Principal GRC / Regulatory / Financial Compliance Engineer
Liberty Mutual InsuranceAbout the role
Pay Philosophy
The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
Description
We deliver our customers peace of mind every day by helping them protect what they value most. Our passion for placing the customer at the center of everything we do is driving a transformational shift at Liberty Mutual. Operating as a tech startup within a Fortune 100 company, we are leading a digital disruption that will redefine how people experience insurance.
This role has a hybrid work schedule (2 days onsite) and we will only consider candidates based in Portsmouth, NH and Indianapolis, IN.
Job introduction:
The GRC (Governance, Risk and Compliance) team within the GCS organization is looking to add a Principal GRC / Regulatory / Financial Compliance Engineer to their team. This candidate will independently execute and assist others in the evaluation and reporting on the effectiveness of security and compliance controls as well as defining risk mitigation strategies in IT and business environments.
As a Principal Cybersecurity Specialist in the Cybersecurity Regulatory Assessment space, you would be responsible for independently designing, executing, evolving, and optimizing our cybersecurity regulatory and contractual assessment programs. Responsibilities would include the coordination, analysis, management, and monitoring of various regulations and harmonizing them with our governing cybersecurity risk and compliance programs, practices, and frameworks. You will support the assurance programs responsible for evaluating the design of controls, identifying data sources and automation opportunities, testing controls, assisting with delivery, and reporting results of our cybersecurity regulatory and contractual requirements in addition to the issues management service for tracking, treatment plan consulting, progress reporting, and closure validation for findings that result from assessment and testing conducted by teams. You will work with stakeholders globally to build awareness, consult on regulatory impacts, implementation and execution of new solutions, understand impacts of new or deprecated technology and business processes, as well as identify and confirm remediation of issues to facilitate successful assessments.
You must have the ability to understand, synthesize, and convey technology and security impacts to stakeholders at all levels of the organization, including management and our first line teams. You will collaborate across our organization and deliver results to internal and external partners, auditors, and regulators.Ideal candidates have a passion for security, the drive to share their expertise, and the ability to collaborate and help teams deliver solutions that meet our business goals while protecting the confidentiality, integrity and availability of information systems and our data.About the job:
- Review and testing of controls and processes to assess, operate and optimize the global cybersecurity regulatory governance operating model.
- Partner with global service delivery and assessment teams to share expertise and adapt programs as necessary to meet regulatory, contractual, or technology needs.
- Lead, contribute to, and influence the definition of a comprehensive global cybersecurity risk and compliance control framework.
- Act as a trusted advisor for interpretation and harmonization of regulatory and contractual cybersecurity drivers and company risk posture.
- Advise on impacts and recommend solutions specific to people, processes, and technology changes in the environment.
- Seek and encourage opportunities for reuse and advise on control design, evaluation, and alignment to support multiple global cybersecurity frameworks, regulatory requirements, and contractual obligations.
- Design test procedures and perform periodic reviews of operating effectiveness of controls and assess compliance to global regulatory requirements and contractual obligations.
- Collaborate and act as liaison to internal and external partners, auditors, and regulators.
- Mentor, lead, and develop team members to deliver ongoing visibility and improvements into enterprise cybersecurity regulatory, contractual, and risk posture.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s