Information Security Manager; GRC
Listed on 2026-05-16
-
IT/Tech
Cybersecurity, Information Security
About Lvt
LVT is redefining how businesses operate in the physical world, moving beyond traditional security solutions to deliver AI‑driven, actionable intelligence that makes sites smarter, safer, and more secure. Since pioneering our first mobile, solar‑powered units, our commitment to scrappy, hands‑on innovation has made us an established leader and one of the fastest‑growing companies in intelligent site technology. We are building the next generation of solutions—from our physical units in the field to a powerful Agentic AI platform—that allows our customers to gain unprecedented visibility and control over safety, compliance, and operations.
This is your chance to join a cutting‑edge team that isn't just watching the world change, but actively building the technology that is changing it.
LVT is actively seeking a highly motivated and detail-oriented Information Security Manager (GRC) to join our growing Information Security team. This role will report directly to the Information Security Director (GRC). The position is designed for an individual eager to delve deeply into the operational aspects of Governance, Risk, and Compliance, directly supporting LVT’s steadfast commitment to security excellence and regulatory adherence as the business continues its innovative scaling.
The Information Security Manager (GRC) will play an instrumental role in driving key operational GRC initiatives. The primary focus of this hands‑on position will be the end‑to‑end management of LVT’s SOC 2 audit processes, initiating third‑party risk assessments, actively contributing to the policy review and approval lifecycle, and documenting and treating risks in our risk register. Fostering collaborative relationships and good communication is critical as you will work closely with cross‑functional teams across the organization to integrate GRC standards and principles into LVT’s operations.
This role demands exceptional organizational skills, both strategic vision and tactical efforts, and the ability to build and mentor a team of security professionals to meet both current and future GRC challenges.
- Manage LVT’s annual SOC 2 audit and other audits as necessary.
- Collaborate with IT, Finance, and Legal to represent Information Security in various cross‑functional processes including vendor risk, contractual terms, and customer security questions.
- Identify inefficiencies in different GRC processes and improve them.
- Design and manage regular internal audits of security controls.
- Implement automated control monitoring and evidence collection.
- Create, review, and maintain LVT’s security policies.
- Maintain LVT’s risk register to ensure accurate and timely recording of identified risks and their mitigation statuses.
- Build strong relationships with risk owners to drive program buy‑in, accountability, and ownership.
- Work with Sales Ops to develop an approach to customer security questionnaires.
- Mature our public‑facing Security Trust Center to enhance transparency, showcase LVT’s commitment to security, and streamline the sales process.
- Identify and operationalize ways to automate tools and processes to improve LVT’s compliance program efficiency and collaboration across multiple teams.
- Establish and maintain measurable GRC program metrics to quantify effectiveness, highlight progress, and drive continuous improvement.
- 5+ years of experience with Information Security, GRC or IT Audit roles, demonstrating a growing understanding of GRC concepts and methodologies.
- Experience managing a GRC function and staff.
- Effective writing skills for tasks such as policy review and approval, developing risk treatment plans, and creating audit documentation and responses for external auditors.
- Strong organizational skills and attention to detail for managing documentation, audit evidence, and maintaining accurate GRC records.
- Proven track record of developing and implementing policies and procedures, assessing and prioritizing risks, and maturing security compliance programs.
- Substantial experience with regulatory frameworks and standards, such as NIST, SOC 2, ISO 27001, and FedRAMP.
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).