Leader Technology Risk and Compliance
Chubb (Chubb) · Other
- Compliance & Financial Crime
- Insurance & Actuarial
- Monterrey, NLE, Mexico
- Regular · Full time
Leader Technology Risk and Compliance
Chubb is seeking a highly experienced and strategic Leader Technology Risk and Compliance to support the management and continued maturation of Chubb's North America Technology SOX Compliance program. Reporting to the Vice President, Global Leader of SOX IT Compliance, this role will serve as a key senior contributor and subject matter expert in ensuring adherence to all applicable IT controls. It will act as a trusted partner to business stakeholders, Internal Audit, and External Audit teams, playing a critical role in driving compliance excellence and operational maturity across the organization. This position offers a unique opportunity to lead high-impact initiatives within a globally recognized financial services organization.
Responsibilities
Leadership & Strategy
- Serve as a leader and subject matter expert within the SOX IT Compliance function, providing strategic direction and hands-on oversight of the North America Technology SOX program
- Contribute to the strategic vision and roadmap for the SOX IT Compliance program, driving continuous improvement and maturation of the control environment
- Build, mentor, and develop a high-performing team of SOX IT compliance professionals, fostering a culture of accountability, collaboration, and continuous learning
- Represent the SOX IT Compliance function in discussions and governance forums, effectively communicating program status, risks, and recommendations to executive leadership
- Champion a risk-aware culture across the organization by promoting awareness of SOX compliance requirements and best practices
SOX Program Management
- Lead and oversee the design, implementation, and monitoring of IT General Controls (ITGCs), IT Application Controls (ITACs), and Software Development Lifecycle (SDLC) requirements to ensure SOX compliance across the region
- Drive the scoping, planning, and execution of the annual SOX IT compliance assessment, ensuring timely and accurate completion of all testing and documentation activities
- Analyze control results and identify opportunities for continuous improvement of the SOX control environment, developing actionable recommendations for remediation and enhancement
- Oversee the remediation of control deficiencies identified by auditors, ensuring appropriate root cause analysis and action plans are defined, tracked, and resolved in a timely manner
Audit & Stakeholder Management
- Serve as a key point of contact and partner for internal, external, and regulatory auditors on the scope, depth, risks, and results of technology audits
- Partner and negotiate with audit teams on control design, testing approaches, and findings to ensure balanced and pragmatic outcomes
- Collaborate with process, control, and system owners across the organization to drive alignment and accountability for SOX compliance obligations
- Oversee the review and evaluation of SOC 1 Type 2 reports or equivalent documentation to assess vendor SOX compliance and determine appropriate reliance on third-party systems and services
Technology & Innovation
- Evaluate and assess emerging technologies and evolving processes (e.g., DevSecOps, cloud environments, AI/large language models) and provide authoritative control guidance for new and developing areas
- Stay current on regulatory changes, industry trends, and technological advancements that may impact the SOX IT compliance landscape, proactively advising leadership on potential risks and opportunities
- Drive the optimization and effective utilization of GRC tools (e.g., AuditBoard) to enhance program efficiency, reporting capabilities, and overall compliance monitoring
Qualifications
Required
- 12+ years of progressive leadership experience across enterprise technology disciplines, including one or more of the following: application development, information security, strategic planning, risk management, compliance monitoring, IT auditing, or operations
- 10+ years of relevant IT SOX auditing experience with a public accounting firm and/or a publicly traded company
- Deep, demonstrable understanding of Sarbanes-Oxley compliance requirements, including IT General Controls, IT Application Controls, and SSAE 18 (SOC 1 Type 2) reporting standards
- Proven track record of leading and developing high-performing teams in a complex, matrixed, and global organizational environment
- Demonstrated ability to influence and negotiate with senior stakeholders, auditors, and cross-functional leaders without direct authority
- Strong executive presence with excellent written and verbal communication skills, including the ability to present complex technical and compliance topics to executive-level audiences
- Proven ability to manage multiple high-priority initiatives simultaneously in a dynamic, fast-paced environment
- Demonstrated leadership competencies including business acumen, strategic thinking, accountability, integrity, and inclusive leadership
Preferred
- Experience working with GRC tools such as AuditBoard or similar platforms
- Familiarity with cloud control frameworks, DevSecOps environments, and emerging technologies such as AI
- Prior experience in the insurance or financial services industry
- Experience working in a large, global, publicly traded organization
Education
- Bachelor's degree (B.S.) or Master's degree in Information Systems, Computer Science, Accounting, Finance, or a related field
Certifications
- Certified Information Systems Auditor (CISA)
- Additional relevant certifications (e.g., CISSP, CRISC, CPA) are a plus