Process & Controls Advisor

HUB InternationalChicago, IL
$120,000 - $135,000Remote

About The Position

The Process and Controls Advisor is a veteran practitioner and the sole owner of a capability that does not exist anywhere else in HUB — the ability to enter a TechOps service domain, assess what exists, identify what is missing, and produce the process and control documentation that makes operationalization possible. This is not a supporting role. It is a self-directing, domain-facing discipline that operates across immediate, mid-term, and long-term horizons simultaneously. In the immediate term, this role conducts discovery interviews with Domain Leads, maps current-state processes, and identifies control gaps against the Technology Governance framework. In the mid-term, it drives operationalization — translating findings into workflow requirements, control design inputs, and actionable backlog items. In the long-term, it builds the analytical muscle and process discipline within domains that sustains what Technology Governance stands up. The right candidate arrives with their own methodology — developed through years of doing this kind of work in regulated environments — and adapts it to HUB's framework and culture. They do not need a playbook. They write one.

Requirements

  • Expert-level ability to assess, map, and document operational processes — current state, gaps, requirements, and improvement opportunities — across diverse technology domains
  • Comfortable working with ambiguity — enters domains with no existing documentation and produces structured outputs from unstructured information
  • Applies the right documentation format to the right purpose — process maps, workflow narratives, swimlane diagrams, gap registers — deliberately and without prompting
  • Understands the full documentation tier structure and the content boundaries between tiers — knows what belongs in a corporate policy versus an operational standard versus an SOP versus a control document, and can identify when tier boundaries have been violated or when a tier is missing entirely
  • Deep working knowledge of IT General Controls — access management, change management, computer operations, and SDLC — and what operationalized controls look like in practice
  • Understands ITGC control requirements well enough to assess whether a process produces defensible audit evidence
  • Familiar with ITIL, COSO, COBIT, or equivalent frameworks as operational design tools — not theoretical constructs
  • Structures and conducts discovery interviews independently — surfaces what isn't being volunteered and comes away with what is needed
  • Extracts institutional knowledge from practitioners who have never been asked to articulate what they do and turns it into documented, referenceable process
  • Recognizes the difference between what a domain team says they do and what they actually do — and documents both
  • Assesses control gaps with enough rigor to distinguish between a minor documentation deficiency and a material control weakness
  • Self-directs across immediate, mid-term, and long-term work horizons without losing track of what matters most right now
  • Communicates risk in terms that inform decisions — not in technical language that obscures it
  • Arrives with a developed methodology and adapts it to HUB's framework, culture, and regulatory context without requiring a defined playbook
  • Builds working relationships with Domain Leads through demonstrated competence — earns access and candor by showing up prepared and following through
  • Operates without direct authority — influence is the tool; expertise and reliability are what make it work
  • Maintains objectivity — documents what is real, not what is convenient, even when findings are uncomfortable
  • Practitioner with a track record — not a candidate building toward one
  • Years of experience doing process assessment and control operationalization work in environments where regulatory scrutiny was real and audit findings had consequences
  • Experience standing up capabilities that didn't exist before, worked in domains where nothing was documented, and produced outputs that held up when examined
  • Senior GRC or controls advisory experience in a regulated industry — financial services, insurance, or healthcare — with direct involvement in ITGC assessment and operationalization
  • Familiarity with internal audit activities and what auditors look for when assessing control environments — enough exposure to design processes that produce defensible evidence
  • Process improvement or operational excellence leadership in a technology organization with regulatory obligations — ITIL, COSO, or equivalent framework fluency applied to real control environments
  • 5-7 years of relevant experience

Nice To Haves

  • Familiarity with ServiceNow, SailPoint, Optro or equivalent GRC platforms, and SharePoint-based governance libraries is useful.

Responsibilities

  • Process design and operationalization support
  • Support control design by providing process analysis, workflow documentation, and current-state context that informs design decisions
  • Identify where existing processes can be modified to produce control evidence systematically — reducing manual burden on domain teams
  • Recommend process improvements that serve both operational efficiency and control integrity
  • Recognize when a process problem requires escalation to the Control Operationalization Manager versus when it can be resolved through documentation and workflow adjustment
  • Discovery and current-state assessment
  • Conduct independent discovery interviews with Domain Leads and domain team members across TechOps service domains — no facilitation support required
  • Map current-state processes with enough fidelity to identify where controls exist, where they are insufficient, and where they are absent entirely
  • Assess domain documentation coverage across the full Technology Governance framework hierarchy — from corporate policies and standards through operational policies, operational standards, SOPs, control documents, monitoring reports, control evidence reports, and domain records — identifying where the documentation chain is intact, where it is broken, and where it does not exist
  • Document workflow requirements — inputs, outputs, decision points, handoffs, system dependencies, and evidence production points — in formats that feed control design and documentation production
  • Assess process maturity honestly — distinguish between processes that exist and are followed, processes that exist on paper only, and processes that have never been formally defined
  • Surface undocumented institutional knowledge and operational workarounds that represent both risk and design opportunity
  • Control gap analysis
  • Evaluate domain processes against Technology Governance control framework requirements — identifying gaps and deficiencies with enough specificity to act on
  • Distinguish between a documentation gap and an operational gap — know which one you are looking at and document it as such
  • Assess the risk profile of identified gaps — severity, regulatory exposure, and operational consequence — and communicate findings in terms that inform prioritization decisions
  • Identify compensating controls where primary controls are absent — and document whether they are sufficient or temporary
  • Operationalization backlog management
  • Own and maintain the operationalization backlog as the authoritative record of Technology Governance's open work across TechOps service domains
  • Translate discovery findings and gap analysis outputs into discrete, actionable backlog items — scoped, described, and linked to the framework requirements they address
  • Track implementation progress — flag items that are stalled, dependent on domain team action, or at risk of missing committed timelines
  • Maintain backlog integrity — ensure items are current, accurately described, and reflect the real state of operationalization across the function
  • Domain advisory
  • Build trusted working relationships with Domain Leads — earned through competence and follow-through, not org chart position
  • Communicate findings, gaps, and recommendations in terms that resonate with domain practitioners — not in governance language that creates distance
  • Maintain enough domain context over time to recognize when operational changes have control implications — and surface them without waiting to be asked

Benefits

  • health/dental/vision/life/disability insurance
  • FSA, HAS and 401(k) accounts
  • paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays
  • annual bonuses
  • equity
  • commissions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service