Lead Associate Principal, Security Assurance

Posted Yesterday
Be an Early Applicant
2 Locations
Hybrid
133K-218K Annually
Senior level
Big Data • Cloud • Fintech • Information Technology • Financial Services
We clear and settle trades for the options industry.
The Role
Lead security assessments and third-party risk reviews, collaborate with security engineering and threat teams, manage observation risk tracking, recommend risk methodologies, enhance Security Assurance processes (including automation/AI opportunities), and support remediation, training, and governance activities.
Summary Generated by Built In
*****THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP*****

To be considered for this position, applications and resumes are accepted only through our careers site by directly applying to the posted job. We do not accept unsolicited resumes or sales solicitations from staffing agencies. Any OCC employee wishing to submit a referral must do so through their Workday account. Any resume submitted outside of an active job posting will not be considered for employment.

What You’ll Do:

The Lead Associate Principal, Security Assurance is responsible for leading the scoping, planning, conducting, and reporting of various Security assessments, including collaboration with other Security teams to assess risk and requirements for new technology onboarding and PoCs, Third Party Security Assessments to support OCC’s Third Party Risk Management team, assisting with oversight of the Security Observation Risk Tracking process, and special risk assessments as requested by the CSO or DCSO.  This position includes supporting Security Assurance team members in the development of these various risk assessments listed above. 

Secondary responsibilities include developing and enhancing Security Assurance processes. This includes automation enhancements, the advancement of Cyber Risk practices, and updating relevant policies and procedures to reflect these changes.

Primary Duties and Responsibilities:

To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.

  • Scoping, planning, conducting, and reporting Security assessments for internal departments and of OCC third parties and technologies

  • Collaborate with the Security Engineering & Technology Integration and Threat Intelligence teams to assess risk and set security requirements for new technology onboarding and PoCs

  • Assist with oversight of the Security Observation Risk Tracking process which includes processing security observations nominated from various sources, assessing risk ratings for observations, communicating observations to risk owners, and managing the observation lifecycle

  • Participate in Security review and approval of Linux server privilege elevation, proxy exception, and firewall exception requests

  • Participate in Security review and approval of Risk Intake, Risk Action Plan, and Risk Acceptance records managed by the Operational Risk Management & Controls team

  • Research and recommend new or updated risk assessment methodologies, frameworks, and standards

  • Assist with other Security Assurance Program efforts including but not limited to tracking of remediation and validation of audit, compliance, and regulatory findings as needed.

  • Collaborate with automation and AI teams to assess opportunities for incorporating AI into team processes

  • Documenting process flow enhancements and working with Security Business Operations to develop and enhance Security Assurance processes.

  • Assist Security Analysts, transferring technical and risk management knowledge

  • Partnering with IT department to disseminate, train, and provide guidance against the Security requirements

  • Assist in project planning, program development, and process formalization.

  • Perform other duties as assigned

Supervisory Responsibilities:

  • None

Qualifications:

The requirements listed are representative of the knowledge, skill, and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.

  • Effective oral and written communication, analytical, judgment and collaboration skills.

  • Analytical skills to successfully analyze, model, and present complex risk assessments

  • Ability to work independently and effectively with local and remote OCC staff, management, vendors, and consultants while exercising sound judgment

  • Strong understanding of information technology, risk management concepts, and analytics

  • Possesses critical OCC values (i.e., fact based, collaborative, credibility/trust and judgment).

Technical Skills:

  • Advanced understanding of information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO etc.

  • Experience in security risk management principles and practices.

  • Experience in working with regulatory frameworks and requirements relevant to OCC such as, Reg SCI, CFTC 99.18, etc.

  • Experience working in ServiceNow, Tableau, Archer GRC, Jira, and Confluence

Education and/or Experience:

  • 5 years hands-on Information Security experience, preferably within previous work in Compliance, Audit, Risk Management, or Security.

  • Bachelor’s degree in Computer Science, Management Information Systems, Statistics & Quantitative Modeling, Mathematics a plus or the equivalent combination of education and/or relevant experience.

Certificates or Licenses:

  • Professional network and/or security certifications are a plus, but not required (i.e., GIAC, CISSP, CISA, CISM, CRISC, AWS cloud computing)

About Us

The Options Clearing Corporation (OCC) is the world's largest equity derivatives clearing organization. Founded in 1973, OCC is dedicated to promoting stability and market integrity by delivering clearing and settlement services for options, futures and securities lending transactions. As a Systemically Important Financial Market Utility (SIFMU), OCC operates under the jurisdiction of the U.S. Securities and Exchange Commission (SEC), the U.S. Commodity Futures Trading Commission (CFTC), and the Board of Governors of the Federal Reserve System. OCC has more than 100 clearing members and provides central counterparty (CCP) clearing and settlement services to 19 exchanges and trading platforms. More information about OCC is available at www.theocc.com.

