Vice President, IT Governance, Risk & Compliance

Northwestern Mutual

Milwaukee (WI)

On-site

USD 220,000 - 330,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible work schedules
Concierge service
Comprehensive benefits
Employee resource groups

Job summary

Northwestern Mutual in Milwaukee seeks a visionary Vice President of IT Governance, Risk & Compliance to shape and lead the enterprise IT GRC function. This executive will align technology risk with business strategy and regulatory expectations.

You will drive automation, analytics, and AI-enabled continuous assurance, translate technical risks into business impacts for the board, and partner with Cybersecurity, Internal Audit, Legal, and Technology leadership.

Qualifications

  • 15+ years of progressive leadership across IT governance, risk, compliance, or cybersecurity.
  • Experience with highly regulated industries and regulators/auditors.
  • Proven ability to lead enterprise programs with measurable outcomes.
  • Exceptional executive communication and stakeholder management.

Responsibilities

  • Define multi-year IT GRC strategy aligned with enterprise objectives.
  • Lead modernization with automation, data-driven reporting and continuous assurance.
  • Oversee governance frameworks, controls, and regulatory compliance programs.
  • Provide executive and board-level risk reporting and guidance.
  • Partner with CISO, CIO, and executives to drive risk-informed decisions.

Skills

Executive IT GRC leadership
Cybersecurity governance
Risk management
Regulatory compliance
Strategic planning
Executive communication
Cross-functional collaboration
Automation and analytics

Education

Bachelor's degree in a relevant field
CISSP / CISM / CRISC / CGEIT / CISA

Tools

GRC platforms (e.g., RSA Archer)
AI governance tools

Job description

Summary

We are seeking an experienced, forward-thinking Vice President of IT Governance, Risk & Compliance (IT GRC) to lead and transform the enterprise IT GRC function. This executive leader will be responsible for establishing and advancing a modern, technology-enabled governance, risk, compliance, and regulatory response program that supports the company mission, protects customers, and enables business growth.

This role requires an exceptional leader who can operate at the intersection of cybersecurity, technology, risk management, audit, regulation, and business strategy. The successful candidate will possess deep knowledge of cybersecurity and technology risks, extensive experience within highly regulated industries, and a demonstrated ability to build scalable programs leveraging automation, data intelligence, continuous assurance, and artificial intelligence.

The Vice President will serve as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders while driving a culture of accountability, transparency, and risk-informed decision making across the enterprise.

