Manager Security Compliance and Risk Management
LexisNexis · Raleigh, NC · 1 mo ago
Information Technology$118k–$220k/yrFull-time
Core Responsibilities
Risk Management
- Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
- Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
- Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
- Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
People Leadership
- Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
- Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
Reporting & Communication
- Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
- Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
Management Duties
- Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws
- Interview, hire, and train employees; plan, assign, and direct work; appraise performance; reward and discipline employees; address complaints and resolve problems
- Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible
- Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently
- Build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
- Empower the staff to be accountable and responsible for their own actions and decisions
Qualifications
- 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
- 2–3 years of people management or formal team leadership experience, including performance management and team development
- Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations
- Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
- Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
- Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
- Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
- Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
- Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
- Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
- Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
- Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
- Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
- Preferred: CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
- Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
- Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
- Prior experience in a SaaS, cloud, or technology product company
Pay
$118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates.