Manager, IT Compliance - Remote, East Coast (Raleigh, Jersey City or New York City preferred)
About the role
The Manager, IT Compliance plays a pivotal role in ensuring the organization adheres to regulatory standards and maintains robust IT controls. Reporting to the CISO and Director of IT Security, this position oversees the compliance function, collaborating closely with IT and business stakeholders.
Responsibilities
- Work with IT process owners to identify and document detailed controls for key application, security, and infrastructure components.
- Provide ongoing guidance on IT control requirements and their impact across the organization.
- Facilitate interactions between control owners and internal/external audit teams, serving as the primary liaison.
- Manage and report on IT control gaps, tracking issues to resolution, and recommending improvements.
- Lead in the design and implementation of efficient and effective IT controls.
- Engage in data privacy governance activities, including data mapping and assessments.
- Respond to IT-related customer security assessments proactively.
- Proactively identify IT control gaps and explore opportunities for automation.
- Manage the access recertification process.
Requirements
- 5+ years of combined experience in Information Systems audit, IT security, IT governance, IT risk, and IT compliance.
- In-depth knowledge and experience with Sarbanes-Oxley, PCI-DSS, ISO 27001, SOC 2, and NYDFS Cybersecurity Regulation.
- Working knowledge of Windows Operating System and Active Directory Security, including Users and Groups, Group Policy, Domain Structures, Security, and Auditing.
- Working knowledge of agile development methodology and DevOps practices and technologies.
- Desire to measure and continuously improve in all areas and facets.
- Demonstrated ability to balance short-term tactical wins with longer-term strategic solutions.
- Transformative mindset and experience operating as a change agent.
Preferred Qualifications
- 8+ years of combined experience in the fields of Information Systems audit, IT security, IT risk, and IT compliance.
- CISSP, CISA, CISM, or CCSK certifications.
- Excellent oral and written communication skills, capable of communicating technical concepts to both technical and non-technical audiences.
- Ability to establish relationships and build rapport to influence colleagues at all levels, uncover business issues, and identify needs.
- Experience in a highly regulated industry, such as insurance and/or financial services.
- Some knowledge of and understanding of creating/running SQL queries, and scripting using Python and PowerShell.
Environment and/or Physical Factors
The role offers the option to work remotely or in Raleigh, with the ability to travel to the main office quarterly for key meetings. Travel within the U.S. is expected to be 10-20% of the time. The incumbent may be asked to perform other duties as required.
Pay and Benefits
Salary is determined by experience and performance. A full benefits package is available, including medical, dental, vision, and prescription drug coverage; a competitive 401(k) plan with generous matching; paid time off; company holidays; volunteer time off; life and AD&D insurance; short and long-term disability; parental leave; student loan assistance; tuition reimbursement; backup child and elder care; and more. Click here to learn more about available benefits.