We are seeking an experienced, forward-thinking Vice President of IT Governance, Risk & Compliance (IT GRC) to lead and transform the enterprise IT GRC function. This executive leader will be responsible for establishing and advancing a modern, technology-enabled governance, risk, compliance, and regulatory response program that supports the company mission, protects customers, and enables business growth.
This role requires an exceptional leader who can operate at the intersection of cybersecurity, technology, risk management, audit, regulation, and business strategy. The successful candidate will possess deep knowledge of cybersecurity and technology risks, extensive experience within highly regulated industries, and a demonstrated ability to build scalable programs leveraging automation, data intelligence, continuous assurance, and artificial intelligence.
The Vice President will serve as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders while driving a culture of accountability, transparency, and risk-informed decision making across the enterprise.
Primary Duties & Responsibilities
Strategic Leadership
- Develop and execute a multi-year vision and strategy for the IT GRC organization aligned with enterprise objectives, technology strategy, and cybersecurity priorities.
- Transform traditional compliance and risk management practices into a modern, data-driven operating model emphasizing automation, scalability, and continuous monitoring.
- Build a high-performing organization that attracts, develops, and retains top talent across governance, compliance, risk management, and regulatory disciplines.
- Partner closely with Cybersecurity, Technology, Enterprise Risk Management, Internal Audit, Legal, Privacy, and business leadership to ensure integrated risk management across the enterprise.
Governance & Risk Management
- Oversee enterprise IT governance frameworks, policies, standards, controls, and risk management processes.
- Ensure effective identification, assessment, measurement, monitoring, and reporting of technology and cybersecurity risks.
- Drive maturation of risk management capabilities through improved metrics, analytics, and automation.
- Develop meaningful executive and board-level reporting that translates technical risks into business and financial impacts.
Regulatory Compliance & Audit
- Lead compliance efforts related to applicable technology and cybersecurity regulations and standards.
- Maintain readiness for regulatory examinations and external reviews.
- Serve as the primary executive sponsor for technology and cybersecurity audits, examinations, and regulatory engagements.
- Establish sustainable and defensible compliance practices that withstand both regulatory and audit scrutiny.
- Drive remediation of audit findings and regulatory concerns through risk-based prioritization and measurable outcomes.
Technology & Cybersecurity Leadership
- Provide strategic oversight for technology and cybersecurity governance programs.
- Partner with cybersecurity leadership to assess and manage emerging threats, control effectiveness, security maturity, and operational risk.
- Apply practical cybersecurity experience to improve governance and risk outcomes rather than relying solely on theoretical compliance models.
- Maintain awareness of evolving threat landscapes, technology trends, cloud risks, AI-related risks, and cybersecurity regulations.
Modernization, Automation & AI
- Champion modernization of IT GRC practices through automation, workflow orchestration, advanced analytics, and data-driven decision making.
- Lead the adoption of continuous assurance capabilities that reduce manual evidence collection and repetitive compliance activities.
- Drive elimination of duplicate processes and fragmented controls across governance, risk, and compliance programs.
- Establish governance frameworks and oversight mechanisms for emerging AI technologies and AI-enabled business processes.
- Foster a culture that embraces innovation while maintaining appropriate risk management and regulatory compliance.
Executive & Board Engagement
- Serve as a trusted advisor to the CISO, CIO, executive leadership team, and governance committees.
- Deliver concise, compelling, and actionable briefings to senior executives, board committees, auditors, and regulators.
- Translate complex technical, cyber, and regulatory issues into language appropriate for executive and board audiences.
- Build strong relationships across the organization to influence decision making and achieve strategic outcomes.
Qualifications
Required Qualifications
- A cybersecurity leader who understands governance and compliance, not simply a compliance leader who understands regulations.
- A technology strategist who understands how platforms, integrations, automation, and AI enable scalable risk management.
- 15+ years of progressive leadership experience across IT governance, risk management, compliance, audit, cybersecurity, or technology management.
- Demonstrated experience leading large-scale enterprise programs within a highly regulated environment.
- Strong understanding of information technology, cybersecurity architectures, cloud technologies, identity and access management, data protection, and technology operations.
- Extensive experience managing regulatory compliance programs and interactions with internal and external auditors.
- Proven experience presenting to executive leadership teams, board committees, regulators, and auditors.
- Demonstrated success developing enterprise-wide governance, risk, compliance, or cybersecurity programs.
- Exceptional executive communication, influencing, and relationship management skills.
