It compliance risk and audit

CNA Insurance
Chicago, IL

You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.

The AVP, Global IT Compliance, Risk and Audit role leads the execution of our technology risk strategy across globally. This senior leadership role is responsible for aligning regional risk practices with global frameworks, ensuring regulatory compliance, and driving continuous improvement in risk posture through automation, governance, and cross-functional collaboration.

Demonstrates Technology risk management, regulatory engagement, and control assurance, with a proven ability to influence and hold senior stakeholders accountable and lead through change in a complex, global environment.

JOB DESCRIPTION:

Essential Duties & Responsibilities

Performs a combination of duties in accordance with departmental guidelines:

  • Serves as the senior global authority on technology risk and compliance, representing the local regions in global risk forums and regulatory engagements.

  • Provides and guides strategic direction to senior technology and business leaders on risk implications of technology initiatives and transformation programs.

  • Leads the regional implementation of the global PRC (Process, Risk, Control) framework, ensuring alignment with enterprise risk appetite and regulatory expectations. Partners with the global GRC team to ensure timely and effective implementation of risk and compliance changes.

  • Oversees regional Technology risk assessments, mitigation strategies, and risk profiling across infrastructure, applications, and business processes.

  • Ensures adherence to cybersecurity frameworks (e.g., ISO 27001, NIST, CIS) and regulatory mandates (e.g., SOX, GDPR, OSFI, DORA).

  • Understands changes to the regulatory landscape for the regions and communicate such changes globally, creating awareness and lead required implementation. Ensures regions identify any control gaps and collaborate with the global team to address and implement controls.

  • Leads the continuous monitoring of technology controls and real-time reporting of deficiencies.

  • Drives the adoption of the use of the GRC platforms (e.g., ServiceNow) within all regions to enhance visibility and operational efficiency. Drives automation of compliance workflows and control testing to reduce manual effort and increase assurance coverage.

  • Coordinates and liaises with global team to ensure audit readiness and execution for internal and external audits, acting as the primary liaison with auditors and regulators for the regions. Ensures timely and accurate reporting on control effectiveness, remediation progress, and regulatory compliance metrics for the regions.

  • Direct regional efforts to identify and remediate End-of-Life (EOL) and End-of-Support (EOS) technology assets. Collaborate with global and regional infrastructure and application teams to manage lifecycle risks and reduce technical debt.

  • Domestic and international travel expectations ~20%

  • May perform additional duties as assigned.

Reporting Relationship: Typically reports to VP and above

Skills, Knowledge & Abilities

  • Deep knowledge of Technology risk frameworks (e.g., NIST, ISO 27001), regulatory standards (e.g., SOX, GDPR, DORA, OSFI, PIPEDA), and audit practices.

  • Strong executive presence with the ability to influence and communicate effectively at all levels of the organization.

  • Experience with GRC platforms (preferably ServiceNow IRM) and control automation technologies.

  • Proven experience with Technology Governance and risk functions with a focus on identifying, assessing, and mitigating Technology risks within a corporate environment.

  • Experience in collaborating with cross-functional teams, including Technology, security, compliance, and business units, to drive risk management initiatives

  • Experience with technology process, risk and control framework



Education & Experience

  • Bachelors or masters degree in information technology, Cybersecurity, Risk Management, or a related field.

  • 10+ years of progressive experience in technology risk, Technology governance, or cybersecurity leadership roles.

  • Demonstrated success in leading regional or global risk programs within a complex, regulated enterprise.

  • Technology Risk and Compliance, Audit, or Quality certifications preferred (e.g. CISSP, CISM, CISA, CIA, CRISC, CGEIT, CIAC, ISO, etc.).

#LI-GV1

#LI-Hybrid

I n certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role. In District of Columbia , California, Colorado, Connecticut, Illinois, Maryland , Massachusetts, New York and Washington, the national base pay range for this job level is $152,000 to $242,000 annually. Salary determinations are based on various factors, including but not limited to, relevant work experience, skills, certifications and location. CNA offers a comprehensive and competitive benefits package to help our employees – and their family members – achieve their physical, financial, emotional and social wellbeing goals. For a detailed look at CNA’s benefits, please visit cnabenefits.com .

CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contact [email protected]

Posted 2025-10-26

Recommended Jobs

Senior application engineer

Daifuku North America
Bolingbrook, IL

Overview: About Us Daifuku is the nation’s leading independent, U.S.‐based provider of intelligent material handling systems. With hundreds of engineers in‐house, the company designs, manufactu…

View Details
Posted 2025-11-03

Discover Mattoon: Your Next Surgical Adventure Awaits!

NurseRecruiter
Mattoon, IL

Surgical Technologist - Operating Room - Travel - (Surg Tech - OR) Embark on your next surgical adventure in Mattoon, where your expertise as a Surgical Technologist will flourish in a vibrant commun…

View Details
Posted 2025-07-31

Robotics DevOps Engineer

Formic
Chicago, IL

Who We Are: At Formic, we’re on a mission to revolutionize American manufacturing and create more abundance in the world. We believe in continuing the American legacy of innovation by making autom…

View Details
Posted 2025-09-22

Senior software engineer

Oracle
Springfield, IL

Job Description OCI (Oracle Cloud Infrastructure) AI Infrastructure is at the forefront of building a cutting-edge, ultra-high-performance GPU platform designed to support AI/ML/HPC workloads. …

View Details
Posted 2025-10-27

RN Field Clinical Supervisor For Home Health Agency

Home Health Advantage INC.
Chicago, IL

Home Health Advantage is an established and growing home healthcare company that has been servicing patients in Chicago Land areas including, South, Southwest, North and Northwest Suburbs of Chicago (…

View Details
Posted 2025-08-28

Quick Lane Service Writer

Romeoville Toyota
Romeoville, IL

Quick Lane Service Writers are usually the first and last impression a customer has with a shop. They’re the ones who greet customers, listen to the problems a client is having with their vehicles, co…

View Details
Posted 2025-08-28

Registered Telemetry Unit Nurse | Granite City, Illinois

Soliant
Granite City, IL

Job Description Job Description Bachelor of Science in Nursing (BSN) degree, active registered nurse (RN) license and minimum 1+ years RN experience required. Applicants who do not meet these qua…

View Details
Posted 2025-10-22

Material Handler - Outbound - 1st Shift

Amsive
Bolingbrook, IL

**Work located at 605 Territorial Dr, Bolingbrook, IL 60440** *Standard work hours are Monday - Friday 6:00am - 2:30pm (plus some overtime/weekends)* Summary/Objective: The  Material Handler - O…

View Details
Posted 2025-09-26

Hotel Maintenance - President Abraham Lincoln Springfield- a DoubleTree by Hilton Hotel

Hilton
America, IL

The President Abraham Lincoln Springfield - a DoubleTree by Hilton Hotel is looking for a Hotel Maintenance Engineer to join their team!  This 310 room property is located just a short walk from Bank…

View Details
Posted 2025-10-30

Program analyst

Aston Carter
Des Plaines, IL

Aston Carter is actively supporting our client in the defense industry in the search for a Program Analyst for a 10+ month contract based in Des Plaines, IL. This person will report to the VP of Prog…

View Details
Posted 2025-11-03