IT and Cybersecurity Regulatory Response Lead

Northwestern MutualMilwaukee, WI

About The Position

The IT and cybersecurity regulatory response lead is accountable for executing the company’s second-line IT SOX/MAR program. This role partners closely with first-line IT control owners, second-line controllership partners, and third-line IT auditors, requiring strong communication, presentation, and stakeholder management skills. The role also requires strong project management capabilities to coordinate both transformational and operational work across multiple team members.

Requirements

  • Bachelor’s degree in MIS, Accounting, Business, or a related field, or equivalent relevant experience.
  • Minimum 8–12 years of experience in information systems, systems audit, IT controls, or a related technology risk and compliance discipline.
  • Including preferred 6–8 years of experience in technology risk, IT audit, or regulatory compliance within a public accounting, consulting, or professional services environment.
  • Technical understanding of IT SOX/MAR program design.
  • Experience building or enhancing regulatory compliance programs; financial services industry experience is a plus.
  • 1–2 years of people leadership experience.
  • Excellent relationship management, influence, communication, negotiation, and professional judgment skills.
  • Proven ability to independently identify and resolve critical and complex issues through effective problem-solving skills.
  • Ability to operate effectively in ambiguous situations and bring structure to complex work.
  • Compliance: Applies knowledge of the organization's standards, policies, processes, and procedures to ensure that regulatory requirements are met and compliance is maintained.
  • Cross Functional Partnering & Planning: Facilitates collaboration, communication, coordination, and planning with individuals and teams from different functions within the organization, and who have different areas of expertise, to achieve common goals.
  • Process Improvement : Assesses the current processes and impact to analyze, design, and manage potential improvement areas for more efficient, effective workflow.
  • Engineering Expertise & Practices: Applies specialized experiences in different facets of engineering, including data, applications, cyber, systems, operations, product, security, and testing, along with technical aptitude to adapt new expertise as they become relevant through an understanding of underlying engineering principles.
  • Strategic Vision & Planning : Develops, defines, and executes strategic vision for the team and business function they manage with an understanding of the enterprise’s goals as a people manager; defines business planning, strategy formulation, and management engine to support strategic vision.
  • Analytical Thinking: Organizes and compares various aspects of a situation to comprehend and identify key or underlying complex issues through the use of quantitative data and analysis; leverages strong business acumen, problem solving, and interpersonal skills to think critically about situations from multiple perspectives and consistently seeks ways to improve processes.
  • Risk Optimization : Aligns residual risk to risk tolerance while considering internal and external factors as well as cost/benefits of available options.
  • Coaching & Mentoring: Develops others by providing actionable, constructive feedback through the lens of technical expertise and offers guidance to others on how to leverage, prioritize, and develop skills to achieve one's goals and objectives.

Responsibilities

  • Own and manage the second-line IT SOX/MAR program through direct individual contribution and serving as a people leader for junior second-line IT SOX/MAR team members.
  • Serve as the primary accountable stakeholder for building an integrated program that jointly addresses IT SOX/MAR requirements and state cybersecurity regulations, including New York DFS Part 500, California Consumer Privacy Act Article 9, and the Wisconsin Insurance Data Security Law.
  • Represent IT SOX/MAR and cybersecurity regulatory requirements in IT GRC and cybersecurity efforts to build an automated continuous controls assurance program leveraging a unified data platform and the organization’s GRC solution, ServiceNow.
  • Develop relationships with and provide guidance to first-line IT teams who manage in-scope applications and infrastructure.
  • Articulate technical positions and reach consensus with third-line auditors on IT SOX/MAR topics such as scoping rationale, control coverage, and IT process conclusions in areas with findings, with increasing responsibility to support similar activities across other cybersecurity and regulatory compliance programs.
  • Identify and navigate dependencies between the business process/accounting components of the IT SOX/MAR program and the IT program components, including segregation of duties governance, IT application scoping, and risks related to interfaces between in-scope systems.
  • Automate and improve IT SOX/MAR processes, with evolving program needs expected to include future system development and data engineering capabilities.

Benefits

  • Geographic specific pay structures, compensation and benefits could be applicable
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service