Preferred Qualifications
- Experience within the insurance industry strongly preferred.
- Experience within financial services, banking, wealth management, or other highly regulated industries.
- Prior leadership experience in a cybersecurity discipline such as cyber defense, security engineering, identity and access management, security architecture, incident response, risk management, or security operations.
- Experience implementing or leading modern GRC platforms and technology-enabled compliance programs.
- Experience leading large-scale compliance transformations, automation initiatives, or digital modernization programs.
- Knowledge of emerging AI governance, model risk management, and technology ethics practices.
- Professional certifications such as CISSP, CISM, CRISC, CGEIT, CISA, CPA, CIA, or equivalent.
Compensation Range:
Pay Range - Start:
$220,000.00
Pay Range - End:
$330,000.00
This role is eligible for additional short-term and long-term incentive compensation.
We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.
Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!
Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.
FIND YOUR FUTURE
We're excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.
- Flexible work schedules
- Concierge service
- Comprehensive benefits
- Employee resource groups
Skills Required
- 15+ years of progressive leadership experience across IT governance, risk management, compliance, audit, cybersecurity, or technology management
- Experience leading large-scale enterprise programs within a highly regulated environment
- Strong understanding of information technology, cybersecurity architectures, cloud technologies, identity and access management, data protection, and technology operations
- Extensive experience managing regulatory compliance programs and interactions with internal and external auditors
- Experience presenting to executive leadership teams, board committees, regulators, and auditors
- Success developing enterprise-wide governance, risk, compliance, or cybersecurity programs
- Exceptional executive communication, influencing, and relationship management skills
- Cybersecurity leadership experience with understanding of governance and compliance
- Technology strategy experience involving platforms, integrations, automation, and AI for scalable risk management
- Insurance industry experience
- Experience in financial services, banking, wealth management, or another highly regulated industry
- Leadership experience in cybersecurity, such as cyber defense, security engineering, identity and access management, security architecture, incident response, risk management, or security operations
- Experience implementing or leading modern GRC platforms and technology-enabled compliance programs
- Experience leading large-scale compliance transformations, automation initiatives, or digital modernization programs
- Knowledge of AI governance, model risk management, and technology ethics practices
- Professional certification such as CISSP, CISM, CRISC, CGEIT, CISA, CPA, CIA, or equivalent
Northwestern Mutual Compensation & Benefits Highlights
-
Retirement Support — Corporate materials describe automatic 401(k) company contributions alongside a separate, company‑funded cash balance pension with a guaranteed interest credit. This dual‑plan design is highlighted as a standout element for corporate roles.
-
Leave & Time Off Breadth — PTO is outlined as starting in the low‑20s of days per year and increasing with tenure, with paid parental and caregiving leave and volunteer time included. This structure signals generous time‑off support for different life stages.
-
Healthcare Strength — Medical, dental, and vision coverage is paired with Lyra mental health services, fertility and family‑building support, and company‑paid disability and life insurance. On‑site health centers, virtual primary care, and fitness centers or reimbursements enhance everyday access and wellbeing.
Northwestern Mutual Insights
What We Do
You’ll Like It Here At Northwestern Mutual, we believe that our lives and our work matter. And that doing what’s right is good for everyone. We follow through by designing tech that improves the community and cultivating creative ways to make finance accessible anywhere. These guiding principles have allowed our company to grow for more than 160 years. Here, you’ll be with a team who emphasizes integrity and prioritizes security to design experiences that better everyone. You’ll work in cross functional teams to create optimal solutions that are rooted in innovative strategy and thoughtful execution. And you’re provided development tools and opportunities to become a leader all with the support of a collaborative team. You’ll be surrounded in a culture that values innovation and works to always evolve to stay ahead of trends and client needs. We are intentional in seeking out team members who will challenge us. Our employees choose us for the career opportunities, commitment to philanthropy and desire to have a meaningful impact in the lives of our clients. You have career passions and goals. We have ambition and opportunity for you to grow your future in tech. Discover today: https://careers.northwesternmutual.com/
Why Work With Us
We invest in our people. We know careers are about choices, so we provide intentional opportunity. Here you can build creative ways to make finance accessible anywhere and revolutionize traditional processes. As a mutual company, our focus is our people — whether professional development or investments in the community.
Gallery
Northwestern Mutual Teams
Northwestern Mutual Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We offer a flexible, hybrid approach for our employees . Teams are in the office a few days a week and work from home the others.









