IT and Cybersecurity Regulatory Response Lead
Job Description
Northwestern Mutual invites you to join a benefits-forward culture that prioritizes flexibility, support, and professional growth. Flexible work schedules, a concierge service, comprehensive benefits, and active employee resource groups create a balanced environment for a role that drives critical regulatory programs. This onsite position in Milwaukee leads the second-line IT SOX/MAR program and cybersecurity regulatory response, collaborating with IT control owners, controllership, and auditors to build an automated, continuous controls assurance program powered by ServiceNow.
Location: Milwaukee, Wisconsin on site
Salary: USD 118,960 - 205,200 per year
Geographic pay structure:
- Structure 110: 130,880 - 196,320 USD
- Structure 115: 136,800 - 205,200 USD
Responsibilities
- Own and steer the second-line IT SOX/MAR program, contributing directly while guiding junior members of the second-line IT SOX/MAR team.
- Serve as the primary accountable stakeholder for a unified program that covers IT SOX/MAR requirements and state cybersecurity regulations, including New York DFS Part 500, California Privacy Act Article 9, and Wisconsin Insurance Data Security Law.
- Represent IT SOX/MAR and cybersecurity regulatory needs within IT GRC and cybersecurity efforts to build an automated continuous controls assurance program using a unified data platform and ServiceNow.
- Develop relationships with first-line IT teams responsible for in-scope applications and infrastructure, providing guidance and collaboration.
- Articulate technical positions and align with third-line auditors on scoping rationale, control coverage, and IT process conclusions in areas with findings, expanding involvement across other cybersecurity and regulatory programs over time.
- Identify and manage dependencies between business process and accounting components of the IT SOX/MAR program and the IT program, including segregation of duties, IT application scoping, and risks from interfaces between in-scope systems.
- Automate and enhance IT SOX/MAR processes, with an eye toward future system development and data engineering capabilities to support evolving program needs.
Requirements
- Bachelor’s degree in MIS, Accounting, Business, or a related field, or equivalent relevant experience.
- 8 to 12 years of experience in information systems, systems audit, IT controls, or a related technology risk and compliance discipline; 6 to 8 years in technology risk, IT audit, or regulatory compliance within public accounting, consulting, or professional services is preferred.
- Technical understanding of IT SOX/MAR program design.
- Experience building or enhancing regulatory compliance programs; financial services industry experience is a plus.
- 1 to 2 years of people leadership experience.
- Strong relationship management, influence, communication, negotiation, and professional judgment skills.
- Proven ability to independently identify and resolve critical and complex issues through effective problem solving.
- Ability to operate effectively in ambiguous situations and bring structure to complex work.
Technologies
- ServiceNow
Benefits
- Flexible work schedules
- Concierge service
- Comprehensive benefits
- Employee resource groups
Find Your Future
- Flexible work schedules
- Concierge service
- Comprehensive benefits
- Employee resource groups