Manager Security Compliance and Risk Management
RELX · Raleigh, NC · 1 mo ago
Information Technology$118k–$220k/yrFull-time
Core Responsibilities
Risk Management
- Own and operate the enterprise technology and security risk management program
- Lead the risk exception and acceptance process
- Drive timely identification, escalation, and resolution of cybersecurity risks and issues
- Provide pragmatic, risk-based guidance to business and technology stakeholders
People Leadership
- Manage, coach, and develop a team of security engineers
- Set clear priorities, delegate work effectively, and maintain team capacity
- Build a team culture focused on audit-readiness and evidence quality
- Produce metrics, KPIs, and dashboard-level reporting for senior leadership
- Communicate risk and compliance posture clearly to technical and non-technical stakeholders
- Translate audit findings and control gaps into concrete next steps
- Carry out management responsibilities in accordance with the organization's policies, procedures, and applicable laws
- Interview, hire, and train employees
- Plan, assign, and direct work
- Appraise performance, reward, and discipline employees
- Address complaints and resolve problems
- Ensure all staff is provided with training and resources
- Provide frequent feedback and coaching to staff
- Encourage new ideas from staff to foster improvements through innovations
- Empower staff to be accountable and responsible for their own actions and decisions
- 6–8 years of progressive experience in information security compliance, risk management, or IT audit
- 2–3 years of people management or formal team leadership experience
- Deep, hands-on knowledge of GRC disciplines
- Experience owning an enterprise risk register and managing the full risk lifecycle
- Experience with control frameworks including NIST CSF and ISO 27001
- Experience with technology-sector regulatory obligations
- Experience with FedRAMP Continuous Monitoring programs
- Proven ability to manage audit engagements end-to-end
- Strong written and verbal communication skills
- Familiarity with cloud environments and their risk and compliance implications
- Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
- Familiarity with AI governance concepts
- Prior experience in a SaaS, cloud, or technology product company