To be considered for this position, applications and resumes are accepted only through our careers site by directly applying to the posted job. We do not accept unsolicited resumes or sales solicitations from staffing agencies. Any OCC employee wishing to submit a referral must do so through their Workday account. Any resume submitted outside of an active job posting will not be considered for employment.
What You'll Do:
The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management Compliance, Internal Audit, Legal, and OCC’s Regulators. This role will lead the end-to-end lifecycle and change management of Security Services policies, procedures, standards, and control documentation, including the development, review, approval, publication, and retirement, in support of the NIST Cyber Security framework. Additionally, this person is responsible for supporting information security initiatives related to regulatory exam and Internal Audit remediation planning, tracking, and mitigation. Likewise, this role will provide subject matter expertise in reviewing the management self-testing efforts for the Security Service Department by identifying, recommending, and driving enhancements to the performance, integrity, and compliance of the organization’s processes.
This role will also focus on compliance with applicable regulatory statutes and legal rules and requirements (i.e. SEC-Regulation SCI, CFTC-System Safeguards, etc.) as they relate to information security.
Primary Duties and Responsibilities:
To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.
Provide subject matter expertise in the development, review, and continuous improvement of Security Services policies, procedures, and controls, ensuring documentation remains current, appropriately governed, and aligned with applicable regulatory requirements, industry frameworks, and OCC’s risk management objectives.
Recommendation and oversight of appropriate reporting frameworks, standards, and best practices.
Supporting efforts for remediating regulatory and Internal Audit findings, including analyzing data to identify root cause of problems, identifying trends, formulating solutions, and escalating potential issues related to the lifecycle of remediation.
Act as a supporting point of contact from Security Services to senior management in Compliance, Internal Audit, Enterprise Risk Management, Legal and regulators
Support strategic development, implementation, review, and improvement of right sized management self-testing of controls.
Serve as the governance facilitator for the Security Working Group Program, ensuring the Working Group meets its applicable obligations and requirements including overseeing the maintenance of appropriate governance documentation and records.
Act on Security Services’ behalf related to compliance matters including developing and implementing strategies for strengthening the Security Services compliance posture.
Provide management oversight and subject matter expertise input on Security Services’ responses to Third-Party requests and surveys.
Perform ad-hoc duties for Security Governance management as necessary.
Supervisory Responsibilities:
None
Qualifications:
The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.
Extensive experience in Information Security related policy, procedure and control writing.
Thorough understanding of information technology and risk management concepts
Extensive knowledge of and experience working with Security and Technology authoritative industry standards and control frameworks (e.g. NIST CSF, NIST 800-53, CIS 20, COBIT, COSO, ITIL, ISO 27001, CSA CCM, etc.)
Proficient knowledge of applicable regulatory, legal rules and requirements (e.g., SEC, CFTC, Federal Reserve Board, etc.) as they pertain to Information Security.
Demonstrable proficiency with AI tools (Claude Code)
Working knowledge of Cloud implementation and Cloud compliance strategies including for data, information, application, platform and network security a plus
Deep seated understanding of Systems Development Life Cycle (SDLC) process (Agile) and Secure Software Development Lifecycle a plus
Demonstrative leadership skills and capabilities
Highly proficient in collaborating with internal business clients from different departments and at various levels of seniority.
Excellent organizational, written and oral communication skills.
Technical Skills:
Experience working with PolicyTech, Confluence, Jira
Strong experience in Information Security related policy, procedure and control management
Understanding information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO etc.
Experience in technology risk management principles and practices
Experience in working with regulatory frameworks and business requirements relevant to OCC such as, RegSCI, CFTC, etc.
Proficiency using an integrated risk management system (such as RSA Archer Suite) and a business intelligence tool (e.g, Tableau)
Education and/or Experience:
Bachelor’s degree in computer science, Management Information Systems, Business Studies, or related field or the equivalent combination of education and/or relevant experience
7+ years previous work experience in Information Security, Compliance, Risk Management, Project Management, or Data analytics
Demonstrative communication and collaboration experience across multiple functions and/or departments
Experience managing regulatory relations and requirements
Previous work in Compliance, Audit, Risk Management, Project Management, or control activities in the financial services industry.
Certificates or Licenses:
Professional network and/or security certifications a plus (i.e., GIAC, CISSP, CISA, CISM, CRISC)
About Us
The Options Clearing Corporation (OCC) is the world's largest equity derivatives clearing organization. Founded in 1973, OCC is dedicated to promoting stability and market integrity by delivering clearing and settlement services for options, futures and securities lending transactions. As a Systemically Important Financial Market Utility (SIFMU), OCC operates under the jurisdiction of the U.S. Securities and Exchange Commission (SEC), the U.S. Commodity Futures Trading Commission (CFTC), and the Board of Governors of the Federal Reserve System. OCC has more than 100 clearing members and provides central counterparty (CCP) clearing and settlement services to 19 exchanges and trading platforms. More information about OCC is available at www.theocc.com.
Benefits
A highly collaborative and supportive environment developed to encourage work-life balance and employee wellness. Some of these components include:
- A hybrid work environment, up to 2 days per week of remote work
- Tuition Reimbursement to support your continued education
- Student Loan Repayment Assistance
- Technology Stipend allowing you to use the device of your choice to connect to our network while working remotely
- Generous PTO and Parental leave
- 401k Employer Match
- Competitive health benefits including medical, dental and vision
Visit https://www.theocc.com/careers/thriving-together for more information.
Compensation
- The salary range listed for any given position is exclusive of fringe benefits and potential bonuses. If hired at OCC, your final base salary compensation will be determined by factors such as skills, experience and/or education.
- In addition, we believe in the importance of pay equity and consider internal equity of our current team members as part of any final offer.
- We typically do not hire at the maximum of the range in order to allow for future and continued salary growth. We also offer a substantial benefits package as noted on www.theocc.com/careers
- All employees may be eligible for a discretionary bonus. Discretionary bonuses are based on various factors, including, but not limited to, company and individual performance and are not guaranteed.
Salary Range
$122,100.00 - $170,500.00Incentive Range
8% to 15%This position is eligible for an annual discretionary incentive compensation award, for which the target range is listed above (see Incentive Range). The amount of such award, if any, will be based on various factors, including without limitation, both individual and company performance.
Step 1
When you find a position you're interested in, click the 'Apply' button. Please complete the application and attach your resume.
Step 2
You will receive an email notification to confirm that we've received your application.
Step 3
If you are called in for an interview, a representative from OCC will contact you to set up a date, time, and location.
For more information about OCC, please click here.
OCC is an Equal Opportunity Employer
OCC Chicago, Illinois, USA Office

Adjacent to the Willis Tower, close to CTA, Metra and expressways with plenty of food and entertainment options nearby.
Similar Jobs at OCC
What you need to know about the Chicago Tech Scene
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory


