InfoSec GRC ManagerRemotePOSITION SUMMARY:
The Information Security GRC Manager is responsible for leading the organization's governance, risk management, and compliance initiatives related to information security. This role ensures that security policies, standards, and controls align with regulatory requirements and business objectives, while effectively managing risk across the enterprise.
RESPONSIBILITIES:- Plan and execute compliance readiness, and certification assessments (e.g., SOX, PCI-DSS, NIST CSF, ISO 27001)
- Serve as the primary point of contact for external assessors and auditors
- Ensure ongoing compliance with applicable regulatory and contractual requirements
- Coordinate internal and external audits, including SOX-related security controls where applicable
- Lead enterprise risk assessments, including identification, analysis, prioritization, and mitigation of security risks
- Define and monitor Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
- Drive risk-based decision-making across security and business stakeholders
- Track remediation activities, ensuring timely closure and proper documentation
- Drive continuous improvement of control effectiveness and assurance processes
- Partner with IT, Legal, Privacy, and business teams to embed security and compliance into operations
- Provide regular reporting on risk posture, compliance status, and program maturity to senior leadership
- Maintain and evolve security policies, standards, procedures, and risk methodologies
- Develop, maintain, and continuously enhance the enterprise information security governance framework
- Develop and deliver security awareness programs related to risk and compliance
- Promote a strong culture of security and accountability across the organization
POSITION QUALIFICATIONS:
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Business, or related field
- 10+ years of experience in information security, IT risk, or compliance, with 2-3+ years in GRC-focused role
- Strong knowledge of industry frameworks and standards (e.g. NIST, ISO 27001, COBIT)
- Proven experience managing assessments and working with external regulators and assessors
- Demonstrated ability to manage multiple concurrent initiatives and remediation efforts
Preferred Certifications:- Experience implementing and maturing cybersecurity compliance programs
- Relevant certifications (e.g., CISSP, CISM, CRISC, CISA)
- Experience with SOX and PCI ITGC controls and audit coordination
- Familiarity with GRC tools (e.g., Optro (AuditBoard), ServiceNow GRC, OneTrust)
Key Skills:- Audit management and coordination
- Risk assessment and mitigation
- Regulatory compliance management
- Cross-functional collaboration
- Leadership and team management
- Strong written and verbal communication
BENEFITS & PERKS:- Comprehensive healthcare, dental, and vision insurance to keep you and your family covered that is active on day 1 of employment
- Generous 401(k) matching after just one year to help secure your financial future
- Ample paid time off, plus seven holidays to recharge and unwind
- Exclusive discounts on premium merchandise just for you
- Dynamic Learning & Development programs to support your growth
- And more!
The salary range for this opportunity is $125,000-$150,000. Base pay offered may vary depending on geographic region, internal equity, job related knowledge, skills and experience, among other factors.