Jobs and Careers
OC

Senior Associate, Operational Risk Management - IT and Security

OCC
United StatesRemotefull_timeVerifiedPosted 16 Jun 2025
💰 $98,900/yr($70,300/yr$98,900/yr)

About the role

What You'll Do:

This role will provide critical support to the Director of Operational Risk to evaluate IT and Security risks by assisting with risk assessments and applying aspects of the risk management framework across the process, risk, and control universe. Additionally, this role will help with the risk assessment program activities, coordinate with other functions (e.g. IT, Security, TPRM, Legal, Compliance, and Internal Audit) and facilitate appropriate Corporate Risk governance to ensure alignment to OCC strategy and short-term objectives.

Primary Duties and Responsibilities:

To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.

  • Collaborate with IT, Security, TPRM, Legal, Compliance, and Internal Audit to ensure that Corporate Risk contributes to strengthening the overall effective management of IT and Security risk across the organization.

  • Lead OCC’s risk identification and assessment process for IT/Security risks and verify the consistency and reliability of the associated technology frameworks (e.g., NIST, COBIT, ISO) and systems supporting clearing and settlement activities.

  • Drive adherence to methodologies, guidance, and standards applicable to risk identification and assessment frameworks.

  • Maintain risk inventories, taxonomies, and other elements supporting IT/Security risk management and compliance activities.

  • Lead and execute the IT and Security risk assessment process, while aligning to the risk and control universe, and regulatory requirements and expectations.

  • Generate reports of Archer data for various stakeholders, including regulators.

  • Help automate IT & Security risk oversight through use of data analytics processes.

  • Communicate results of risk assessments to governance committees, business owners, and various levels of leadership.

  • Collaborate on the enhancement and maintenance of Corporate Risk program methodologies, policies, procedures, and job aides, including the development of new program activities.

  • Track and update ORMC team internal findings, external exam issues, and business area self-identified issues resulting from Enterprise Risk Assessment.

Supervisory Responsibilities:

  • None

Qualifications:

The requirements listed are representative of the knowledge, skill, and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.

  • [Required] Advanced understanding of IT risk and Security risk, specifically relating to cybersecurity (e.g., blue team, red team, threat & vulnerability management), disaster recovery, database management, network engineering, storage management, software development, and mainframe technologies. Intermediate understanding of Operational risk.

  • [Required] Familiarity with the evolving cybersecurity landscape impacting central clearing counterparties (CCPs).                                                                                                                                       

  • [Required] Ability to act as a trusted advisor and provide effective challenge.

  • [Required] Creative, independent thinker, with a willingness to develop and drive new ideas.

  • [Required] Excellent written, verbal and presentation skills.

  • [Required] Must be team-oriented and be able to collaborate effectively in department and cross-departmental efforts.

  • [Required] Ability to work under pressure and with tight deadlines.

  • [Preferred] Familiarity with Financial Market Utilities; securities and derivatives markets.

  • [Preferred] Ability to work in a highly regulated environment, including with the SEC, CFTC, and Federal Reserve; Familiarity with the Covered Clearing Agency regulations.

  • [Preferred] Understanding of cloud technologies, including experience supporting migration to a cloud platform.

  • [Preferred] Understanding of tools supporting capacity management, network architecture, threat assessment, code review, and software development.

Technical Skills:

  • [Required] Proficient in Microsoft Word, Excel, Access, and PowerPoint.

  • [Required] Experience with eGRC systems (e.g., Archer).

  • [Required] Experience with data analytic techniques and tools (e.g., Tableau, SQL).

Education and/or Experience:

  • [Required] Bachelor’s Degree in Information Systems, Computer Science, Cybersecurity (or equivalent) preferred.

  • [Required] 3+  years of experience in enterprise risk, cybersecurity, IT a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

OCC

View company profile →