Benefits

A highly collaborative and supportive environment developed to encourage work-life balance and employee wellness. Some of these components include:

  • A hybrid work environment, up to 2 days per week of remote work
  • Tuition Reimbursement to support your continued education
  • Student Loan Repayment Assistance
  • Technology Stipend allowing you to use the device of your choice to connect to our network while working remotely
  • Generous PTO and Parental leave
  • 401k Employer Match
  • Competitive health benefits including medical, dental and vision

Visit https://www.theocc.com/careers/thriving-together for more information.

Compensation

  • The salary range listed for any given position is exclusive of fringe benefits and potential bonuses. If hired at OCC, your final base salary compensation will be determined by factors such as skills, experience and/or education.
  • In addition, we believe in the importance of pay equity and consider internal equity of our current team members as part of any final offer.
  • We typically do not hire at the maximum of the range in order to allow for future and continued salary growth. We also offer a substantial benefits package as noted on www.theocc.com/careers
  • All employees may be eligible for a discretionary bonus. Discretionary bonuses are based on various factors, including, but not limited to, company and individual performance and are not guaranteed.

Salary Range

$132,500.00 - $218,300.00

Incentive Range

8% to 15%

This position is eligible for an annual discretionary incentive compensation award, for which the target range is listed above (see Incentive Range). The amount of such award, if any, will be based on various factors, including without limitation, both individual and company performance.

Step 1
When you find a position you're interested in, click the 'Apply' button. Please complete the application and attach your resume.  

Step 2
You will receive an email notification to confirm that we've received your application.

Step 3
If you are called in for an interview, a representative from OCC will contact you to set up a date, time, and location. 

For more information about OCC, please click here.

OCC is an Equal Opportunity Employer

Skills Required

  • 5 years hands-on Information Security experience
  • Bachelor's degree in Computer Science, MIS, Statistics, Mathematics or equivalent experience
  • Advanced understanding of frameworks such as COBIT, NIST 800-53, NIST CSF, ISO
  • Experience in security risk management principles and practices
  • Experience with regulatory frameworks relevant to OCC (e.g., Reg SCI, CFTC 99.18)
  • Experience working in ServiceNow, Tableau, Archer GRC, Jira, and Confluence
  • Strong understanding of information technology, risk management concepts, and analytics
  • Effective oral and written communication, analytical, judgment and collaboration skills
  • Ability to work independently and effectively with local and remote staff, vendors, and consultants
  • Professional network and/or security certifications (GIAC, CISSP, CISA, CISM, CRISC, AWS) are a plus

What the Team is Saying

Bailey
Daniel
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,200 Employees
Year Founded: 1973

What We Do

As the foundation for secure markets, OCC is a customer-driven organization that delivers world-class Risk Management, Clearing, and Settlement Services for a sophisticated mix of financial products that includes standard options, stock loans, and futures contracts.

Why Work With Us

We're bound together by values and behaviors that shape the way we work and live, from team projects to after-hours events and to making a difference in our communities. OCC colleagues thrive in an atmosphere of intellectual curiosity, creative problem-solving and effective interaction.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

OCC Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

A hybrid work environment, up to 2 days per week of remote work

Typical time on-site: 3 days a week
Company Office Image
HQChicago, IL
Company Office Image
Dallas, TX
Company Office Image
Washington, DC
Learn more

Similar Jobs

OCC Logo OCC

Manager, Software Engineering: Middleware

Big Data • Cloud • Fintech • Information Technology • Financial Services
Hybrid
2 Locations
1200 Employees
136K-188K Annually

OCC Logo OCC

Lead Associate Principal, Security Engineering

Big Data • Cloud • Fintech • Information Technology • Financial Services
Hybrid
2 Locations
1200 Employees
145K-237K Annually

OCC Logo OCC

Director, Member Services

Big Data • Cloud • Fintech • Information Technology • Financial Services
Hybrid
2 Locations
1200 Employees
153K-200K Annually

OCC Logo OCC

Associate Principal, Network Engineering

Big Data • Cloud • Fintech • Information Technology • Financial Services
Hybrid
2 Locations
1200 Employees
109K-155K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account