Jobs and Careers
UN

Team Leader, IT Governance, Risk, & Compliance

United Wholesale Mortgage
United Statesfull_timeVerifiedPosted 5 Sept 2025

About the role

 

As the Information Security - GRC Team Leader at United Wholesale Mortgage (UWM), you will spearhead information security initiatives aimed at minimizing risks and maximizing compliance across the organization. You will lead a team responsible for assessments, audit fulfillment, risk remediation, and governance of business data and records. Your strategic oversight will be critical to key programs including Business Continuity/Disaster Recovery, IT Risk Management, Third Party Risk Management, Data Governance, Security Awareness and more.

This role will monitor performance of various GRC Programs, drive specific initiatives, and foster a culture of security awareness through effective coaching and leadership. You will ensure that all planning, coordination, and execution of work assignments align with the strategic priorities established by the Information Security Team Lead.

WHAT YOU WILL BE DOING

Key Responsibilities

  • Cybersecurity Compliance: Oversee the development and implementation of comprehensive cybersecurity compliance programs within the IT department that align with industry standards and regulatory requirements. Regularly assess compliance status and facilitate audits to ensure adherence to relevant laws and regulations, including IT laws and regulations.
  • Cybersecurity Awareness: Foster a culture of security awareness within the IT department by developing and delivering training programs that educate employees on cybersecurity best practices, data privacy, and compliance obligations. Establish ongoing professional development opportunities for team members to stay current with GRC trends and technologies.
  • Business Continuity and Disaster Recovery: Manage the IT department’s business continuity planning and disaster recovery efforts. Ensure that plans are regularly updated, tested, and effectively communicated to minimize disruption during unforeseen events.
  • Data Governance and Privacy: Enhance data governance frameworks within the IT department to ensure data integrity, security, and compliance with regulations. Collaborate with stakeholders to document data privacy requirements and implement processes for effective data management, ensuring that data privacy practices are integrated into governance strategies.
  • Third-Party Risk Management: Lead the third-party risk management program within the IT department, establishing evaluation criteria and remediation processes. Conduct regular assessments of vendors and service providers to identify and mitigate risks associated with third-party relationships, ensuring ongoing compliance through regular reviews.
  • Cyber Insurance: Oversee the IT department’s cyber insurance policies, ensuring coverage aligns with the risk profile and compliance requirements. Manage claims and liaise with insurance providers to address any incidents effectively.
  • IT Risk Management: Develop and maintain a robust IT risk management framework that identifies, assesses, and mitigates risks associated with information technology and security in the IT department. Conduct regular risk assessments to identify potential vulnerabilities and prepare detailed risk reports for senior leadership.
  • Artificial Intelligence Regulation: Stay informed about emerging regulations and best practices related to artificial intelligence that impact the IT department, ensuring strategies align with compliance requirements and ethical considerations.
  • State and Federal Audits: Facilitate state and federal audits and regulatory reviews within the IT department, ensuring all necessary documentation and evidence are prepared and available. Collaborate with regulatory bodies to address findings and implement necessary changes.
  • Incident Response Management: Develop and manage the incident response plan, ensuring the IT department is prepared to respond effectively to security incidents. Conduct post-incident reviews to identify lessons learned and areas for improvement.
  • Policy Development and Management: Lead the creation, review, and maintenance of security and compliance policies across the IT department, ensuring they are up-to-date and reflect the current regulatory landscape.
  • Monitoring and Metrics: Implement continuous monitoring mechanisms for compliance and risk management activities, utilizing key performance indicators (KPIs) to assess the effectiveness of GRC initiatives.
  • Regulatory Change Management: Monitor changes in regulations and standards that may impact the IT department, leading initiatives to adapt policies and practices accordingly.
  • Stakeholder Engagement: Engage with st

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

United Wholesale Mortgage

View company profile →