Manager, IT Compliance - Remote, East Coast (Raleigh, Jersey City or New York City preferred)
With a company culture rooted in collaboration, expertise and innovation, we aim to promote progress and inspire our clients, employees, investors and communities to achieve their greatest potential. Our work is the catalyst that helps others achieve their goals. In short, We Enable Possibility℠.
About the role
The Manager, IT Compliance, working closely with the CISO and Director of IT Security, will provide management, leadership and delivery of the compliance function, liaising closely with other IT and business stakeholders. This role will be the main point of contact for all IT Compliance related activities including leading/coordinating IT control assessment activities (SOX, SOC 2, etc.) and customer information security due diligence reviews.
Responsibilities
- Work with IT process owners to identify, improve, and document detailed controls for key application, security, and infrastructure components.
- Provide ongoing organization-wide guidance on IT control requirements and impact.
- Facilitate requests between control owners and internal/external audit teams and serve as the main point of contact with the Internal and External Audit teams.
- Manage and report on IT control gaps, track issues to completion, and provide recommendations for improvements.
- Lead in the design and implementation of efficient and effective controls within the organization.
- Participate in data privacy governance related activities such as data mapping and data privacy assessments.
- Manage the response for IT-related customer security assessments.
- Proactively identify IT control gaps with a focus on automating control reviews wherever possible.
- Manage access recertification process.
Requirements
- 5+ years of combined experience in the fields of Information Systems audit, IT security, IT governance, IT risk, and IT compliance.
- In-depth knowledge and experience with Sarbanes-Oxley, PCI-DSS, ISO 27001, SOC 2, and the NYDFS Cybersecurity Regulation.
- Working knowledge of Windows Operating System and Active Directory Security including Users and Groups, Group Policy, Domain Structures, Security, and Auditing.
- Working knowledge of agile development methodology.
- Working knowledge of DevOps practices and technologies.
- Desire to measure and continuously improve in all areas and facets.
- Demonstrated ability to balance short-term tactical wins with longer-term strategic solutions.
- Transformative mindset and experience operating as a change agent.
Qualifications
- 8+ years of combined experience in the fields of Information Systems audit, IT security, IT risk, and IT compliance.
- CISSP, CISA, CISM, or CCSK Certifications.
- Excellent oral and written communication skills with the ability to communicate technical concepts to technical and non-technical audiences.
- Demonstrated ability to establish relationships and build rapport to influence colleagues at all levels, uncover business issues, and identify needs.
- Experience in a highly regulated industry, such as insurance and/or financial services.
- Some knowledge of and understanding of how to create/execute SQL queries, and scripts using Python and PowerShell.
Schedule
- Raleigh or remote work with the ability to travel to the main assigned office quarterly for key meetings.
- Ability to travel within the U.S. up to 10-20% of the time.
Pay
Base salary range: $90,000 - $130,000/year. Total individual compensation (base salary, short & long-term incentives) offered will take into account factors including but not limited to geographic location, scope & responsibilities of the role, qualifications, talent availability, and business needs. The above pay range may be modified in the future.
Benefits
- Multiple medical plans plus dental, vision, and prescription drug coverage.
- Competitive 401k with generous matching.
- PTO beginning at 20 days per year.
- Up to 12 paid company holidays per year plus 2 paid days of Volunteer Time Offer.
- Basic Life and AD&D Insurance as well as Short and Long-Term Disability.
- Paid Parental Leave of up to 10 weeks.
- Student Loan Assistance and Tuition Reimbursement.
- Backup Child and Elder Care.