Leader, Technology Risk and Compliance – SOX Expert
Chubb · Bengaluru, Karnataka, India
Chubb · Bengaluru, Karnataka, India
**About Chubb** Chubb is a world leader in insurance. With operations in 54 countries and territories, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance and life insurance to a diverse group of clients. The company is defined by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength and local operations globally. Parent company Chubb Limited is listed on the New York Stock Exchange (NYSE: CB) and is a component of the S&P 500 index. Chubb employs approximately 40,000 people worldwide. Additional information can be found at: www.chubb.com. **About Chubb India** At Chubb India, we are on an exciting journey of digital transformation driven by a commitment to engineering excellence and analytics. We are proud to share that we have been officially certified as a Great Place to Work® for the third consecutive year, reflecting the culture at Chubb, where we believe in fostering an environment where everyone can thrive, innovate, and grow. With a team of over 2500 talented professionals, we encourage a start-up mindset that promotes collaboration, diverse perspectives, and a solution-driven attitude. We are dedicated to building expertise in engineering, analytics, and automation, empowering our teams to excel in a dynamic digital landscape. We offer an environment where you will be part of an organisation that is dedicated to solving real-world challenges in the insurance industry. Together, we will work to shape the future through innovation and continuous learning. **Roles Overview** Chubb is seeking a highly experienced and strategic Leader, Technology Risk and Compliance to support the management and continued maturation of Chubb's North America Technology SOX Compliance programme. Reporting to the Vice President, Global Leader of SOX IT Compliance, this role will serve as a key senior contributor and subject matter expert in ensuring adherence to all applicable IT controls. It will act as a trusted partner to business stakeholders, Internal Audit, and External Audit teams, playing a critical role in driving compliance excellence and operational maturity across the organisation. This position offers a unique opportunity to lead high-impact initiatives within a globally recognised financial services organisation. **Job Description** **Leadership & Strategy** - Serve as a leader and subject matter expert within the SOX IT Compliance function, providing strategic direction and hands-on oversight of the North America Technology SOX programme. - Contribute to the strategic vision and roadmap for the SOX IT Compliance programme, driving continuous improvement and maturation of the control environment. - Build, mentor, and develop a high-performing team of SOX IT compliance professionals, fostering a culture of accountability, collaboration, and continuous learning. - Represent the SOX IT Compliance function in governance forums, effectively communicating programme status, risks, and recommendations to executive leadership. - Champion a risk-aware culture across the organisation by promoting awareness of SOX compliance requirements and best practices. **SOX Programme Management** - Lead and oversee the design, implementation, and monitoring of IT General Controls (ITGCs), IT Application Controls (ITACs), and Software Development Lifecycle (SDLC) requirements to ensure SOX compliance across the region. - Drive the scoping, planning, and execution of the annual SOX IT compliance assessment, ensuring timely and accurate completion of all testing and documentation activities. - Analyse control results and identify opportunities for continuous improvement of the SOX control environment, developing actionable recommendations for remediation and enhancement. - Oversee the remediation of control deficiencies identified by auditors, ensuring appropriate root cause analysis and action plans are defined, tracked, and resolved in a timely manner. **Audit & Stakeholder Management** - Serve as a key point of contact and partner for internal, external, and regulatory auditors (including PwC) on the scope, depth, risks, and results of technology audits. - Partner and negotiate with audit teams on control design, testing approaches, and findings to ensure balanced and pragmatic outcomes. - Collaborate with process, control, and system owners across the organisation to drive alignment and accountability for SOX compliance obligations. - Oversee the review and evaluation of SOC 1 Type 2 reports to assess vendor SOX compliance and determine appropriate reliance on third-party systems and services. **Technology & Innovation** - Evaluate and assess emerging technologies and evolving processes (e.g., DevSecOps, cloud environments, AI / large language models) and provide authoritative control guidance. - Stay current on regulatory changes, industry trends, and technological advancements that may impact the SOX IT compliance landscape, proactively advising leadership on potential risks and opportunities. - Drive the optimisation and effective utilisation of GRC tools (e.g., AuditBoard) to enhance programme efficiency, reporting capabilities, and overall compliance monitoring. **Qualifications / Key Requirements** **Required** - 12+ years of progressive leadership experience across enterprise technology disciplines, including one or more of the following: application development, information security, strategic planning, risk management, compliance monitoring, IT auditing, or operations. - 10+ years of relevant IT SOX auditing experience with a public accounting firm and/or a publicly traded company. - Deep, demonstrable understanding of Sarbanes-Oxley compliance requirements, including IT General Controls (ITGCs), IT Application Controls (ITACs), and SSAE 18 (SOC 1 Type 2) reporting standards. - Proven track record of leading and developing high-performing teams in