The role partners closely with Security Risk, Governance, Technology, Privacy, Financial Governance, BISOs, external auditors, and delivery partners to strengthen control accountability, improve audit readiness, and provide clear reporting on status, risks, issues, and decisions needed by leadership.
Lead assigned regulatory compliance programs and control portfolios across SOX, PCI, SWIFT, SOC 1/SOC 2, privacy, and other security control areas, ensuring scope, inventories, evidence expectations, and audit timelines are clearly defined and actively managed.
Serve as senior control advisor and escalation point for assigned stakeholders, compliance partners, and delivery resources, providing guidance on control design, operating effectiveness, audit response quality, and remediation approach.
Manage auditor coordination, RFIs, walkthroughs, findings, and remediation tracking by holding auditors and control owners accountable to milestones, improving quality of responses, and ensuring issues are escalated early with clear risk and impact framing.
Maintain and improve compliance scope, control documentation, and control library data in partnership with GRC, ServiceNow, Axonius, Technology, and Security teams, ensuring control attributes, scope tags, ownership, and evidence requirements remain current and audit-ready.
Build strong relationships with VP-level control owners, BISOs, Privacy, Financial Governance, Security Architecture, GIO, GPP, Product & Technology, and external audit partners to identify risks, resolve control gaps, and promote accountability for compliance outcomes.
Support regulatory transformation and recurring gap remediation by identifying root causes, developing practical remediation plans, coordinating cross-functional follow-up, and helping implement sustainable control improvements.
Provide concise status reporting and executive-ready updates on audit progress, RFIs, findings, indicators, risks, issues, decisions needed, and upcoming milestones for Director, SVP, CISO, and stakeholder reporting.
Contribute to control automation and continuous monitoring initiatives by identifying candidate controls, validating business requirements, and ensuring automated indicators and dashboards support regulatory and operational compliance needs without owning the continuous controls monitoring capability.