Jobs · Information Technology · Ohio

Manager, Information Security GRC

Sutton Bank · Columbus, OH · 1 wk ago
Information TechnologyFull-time

About the Role

The Information Security Governance, Risk, and Compliance (GRC) Manager leads the development, implementation, and ongoing management of the organization's security governance framework. This role oversees risk management activities, ensures compliance with applicable regulations and standards, and drives continuous improvement in the security program. The GRC Manager partners closely with technology, legal, audit, and business stakeholders to embed security into operations and support strategic objectives.

Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or related field. Master's Degree preferred.
  • Valid Driver's License.
  • Required certifications: CISSP, CISA, or CRISC.
  • Preferred certifications: CompTIA Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or similar credentials.
  • Seven or more years of combined experience in information security, IT, or risk management, preferably in a financial institution.
  • Experience leading a team.
  • Or equivalent combination of education and experience.

Responsibilities

  • Designs and executes end-to-end risk assessments that include internal, third-party, and fourth-party vendors, identifying high-impact vulnerabilities, threats, and business risk across the enterprise.
  • Oversees compliance with security policies, industry standards, and regulations (e.g., NIST CSF, HIPAA, NIST 800-53, PCI-DSS, GDPR, GLBA, or ISO 27001).
  • Develops and updates security policies, standards, and procedures to address evolving risk and regulatory requirements.
  • Leads audit preparation and response efforts, managing interactions with external auditors and ensuring timely resolution of findings.
  • Leads investigations into security incidents, performing detailed root cause analysis and impact assessments.
  • Designs and implements advanced security metrics and key risk indicators (KRIs) to measure and communicate risk posture.
  • Acts as a trusted advisor to senior management, providing insights on risk trends, mitigation strategies, and security investments.
  • Collaborates with business units, IT, legal, and compliance teams to embed risk management into strategic initiatives and projects.
  • Leads and mentors junior analysts, providing guidance on technical skills, risk methodologies, and professional development.
  • Partners with HR to manage staff performance issues/concerns, develop/identify training needs, and support recruitment processes.

Skills

  • Excellent verbal and written communications at both business and deep technical levels.
  • Strong understanding of and experience with process improvement and process mapping.
  • Strong leadership skills: dependable, curious, matrix-oriented, visionary, solution-oriented, delivers exemplary customer service, and quality-focused.
  • Excellent interpersonal skills.
  • Self-directed and motivated.
  • Ability to manage multiple tasks.
  • Ability to read and comprehend instructions, correspondence, technical manuals, and memos.
  • Ability to respond to common inquiries or complaints from employees, vendors, and management staff.
  • Ability to effectively present information to individuals one-on-one or in a small group setting.
  • Ability to articulate technical concepts to end-users.
  • Advanced knowledge of TPRM platforms and ability to optimize.
  • Proactive mindset: staying ahead of emerging threats and taking initiative in risk mitigation.
  • Strong analytical and problem-solving skills.
  • Attention to detail: ability to identify subtle security vulnerabilities and ensure accurate documentation.
  • Adaptability: capacity to learn and adapt to rapidly evolving security threats and technologies.
  • Teamwork: willingness to collaborate with other team members for effective risk mitigation.
  • Time management: skill in prioritizing tasks and managing workload in a fast-paced environment.

Similar jobs

Security Officer

Guardian Security Services, Inc.Downers Grove, IL· 1 mo ago
Information Technologyapply on de.jobsyn.org

Security Officer

Per Mar Security ServicesMinneapolis, MN· 1 mo ago
Information Technologyapply on joblinkapply.com

Security Officer

Signet JewelersNew York, NY· 1 mo ago
Information Technology$28–$35/hrapply on signetjewelers.wd1.myworkdayjobs.com

Security Officer

Securitas Security Services USA, Inc.Grand Rapids, MN· 1 mo ago
Information Technology$18.35/hrapply on ekaw.fa.us2.oraclecloud.com

Security Officer

SedgebrookLincolnshire, IL· 2 mo ago
Information Technology$18/hrapply on eexs.fa.us2.oraclecloud.com

Security Officer

CARTILittle Rock, AR· 2 mo ago
Information Technologyapply on secure4.saashr.com