Skip to main content
Back to jobs

Lead Associate Principal, Security Assurance

External
theocc logoTheocc · Chicago - 125 S Franklin
Full-timeRemote1w ago
AWSComplianceConfluenceInformation SecurityJiraLinux
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

The Options Clearing Corporation (OCC) is the world's largest equity deri

Responsibilities

  • Secondary responsibilities include developing and enhancing Security Assurance processes. This includes automation enhancements, the advancement of Cyber Risk practices, and updating relevant policies and procedures to reflect these changes.
  • Primary Duties and Responsibilities:
  • To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.
  • Scoping, planning, conducting, and reporting Security assessments for internal departments and of OCC third parties and technologies
  • Collaborate with the Security Engineering & Technology Integration and Threat Intelligence teams to assess risk and set security requirements for new technology onboarding and PoCs
  • Assist with oversight of the Security Observation Risk Tracking process which includes processing security observations nominated from various sources, assessing risk ratings for observations, communicating observations to risk owners, and managing the observation lifecycle
  • Participate in Security review and approval of Linux server privilege elevation, proxy exception, and firewall exception requests
  • Participate in Security review and approval of Risk Intake, Risk Action Plan, and Risk Acceptance records managed by the Operational Risk Management & Controls team
  • Research and recommend new or updated risk assessment methodologies, frameworks, and standards
  • Assist with other Security Assurance Program efforts including but not limited to tracking of remediation and validation of audit, compliance, and regulatory findings as needed.
  • Collaborate with automation and AI teams to assess opportunities for incorporating AI into team processes
  • Documenting process flow enhancements and working with Security Business Operations to develop and enhance Security Assurance processes.
  • Assist Security Analysts, transferring technical and risk management knowledge
  • Partnering with IT department to disseminate, train, and provide guidance against the Security requirements
  • Assist in project planning, program development, and process formalization.
  • Perform other duties as assigned
  • Supervisory Responsibilities:
  • None

Requirements

  • The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.
  • Effective oral and written communication, analytical, judgment and collaboration skills.
  • Analytical skills to successfully analyze, model, and present complex risk assessments
  • Ability to work independently and effectively with local and remote OCC staff, management, vendors, and consultants while exercising sound judgment
  • Strong understanding of information technology, risk management concepts, and analytics
  • Possesses critical OCC values (i.e., fact based, collaborative, credibility/trust and judgment).
  • Technical Skills:
  • Advanced understanding of information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO etc.
  • Experience in security risk management principles and practices.
  • Experience in working with regulatory frameworks and requirements relevant to OCC such as, Reg SCI, CFTC 99.18, etc.
  • Experience working in ServiceNow, Tableau, Archer GRC, Jira, and Confluence
  • Education and/or Experience:
  • 5 years hands-on Information Security experience, preferably within previous work in Compliance, Audit, Risk Management, or Security.
  • Bachelor's degree in Computer Science, Management Information Systems, Statistics & Quantitative Modeling, Mathematics a plus or the equivalent combination of education and/or relevant experience.
  • Certificates or Licenses:
  • Professional network and/or security certifications are a plus, but not required (i.e., GIAC, CISSP, CISA, CISM, CRISC, AWS cloud computing)

Benefits

Remote work optionsEquity / stock options

Additional Information

*****THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP***** To be considered for this position, applications and resumes are accepted only through our careers site by directly applying to the posted job. We do not accept unsolicited resumes or sales solicitations from staffing agencies. Any OCC employee wishing to submit a referral must do so through their Workday account. Any resume submitted outside of an active job posting will not be considered for employment.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at theocc? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect