including the development of new program activities.
  • Track and update ORM team internal findings, external exam issues, and business area self-identified issues resulting from Enterprise Risk Assessment.

Benefits

  • A standard benefits package
  • Tuition Reimbursement to support your continued education
  • Student Loan Repayment Assistance
  • Technology Stipend allowing you to use the device of your choice to connect to our network while working remotely
  • Generous PTO and Parental leave
  • 401k Employer Match
  • Competitive health benefits including medical, dental and vision
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service