Associate Principal, Security Assurance
$116,100–$158,300 year
HybridChicago, Illinois, United States
Job Summary
Conduct Security risk assessments of OCC third parties and technologies, collaborating with Engineering and Threat Intelligence teams to set requirements for new technology onboarding and PoCs. Assist with oversight of the Security Observation Risk Tracking process, including processing nominations, assessing risk ratings, and managing the observation lifecycle. Support configuration monitoring for CIS Benchmark compliance on Windows and Linux platforms, review privilege elevation requests, and prepare monthly reporting metrics for executive and Board audiences. Manage team request intake for risk assessment applicability and review Risk Action Plans and acceptances from Operational Risk Management. Track remediation and validation of audit, compliance, and regulatory findings as needed.
Required Qualifications
- 5 years hands-on Information Security experience
- Bachelor's degree in Computer Science, Management Information Systems, Statistics & Quantitative Modeling, Mathematics
- Advanced understanding of information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO
- Experience in security risk management principles and practices
- Experience in working with regulatory frameworks and requirements relevant to OCC such as, Reg SCI, CFTC 99.18
- Effective oral and written communication skills
- Analytical skills to successfully analyze, model, and present complex risk assessments
- Ability to work independently and effectively with local and remote OCC staff, management, vendors, and consultants while exercising sound judgment
- Strong understanding of information technology, risk management concepts, and analytics
- Possesses critical OCC values (i.e., fact based, collaborative, credibility/trust and judgment)
- Experience working in ServiceNow, Tableau, Archer GRC, Jira, and Confluence
Desired Qualifications
- Experience, preferably within previous work in Compliance, Audit, Risk Management, or Security
- Professional network and/or security certifications (i.e., GIAC, CISSP, CISA, CISM, CRISC, AWS cloud computing)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.