×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Manager Security Compliance and Risk Management

Job in Raleigh, Wake County, North Carolina, 27601, USA
Listing for: RELX
Full Time position
Listed on 2026-08-05
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Manager, Security – Security Compliance & Risk Management

Core Responsibilities

  • Risk Management
  • People Leadership
  • Reporting & Communication
  • Management Duties
  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and Con Mon activities
  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program
  • Carry out management responsibilities in accordance with the organization's policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.
  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.
  • Manage and encourage new ideas from staff to foster improvements through innovations.
  • Empower the staff to be accountable and responsible for their own actions and decisions.

Qualifications

Required

  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
  • 2–3 years of people management or formal team leadership experience, including performance management and team development
  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary