Manager, Security – Security Compliance & Risk Management
Core Responsibilities
Risk Management
Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
People Leadership
Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities
Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
Reporting & Communication
Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
Support the CISO in preparing board and executive committee materials on the state of the security and compliance program
Management Duties
Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.
Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.
Manage and encourage new ideas from staff to foster improvements through innovations.
Empower the staff to be accountable and responsible for their own actions and decisions.
All other duties as assigned.
Qualifications
Required
6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
2–3 years of people management or formal team leadership experience, including performance management and team development
Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations
Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
Preferred
CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
Prior experience in a SaaS, cloud, or technology product company
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights.
Skills Required
- 6-8 years of progressive experience in information security compliance, risk management, or IT audit, with program-level ownership
- 2-3 years of people management or formal team leadership experience, including performance management and team development
- Hands-on knowledge of GRC disciplines, including risk management, compliance, and control governance
- Experience owning an enterprise risk register, managing the full risk lifecycle, and producing executive risk reporting
- Working knowledge of NIST CSF and ISO 27001, including control mapping, gap identification, and compliance activity development
- SOC 2 experience
- Experience with technology-sector regulatory obligations such as SOC 2, GDPR, and CCPA
- Experience with FedRAMP Continuous Monitoring programs and related compliance obligations
- Experience managing audit engagements end-to-end and interfacing with internal and external auditors
- Experience designing or maturing compliance programs and driving continuous improvement across people, processes, and controls
- Ability to build relationships with technical and executive stakeholders, influence decisions, and drive organizational remediation
- Strong written and verbal communication skills, including translating technical risk for senior leadership and boards
- Familiarity with AWS, GCP, or Azure and their risk, compliance, control design, and evidence implications
- Bachelor's degree in Information Security, Computer Science, Risk Management, or related field, or equivalent practical experience
- CRISC or CISA certification; CISSP or CISM acceptable with demonstrated GRC focus
- Experience with ServiceNow GRC, Archer, OneTrust, or LogicGate
- Familiarity with AI governance concepts and frameworks such as ISO 42001 and NIST AI RMF
- Prior experience in a SaaS, cloud, or technology product company
LexisNexis Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about LexisNexis and has not been reviewed or approved by LexisNexis.
-
Healthcare Strength — Healthcare options are often described as comprehensive, spanning medical, dental, and vision coverage alongside life and disability protection. Wellbeing programming such as wellness initiatives and fitness support is also positioned as part of the overall package.
-
Retirement Support — Retirement benefits are repeatedly framed as a meaningful component of total rewards through 401(k) matching and access to stock purchase opportunities. Performance bonuses and charitable matching are also included as financial-support features within the broader rewards mix.
-
Leave & Time Off Breadth — Time-off offerings are portrayed as broad, including PTO, paid holidays, sick leave, and paid volunteer time. Flexible work arrangements, including remote options and flexible hours, further strengthen the overall rewards experience.
LexisNexis Insights
What We Do
LexisNexis Legal & Professional is a leading global provider of legal, regulatory and business information and analytics that help customers increase productivity, improve decision-making and outcomes, and advance the rule of law around the world. We help lawyers win cases, manage their work more efficiently, serve their clients better and grow their practices. We assist corporations in better understanding their markets, monitoring their brands and competition, and in mitigating business risk. We collaborate with universities to educate students, and we support nation-building with governments and courts by making laws accessible and strengthening legal infrastructures. We partner with leading global associations and customers to collect evidence against war criminals and provide tools to combat human trafficking. LexisNexis Legal & Professional, which serves customers in more than 130 countries with 10,000 employees worldwide, is part of RELX Group, a global provider of information and analytics for professional and business customers across industries.







