Lead Associate Principal, Security Governance
OCCAbout the role
*****THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP*****
To be considered for this position, applications and resumes are accepted only through our careers site by directly applying to the posted job. We do not accept unsolicited resumes or sales solicitations from staffing agencies. Any OCC employee wishing to submit a referral must do so through their Workday account. Any resume submitted outside of an active job posting will not be considered for employment.
What You'll Do:
The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management Compliance, Internal Audit, Legal, and OCC’s Regulators. This role will lead the end-to-end lifecycle and change management of Security Services policies, procedures, standards, and control documentation, including the development, review, approval, publication, and retirement, in support of the NIST Cyber Security framework. Additionally, this person is responsible for supporting information security initiatives related to regulatory exam and Internal Audit remediation planning, tracking, and mitigation. Likewise, this role will provide subject matter expertise in reviewing the management self-testing efforts for the Security Service Department by identifying, recommending, and driving enhancements to the performance, integrity, and compliance of the organization’s processes.
This role will also focus on compliance with applicable regulatory statutes and legal rules and requirements (i.e. SEC-Regulation SCI, CFTC-System Safeguards, etc.) as they relate to information security.
Primary Duties and Responsibilities:
To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.
Provide subject matter expertise in the development, review, and continuous improvement of Security Services policies, procedures, and controls, ensuring documentation remains current, appropriately governed, and aligned with applicable regulatory requirements, industry frameworks, and OCC’s risk management objectives.
Recommendation and oversight of appropriate reporting frameworks, standards, and best practices.
Supporting efforts for remediating regulatory and Internal Audit findings, including analyzing data to identify root cause of problems, identifying trends, formulating solutions, and escalating potential issues related to the lifecycle of remediation.
Act as a supporting point of contact from Security Services to senior management in Compliance, Internal Audit, Enterprise Risk Management, Legal and regulators
Support strategic development, implementation, review, and improvement of right sized management self-testing of controls.
Serve as the governance facilitator for the Security Working Group Program, ensuring the Working Group meets its applicable obligations and requirements including overseeing the maintenance of appropriate governance documentation and records.
Act on Security Services’ behalf related to compliance matters including developing and implementing strategies for strengthening the Security Services compliance posture.
Provide management oversight and subject matter expertise input on Security Services’ responses to Third-Party requests and surveys.
Perform ad-hoc duties for Security Governance management as necessary.
Supervisory Responsibilities:
None
Qualifications:
The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.
Extensive experience in Information Security related policy, procedure and control writing.
Thorough understanding of information technology and risk management concepts
Extensive knowledge of and experience working with Security and Technology authoritative industry standards and control frameworks (e.g. NIST CSF, NIST 800-53, CIS 20, COBIT, COSO, ITIL, ISO 27001, CSA CCM, etc.)
Proficient knowledge of applicable regulatory, legal rules and requirements (e.g., SEC, CFTC, Federal Reserve Board, etc.) as they pertain to Information Security.
Demonstrable proficiency with AI tools (Claude Code)
Working knowledge of Cloud implementation and Cloud compliance strategies including for data, information, application, platform and network security a plus
Deep seated understanding of Systems Development Life Cycle (SDLC) process (Agile) and Secure Software Development Lifecycle a plus
Demonstrative leadership skills and ca
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s