Manager, IT Compliance - Remote, East Coast (Raleigh, Jersey City or New York City preferred)
About the role
The Manager, IT Compliance plays a crucial role in ensuring the organization adheres to relevant regulations and standards, collaborating closely with the CISO and Director of IT Security.
Responsibilities
- Work with IT process owners to identify and improve detailed controls for key application, security, and infrastructure components.
- Provide ongoing guidance on IT control requirements and their impact across the organization.
- Facilitate interactions between control owners and internal/external audit teams, serving as the primary point of contact.
- Manage and report on IT control gaps, track issues to resolution, and recommend improvements.
- Lead in the design and implementation of efficient and effective controls within the organization.
- Participate in data privacy governance activities such as data mapping and assessments.
- Manage responses to IT-related customer security assessments.
- Proactively identify IT control gaps and automate control reviews where possible.
- Manage the access recertification process.
Requirements
- 5+ years of combined experience in Information Systems audit, IT security, IT governance, IT risk, and IT compliance.
- In-depth knowledge and experience with Sarbanes-Oxley, PCI-DSS, ISO 27001, SOC 2, and NYDFS Cybersecurity Regulation.
- Working knowledge of Windows Operating System and Active Directory Security, including Users and Groups, Group Policy, Domain Structures, Security, and Auditing.
- Working knowledge of agile development methodology and DevOps practices and technologies.
- Desire to measure and continuously improve in all areas and facets.
- Demonstrated ability to balance short-term tactical wins with longer-term strategic solutions.
- Transformative mindset and experience operating as a change agent.
Preferred Qualifications
- 8+ years of combined experience in the fields of Information Systems audit, IT security, IT risk, and IT compliance.
- CISSP, CISA, CISM, or CCSK certifications.
- Excellent oral and written communication skills with the ability to communicate technical concepts to both technical and non-technical audiences.
- Experience in a highly regulated industry, such as insurance and/or financial services.
- Some knowledge of and understanding of creating/running SQL queries, and scripting using Python and PowerShell.
Environment and/or Physical Factors
Raleigh or remote work with the ability to travel to the main assigned office quarterly for key meetings. Ability to travel within the U.S. up to 10-20% of the time. Incumbent may be asked to perform other duties as required.
Benefits
Full benefits package available including medical, dental, vision, and prescription drug coverage; a competitive 401k with generous matching; PTO beginning at 20 days per year; up to 12 paid company holidays per year plus 2 paid days of Volunteer Time Offer; basic Life and AD&D Insurance as well as Short and Long-Term Disability; Paid Parental Leave of up to 10 weeks; Student Loan Assistance and Tuition Reimbursement, Backup Child and Elder Care; and more. Click here to learn more on available benefits.