Process & Controls Advisor

Hub International InsuranceChicago, IL
Remote

About The Position

The Process and Controls Advisor is a veteran practitioner and the sole owner of a capability that does not exist anywhere else in HUB — the ability to enter a TechOps service domain, assess what exists, identify what is missing, and produce the process and control documentation that makes operationalization possible. This is not a supporting role. It is a self-directing, domain-facing discipline that operates across immediate, mid-term, and long-term horizons simultaneously. In the immediate term, this role conducts discovery interviews with Domain Leads, maps current-state processes, and identifies control gaps against the Technology Governance framework. In the mid-term, it drives operationalization — translating findings into workflow requirements, control design inputs, and actionable backlog items. In the long-term, it builds the analytical muscle and process discipline within domains that sustains what Technology Governance stands up. The right candidate arrives with their own methodology — developed through years of doing this kind of work in regulated environments — and adapts it to HUB's framework and culture. They do not need a playbook. They write one.

Requirements

  • Expert-level ability to assess, map, and document operational processes — current state, gaps, requirements, and improvement opportunities — across diverse technology domains.
  • Comfortable working with ambiguity — enters domains with no existing documentation and produces structured outputs from unstructured information.
  • Applies the right documentation format to the right purpose — process maps, workflow narratives, swimlane diagrams, gap registers — deliberately and without prompting.
  • Understands the full documentation tier structure and the content boundaries between tiers — knows what belongs in a corporate policy versus an operational standard versus an SOP versus a control document, and can identify when tier boundaries have been violated or when a tier is missing entirely.
  • Deep working knowledge of IT General Controls — access management, change management, computer operations, and SDLC — and what operationalized controls look like in practice.
  • Understands ITGC control requirements well enough to assess whether a process produces defensible audit evidence.
  • Familiar with ITIL, COSO, COBIT, or equivalent frameworks as operational design tools — not theoretical constructs.
  • Structures and conducts discovery interviews independently — surfaces what isn't being volunteered and comes away with what is needed.
  • Extracts institutional knowledge from practitioners who have never been asked to articulate what they do and turns it into documented, referenceable process.
  • Recognizes the difference between what a domain team says they do and what they actually do — and documents both.
  • Assesses control gaps with enough rigor to distinguish between a minor documentation deficiency and a material control weakness.
  • Self-directs across immediate, mid-term, and long-term work horizons without losing track of what matters most right now.
  • Communicates risk in terms that inform decisions — not in technical language that obscures it.
  • Arrives with a developed methodology and adapts it to HUB's framework, culture, and regulatory context without requiring a defined playbook.
  • Builds working relationships with Domain Leads through demonstrated competence — earns access and candor by showing up prepared and following through.
  • Operates without direct authority — influence is the tool; expertise and reliability are what make it work.
  • Maintains objectivity — documents what is real, not what is convenient, even when findings are uncomfortable.
  • Practitioner with a track record — not a candidate building toward one.
  • Years of experience doing process assessment and control operationalization work in environments where regulatory scrutiny was real and audit findings had consequences.
  • Experience standing up capabilities that didn't exist before, working in domains where nothing was documented, and producing outputs that held up when examined.
  • Senior GRC or controls advisory experience in a regulated industry — financial services, insurance, or healthcare — with direct involvement in ITGC assessment and operationalization.
  • Familiarity with internal audit activities and what auditors look for when assessing control environments — enough exposure to design processes that produce defensible evidence.
  • Process improvement or operational excellence leadership in a technology organization with regulatory obligations — ITIL, COSO, or equivalent framework fluency applied to real control environments.
  • 5-7 years of relevant experience.
  • Bachelor's degree (4-year degree)

Nice To Haves

  • Familiarity with ServiceNow, SailPoint, Optro or equivalent GRC platforms, and SharePoint-based governance libraries is useful.
  • Ability to walk into a domain that has never been formally assessed and come out the other side with something the function can act on — accurately, completely, and without being told how to do it.

Responsibilities

  • Process design and operationalization support: Support control design by providing process analysis, workflow documentation, and current-state context that informs design decisions. Identify where existing processes can be modified to produce control evidence systematically — reducing manual burden on domain teams. Recommend process improvements that serve both operational efficiency and control integrity. Recognize when a process problem requires escalation to the Control Operationalization Manager versus when it can be resolved through documentation and workflow adjustment.
  • Discovery and current-state assessment: Conduct independent discovery interviews with Domain Leads and domain team members across TechOps service domains — no facilitation support required. Map current-state processes with enough fidelity to identify where controls exist, where they are insufficient, and where they are absent entirely. Assess domain documentation coverage across the full Technology Governance framework hierarchy — from corporate policies and standards through operational policies, operational standards, SOPs, control documents, monitoring reports, control evidence reports, and domain records — identifying where the documentation chain is intact, where it is broken, and where it does not exist. Document workflow requirements — inputs, outputs, decision points, handoffs, system dependencies, and evidence production points — in formats that feed control design and documentation production. Assess process maturity honestly — distinguish between processes that exist and are followed, processes that exist on paper only, and processes that have never been formally defined. Surface undocumented institutional knowledge and operational workarounds that represent both risk and design opportunity.
  • Control gap analysis: Evaluate domain processes against Technology Governance control framework requirements — identifying gaps and deficiencies with enough specificity to act on. Distinguish between a documentation gap and an operational gap — know which one you are looking at and document it as such. Assess the risk profile of identified gaps — severity, regulatory exposure, and operational consequence — and communicate findings in terms that inform prioritization decisions. Identify compensating controls where primary controls are absent — and document whether they are sufficient or temporary.
  • Operationalization backlog management: Own and maintain the operationalization backlog as the authoritative record of Technology Governance's open work across TechOps service domains. Translate discovery findings and gap analysis outputs into discrete, actionable backlog items — scoped, described, and linked to the framework requirements they address. Track implementation progress — flag items that are stalled, dependent on domain team action, or at risk of missing committed timelines. Maintain backlog integrity — ensure items are current, accurately described, and reflect the real state of operationalization across the function.
  • Domain advisory: Build trusted working relationships with Domain Leads — earned through competence and follow-through, not org chart position. Communicate findings, gaps, and recommendations in terms that resonate with domain practitioners — not in governance language that creates distance. Maintain enough domain context over time to recognize when operational changes have control implications — and surface them without waiting to be asked.

Benefits

  • health/dental/vision/life/disability insurance
  • FSA, HAS and 401(k) accounts
  • paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays
  • eligible annual bonuses, equity and commissions may be available for some positions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service