Manager Security Compliance and Risk Management

Posted 9 Days Ago
Be an Early Applicant
Raleigh, NC, USA
In-Office
118K-220K Annually
Senior level
Information Technology • Legal Tech • Analytics
The Role
Lead and operate the enterprise security risk and compliance program: manage risk identification, scoring, register, exceptions, and remediation. Manage a team of security engineers, drive audit readiness, produce executive risk and compliance reporting, and advise stakeholders on control design and compliance obligations (SOC 2, NIST, ISO, FedRAMP).
Summary Generated by Built In

Manager, Security – Security Compliance & Risk Management 

 

Core Responsibilities 

Risk Management 

  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register 

  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced 

  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization 

  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns 

 

People Leadership 

  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring 

  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities 

  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles 

 

Reporting & Communication 

  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics 

  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps 

  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program 

 

Management Duties 

  • Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems. 

  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently. 

  • Manage and encourage new ideas from staff to foster improvements through innovations. 

  • Empower the staff to be accountable and responsible for their own actions and decisions. 

  • All other duties as assigned. 

 

 

Qualifications 

Required 

  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation 

  • 2–3 years of people management or formal team leadership experience, including performance management and team development 

  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations 

  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences 

  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required 

  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements 

  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations 

  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors 

  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls 

  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level 

  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences 

  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection 

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience 

 

Preferred 

  • CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience 

  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate 

  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF) 

  • Prior experience in a SaaS, cloud, or technology product company 

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

Skills Required

  • 6-8 years progressive experience in information security compliance, risk management, or IT audit with program-level ownership
  • 2-3 years of people management or formal team leadership experience
  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and executive risk reporting
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001 and hands-on experience performing control mapping and gap identification; SOC 2 experience required
  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and assessing organizational impact
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end-to-end and interface with internal and external auditors
  • Proven ability to design or mature a compliance program and drive continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with technical and executive stakeholders and drive organizational remediation
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language for senior leadership and board audiences
  • Familiarity with cloud environments (AWS, GCP, or Azure) and their risk and compliance implications
  • Bachelor's degree in Information Security, Computer Science, Risk Management, or related field — or equivalent practical experience
  • CRISC or CISA preferred; CISSP or CISM acceptable with demonstrated GRC focus
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
  • Familiarity with AI governance concepts and frameworks (e.g., ISO 42001, NIST AI RMF)
  • Prior experience in a SaaS, cloud, or technology product company

RELX Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about RELX and has not been reviewed or approved by RELX.

  • Retirement Support Retirement support is positioned as a meaningful part of total rewards through a 401(k) plan with matching contributions, alongside other financial protections such as life and disability coverage. Tuition reimbursement and share purchase access further broaden the financial value of the package beyond base salary.
  • Leave & Time Off Breadth Leave and time off breadth appears strong, with generous vacation allowances, mental health days, and options like sabbaticals and tiered PTO by tenure. Parental and caregiving leaves are described in detail, reinforcing time-away benefits as a standout component of the overall package.
  • Wellbeing & Lifestyle Benefits Wellbeing and lifestyle benefits are supported by offerings such as mental health support (e.g., app access), EAP resources, gym-related perks, and wellness incentives. Flexible working hours and related work-life supports add to the perceived day-to-day value of benefits.

RELX Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
10,001 Employees
Year Founded: 1880

What We Do

RELX is a global provider of information-based analytics for professional and business customers across industries. We help scientists make new discoveries, doctors and nurses improve the lives of patients and lawyers win cases. We prevent online fraud and money laundering, and help insurance companies evaluate and predict risk. Our events enable customers to learn about markets, source products and complete transactions. In short, we enable our customers to make better decisions, get better results and be more productive. We do this by leveraging a deep understanding of our customers to create innovative solutions which combine content and data with analytics and technology in global platforms. RELX serves customers in more than 180 countries and has offices in about 40 countries. It employs approximately 30,000 people of whom almost half are in North America. We operate in four major market segments: Scientific, Technical & Medical; Risk & Business Analytics; Legal; and Exhibitions.

Similar Jobs

Spectrum Logo Spectrum

Director, Human Resources - Fort Mill, SC

Information Technology • Internet of Things • Mobile • On-Demand • Software
In-Office
Charlotte, NC, USA
100000 Employees

CDW Logo CDW

Architect

Information Technology
Remote or Hybrid
US
15100 Employees

Capital One Logo Capital One

Sr. Risk Manager, Controls

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
4 Locations
55000 Employees
162K-203K Annually

Imprivata Logo Imprivata

Technical Knowledge Enablement Specialist

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
87K-112K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account