Primary Duties & Responsibilities
Strategic Leadership
  • Develop and execute a multi-year vision and strategy for the IT GRC organization aligned with enterprise objectives, technology strategy, and cybersecurity priorities.
  • Transform traditional compliance and risk management practices into a modern, data-driven operating model emphasizing automation, scalability, and continuous monitoring.
  • Build a high-performing organization that attracts, develops, and retains top talent across governance, compliance, risk management, and regulatory disciplines.
  • Partner closely with Cybersecurity, Technology, Enterprise Risk Management, Internal Audit, Legal, Privacy, and business leadership to ensure integrated risk management across the enterprise.
Governance & Risk Management
  • Oversee enterprise IT governance frameworks, policies, standards, controls, and risk management processes.
  • Ensure effective identification, assessment, measurement, monitoring, and reporting of technology and cybersecurity risks.
  • Drive maturation of risk management capabilities through improved metrics, analytics, and automation.
  • Develop meaningful executive and board-level reporting that translates technical risks into business and financial impacts.
Regulatory Compliance & Audit
  • Lead compliance efforts related to applicable technology and cybersecurity regulations and standards.
  • Maintain readiness for regulatory examinations and external reviews.
  • Serve as the primary executive sponsor for technology and cybersecurity audits, examinations, and regulatory engagements.
  • Establish sustainable and defensible compliance practices that withstand both regulatory and audit scrutiny.
  • Drive remediation of audit findings and regulatory concerns through risk-based prioritization and measurable outcomes.
Technology & Cybersecurity Leadership
  • Provide strategic oversight for technology and cybersecurity governance programs.
  • Partner with cybersecurity leadership to assess and manage emerging threats, control effectiveness, security maturity, and operational risk.
  • Apply practical cybersecurity experience to improve governance and risk outcomes rather than relying solely on theoretical compliance models.
  • Maintain awareness of evolving threat landscapes, technology trends, cloud risks, AI-related risks, and cybersecurity regulations.
Modernization, Automation & AI
  • Champion modernization of IT GRC practices through automation, workflow orchestration, advanced analytics, and data-driven decision making.
  • Lead the adoption of continuous assurance capabilities that reduce manual evidence collection and repetitive compliance activities.
  • Drive elimination of duplicate processes and fragmented controls across governance, risk, and compliance programs.
  • Establish governance frameworks and oversight mechanisms for emerging AI technologies and AI-enabled business processes.
  • Foster a culture that embraces innovation while maintaining appropriate risk management and regulatory compliance.
Executive & Board Engagement
  • Serve as a trusted advisor to the CISO, CIO, executive leadership team, and governance committees.
  • Deliver concise, compelling, and actionable briefings to senior executives, board committees, auditors, and regulators.
  • Translate complex technical, cyber, and regulatory issues into language appropriate for executive and board audiences.
  • Build strong relationships across the organization to influence decision making and achieve strategic outcomes.
Qualifications
Required Qualifications
  • A cybersecurity leader who understands governance and compliance, not simply a compliance leader who understands regulations.
  • A technology strategist who understands how platforms, integrations, automation, and AI enable scalable risk management.
  • 15+ years of progressive leadership experience across IT governance, risk management, compliance, audit, cybersecurity, or technology management.
  • Demonstrated experience leading large-scale enterprise programs within a highly regulated environment.
  • Strong understanding of information technology, cybersecurity architectures, cloud technologies, identity and access management, data protection, and technology operations.
  • Extensive experience managing regulatory compliance programs and interactions with internal and external auditors.
  • Proven experience presenting to executive leadership teams, board committees, regulators, and auditors.
  • Demonstrated success developing enterprise-wide governance, risk, compliance, or cybersecurity programs.
  • Exceptional executive communication, influencing, and relationship management skills.
Preferred Qualifications
  • Experience within the insurance industry strongly preferred.
  • Experience within financial services, banking, wealth management, or other highly regulated industries.
  • Prior leadership experience in a cybersecurity discipline such as cyber defense, security engineering, identity and access management, security architecture, incident response, risk management, or security operations.
  • Experience implementing or leading modern GRC platforms and technology-enabled compliance programs.
  • Experience leading large-scale compliance transformations, automation initiatives, or digital modernization programs.
  • Knowledge of emerging AI governance, model risk management, and technology ethics practices.
  • Professional certifications such as CISSP, CISM, CRISC, CGEIT, CISA, CPA, CIA, or equivalent.
Compensation Range:

Pay Range - Start:

$220,000.00

Pay Range - End:

$330,000.00

This role is eligible for additional short-term and long-term incentive compensation.

We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable,

Grow your career with a best-in-class company that puts our clients' interests at the center of all we do.

Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.

FIND YOUR FUTURE

We're excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.

  • Flexible work schedules
  • Concierge service
  • Comprehensive benefits
  • Employee resource groups
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Audit Specialist
Senior IT Audit Specialist

Northwestern Mutual • Milwaukee (WI)

On-site
USD 70,000 - 105,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Manager Software Engineering - Electronic Communication Compliance
Manager Software Engineering - Electronic Communication Compliance

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 144,000 - 216,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Milwaukee Succeeds • Milwaukee (WI)

Hybrid
USD 119,000 - 178,000
LI-Hybrid
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,600 - 169,000
Investment Compliance Consultant
Investment Compliance Consultant

Northwestern Mutual • Milwaukee (WI)

On-site
USD 89,000 - 135,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
VP Procurement - Technology and Digital
VP Procurement - Technology and Digital

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 160,000 - 240,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Tech Success Consultant
Tech Success Consultant

Northwestern Mutual • Boise (ID)

On-site
USD 70,000 - 105,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
VP, Technology & Digital Services
VP, Technology & Digital Services

Preferred Mutual Insurance Company • New York (NY)

On-site
USD 170,000 - 230,000
Short-term disability
Long-term disability
Life insurance
+12