×
Register Here to Apply for Jobs or Post Jobs. X

Senior Manager, Governance, Risk & Compliance

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Andersen
Full Time position
Listed on 2026-05-19
Job specializations:
  • IT/Tech
    Information Security, Cybersecurity, IT Consultant, Data Security
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below

The Role

Andersen is scaling its information security function, and this is a critical hire for the program’s next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer (CISO) and own the build‑out of the firm’s governance, risk, and compliance program. The immediate mandate is significant – lead simultaneous SOC 2 Type II and ISO 27001 certification initiatives while establishing the policy and risk management infrastructure the firm will rely on long‑term.

This is a program‑building role, and the right candidate will be energized by the opportunity to design systems rather than maintain them.

Senior Manager, Governance Risk & Compliance (GRC) can expect to: SOC 2 Type II & ISO 27001 Certification
  • Lead end‑to‑end certification programs for SOC 2 Type II and ISO 27001 simultaneously, from scoping through audit closure
  • Define control environments, manage evidence collection, and serve as the primary liaison with external auditors and certification bodies
  • Administer the firm’s compliance automation platform and maintain continuous control monitoring and audit readiness
  • Manage both programs through their full lifecycle, including observation periods, annual renewals, surveillance audits, and ISO recertification cycles
Policy & Risk Management
  • Develop and maintain a comprehensive information security policy suite aligned to SOC 2, ISO 27001, and applicable regulatory requirements, with defined processes for ownership, annual review, and exception management
  • Build and maintain an enterprise risk register using structured methodology (e.g., ISO 27005, NIST CSF) and lead annual and ad‑hoc risk assessments
  • Communicate risk posture and policy compliance to the CISO and, where appropriate, to firm leadership and clients
  • Develop and maintain an AI governance policy covering acceptable use of AI tools, agentic system deployments, and citizen developer activity, ensuring alignment with the firm’s risk appetite and applicable regulatory requirements
Privacy & Regulatory Compliance
  • Serve as the firm’s subject‑matter expert on GDPR, CCPA, and other applicable privacy and data protection requirements
  • Monitor evolving regulatory obligations globally and translate them into actionable compliance programs
  • Partner with Legal and Operations on data subject requests, privacy impact assessments, and breach notification procedures
  • Advise the CISO on emerging compliance obligations relevant to a global professional services firm
Third‑Party Risk & Client Due Diligence
  • Design and operate the firm’s third‑party risk management program, including vendor tiering, security assessments, and remediation tracking
  • Manage the firm’s response program for client security questionnaires and due diligence requests
  • Maintain a library of certification‑aligned response language and track contractual security commitments across vendors and clients
Security Awareness & Training
  • Own the firm’s security awareness program, including curriculum design, platform administration, and completion tracking
  • Develop role‑specific content for high‑risk populations and keep training current against the evolving threat landscape
  • Develop and maintain training content addressing AI‑related threats and responsible AI use, including risks from unsanctioned AI tools, citizen developer activity, and AI agents operating with access to firm data and systems
  • Track and report program effectiveness to the CISO on a regular cadence
Team & Stakeholder Leadership
  • Build collaborative relationships across Legal, IT, Operations, Audit, and client‑facing teams to embed security and compliance into firm workflows
  • Represent the information security function in client‑facing conversations regarding the firm’s security posture
Requirements
  • 8–12 years of progressive experience in information security GRC, with a demonstrated record of building programs, not just maintaining them
  • Bachelor’s degree in Information Security, Computer Science, Risk Analysis, or a related field
  • Proven track record achieving and sustaining both SOC 2 Type II and ISO 27001 certifications, including scoping, control design, ISMS development, and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary