Lead Associate Principal, Security Governance

OCCChicago, IL
$122,100 - $170,500Hybrid

About The Position

The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management Compliance, Internal Audit, Legal, and OCC’s Regulators. This role will lead the end-to-end lifecycle and change management of Security Services policies, procedures, standards, and control documentation, including the development, review, approval, publication, and retirement, in support of the NIST Cyber Security framework. Additionally, this person is responsible for supporting information security initiatives related to regulatory exam and Internal Audit remediation planning, tracking, and mitigation. Likewise, this role will provide subject matter expertise in reviewing the management self-testing efforts for the Security Service Department by identifying, recommending, and driving enhancements to the performance, integrity, and compliance of the organization’s processes. This role will also focus on compliance with applicable regulatory statutes and legal rules and requirements (i.e. SEC-Regulation SCI, CFTC-System Safeguards, etc.) as they relate to information security.

Requirements

  • Extensive experience in Information Security related policy, procedure and control writing.
  • Thorough understanding of information technology and risk management concepts
  • Extensive knowledge of and experience working with Security and Technology authoritative industry standards and control frameworks (e.g. NIST CSF, NIST 800-53, CIS 20, COBIT, COSO, ITIL, ISO 27001, CSA CCM, etc.)
  • Proficient knowledge of applicable regulatory, legal rules and requirements (e.g., SEC, CFTC, Federal Reserve Board, etc.) as they pertain to Information Security.
  • Demonstrable proficiency with AI tools (Claude Code)
  • Demonstrative leadership skills and capabilities
  • Highly proficient in collaborating with internal business clients from different departments and at various levels of seniority.
  • Excellent organizational, written and oral communication skills.
  • Experience working with PolicyTech, Confluence, Jira
  • Strong experience in Information Security related policy, procedure and control management
  • Understanding information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO etc.
  • Experience in technology risk management principles and practices
  • Experience in working with regulatory frameworks and business requirements relevant to OCC such as, RegSCI, CFTC, etc.
  • Proficiency using an integrated risk management system (such as RSA Archer Suite) and a business intelligence tool (e.g, Tableau)
  • Bachelor’s degree in computer science, Management Information Systems, Business Studies, or related field or the equivalent combination of education and/or relevant experience
  • 7+ years previous work experience in Information Security, Compliance, Risk Management, Project Management, or Data analytics
  • Demonstrative communication and collaboration experience across multiple functions and/or departments
  • Experience managing regulatory relations and requirements
  • Previous work in Compliance, Audit, Risk Management, Project Management, or control activities in the financial services industry.

Nice To Haves

  • Working knowledge of Cloud implementation and Cloud compliance strategies including for data, information, application, platform and network security a plus
  • Deep seated understanding of Systems Development Life Cycle (SDLC) process (Agile) and Secure Software Development Lifecycle a plus
  • Professional network and/or security certifications a plus (i.e., GIAC, CISSP, CISA, CISM, CRISC)

Responsibilities

  • Provide subject matter expertise in the development, review, and continuous improvement of Security Services policies, procedures, and controls, ensuring documentation remains current, appropriately governed, and aligned with applicable regulatory requirements, industry frameworks, and OCC’s risk management objectives.
  • Recommendation and oversight of appropriate reporting frameworks, standards, and best practices.
  • Supporting efforts for remediating regulatory and Internal Audit findings, including analyzing data to identify root cause of problems, identifying trends, formulating solutions, and escalating potential issues related to the lifecycle of remediation.
  • Act as a supporting point of contact from Security Services to senior management in Compliance, Internal Audit, Enterprise Risk Management, Legal and regulators
  • Support strategic development, implementation, review, and improvement of right sized management self-testing of controls.
  • Serve as the governance facilitator for the Security Working Group Program, ensuring the Working Group meets its applicable obligations and requirements including overseeing the maintenance of appropriate governance documentation and records.
  • Act on Security Services’ behalf related to compliance matters including developing and implementing strategies for strengthening the Security Services compliance posture.
  • Provide management oversight and subject matter expertise input on Security Services’ responses to Third-Party requests and surveys.
  • Perform ad-hoc duties for Security Governance management as necessary.

Benefits

  • A hybrid work environment, up to 2 days per week of remote work
  • Tuition Reimbursement to support your continued education
  • Student Loan Repayment Assistance
  • Technology Stipend allowing you to use the device of your choice to connect to our network while working remotely
  • Generous PTO and Parental leave
  • 401k Employer Match
  • Competitive health benefits including medical, dental and vision
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service