Jobs · Information Technology · North Carolina

Manager Security Compliance and Risk Management

LexisNexis · Raleigh, NC · 1 mo ago
Information Technology$118k–$220k/yrFull-time

Core Responsibilities

Risk Management

  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns

People Leadership

  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles

Reporting & Communication

  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps

Management Duties

  • Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws
  • Interview, hire, and train employees; plan, assign, and direct work; appraise performance; reward and discipline employees; address complaints and resolve problems
  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible
  • Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently
  • Build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Empower the staff to be accountable and responsible for their own actions and decisions

Qualifications

  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
  • 2–3 years of people management or formal team leadership experience, including performance management and team development
  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
  • Preferred: CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
  • Prior experience in a SaaS, cloud, or technology product company

Pay

$118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates.

Similar jobs