Live opening · Posted 9 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job Title: Manager, Information Security Governance, Risk & Compliance (GRC)
Location: Remote, United States
About The Company
Our client is a large, established financial services organization undergoing significant technology, cybersecurity, and risk transformation. The organization operates within a highly regulated environment and is investing in modern governance, risk, compliance, and cybersecurity assurance capabilities to strengthen enterprise controls, regulatory readiness, and information security risk management.
The organization offers a highly collaborative environment where senior leaders have the opportunity to influence enterprise security strategy, regulatory compliance, technology risk, assurance practices, and the continued maturation of the broader Information Security organization.
Job Summary
We are looking for a Manager, Information Security Governance, Risk & Compliance (GRC) to provide strategic and operational leadership across cybersecurity assurance, governance, controls, regulatory compliance, and technology risk.
This individual will lead a team while owning and advancing critical assurance capabilities across a highly regulated enterprise environment. The ideal candidate will combine deep GRC and cybersecurity controls expertise with strong people leadership, executive presence, regulatory experience, and the ability to personally engage in complex assurance and control activities when needed.
The Manager will work across Information Security, Technology, Risk, Audit, Legal, Compliance, and business leadership, establishing sustainable governance and assurance practices while improving control effectiveness, audit readiness, regulatory alignment, and measurable risk outcomes.
Key Responsibilities
GRC & Assurance Strategy: Establish and execute a multi-year vision and roadmap for information security governance, risk, compliance, controls, and assurance capabilities.
Cybersecurity Controls: Design, assess, test, document, and remediate IT general controls (ITGCs), application-level controls, and cybersecurity controls across complex enterprise environments.
PCI DSS Compliance: Provide leadership across PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and interaction with QSA/ISA stakeholders.
Regulatory & Framework Alignment: Apply frameworks and regulatory requirements including NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS to enterprise security and control environments.
Audit & Regulatory Readiness: Partner directly with internal and external auditors, regulators, and business stakeholders to explain and defend control design, risk decisions, remediation strategies, and supporting evidence.
GRC Technology & Automation: Advance the use of GRC platforms and automation to improve control monitoring, assurance testing, evidence collection, audit readiness, and overall program efficiency.
People Leadership: Lead, coach, develop, and manage information security and assurance professionals through performance management, workforce planning, stretch assignments, and structured talent development.
Executive & Stakeholder Communication: Communicate complex cybersecurity, control, compliance, and technology-risk topics to senior executives, business leaders, auditors, regulators, and other cross-functional stakeholders.
Risk & Decision Ownership: Make and document defensible decisions regarding control design, exception treatment, risk acceptance recommendations, remediation priorities, and resource allocation.
Operational Leadership: Establish measurable outcomes across audit performance, control coverage, exemption rates, remediation, completion velocity, and other assurance-program metrics while remaining hands-on when senior-level execution is required.
Requirements
Education: Bachelor's degree in Information Security, Computer Science, Information Systems, a related discipline, or equivalent professional experience.
Experience: Minimum 10 years of progressive experience across GRC, information security, technology risk, internal/external audit, controls, cybersecurity assurance, or closely related disciplines.
Leadership: Minimum 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development.
PCI DSS: Demonstrated experience operating within or directly supporting PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and QSA/ISA interaction.
Frameworks & Regulations: Strong working knowledge of NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS, including the ability to design and defend control rationale.
Controls: Demonstrated experience designing, testing, and remediating IT general controls (ITGCs) and application-level controls.
Executive Communication: Proven ability to communicate complex risk and control matters to executive audiences, audit committees, regulators, and cross-functional stakeholders.
Other: Ability to operate independently under limited direction, prioritize competing demands, make defensible decisions, and consistently deliver results within ambiguous and fast-moving environments.
Preferred Qualifications
Experience implementing or operating ServiceNow Integrated Risk Management (IRM) or comparable enterprise GRC platforms such as Archer, AuditBoard, OneTrust, or MetricStream is preferred.
Experience operating within a Product Operating Model, including roadmap planning, backlog grooming, sprint-based delivery, feature commitment management, and metrics-driven execution, is also preferred.
Experience within financial services, banking, or another highly regulated industry, including direct interaction with regulators such as state banking authorities, the OCC, FDIC, or NYDFS, is highly desirable.
Industry certifications including CISSP, CISA, CISM, CRISC, CGEIT, or CIA are preferred. Demonstrated success improving control automation, continuous control monitoring, assurance testing efficiency, audit-readiness practices, and evidence-as-code approaches is also beneficial.
Benefits
Competitive Compensation: Competitive compensation commensurate with senior-level GRC, cybersecurity assurance, and leadership experience.
Health and Wellness: Comprehensive health and wellness benefits.
Work-Life Balance: Remote U.S.-based opportunity within a collaborative enterprise organization.
Professional Development: Opportunity to lead and develop assurance professionals while influencing enterprise cybersecurity, governance, regulatory compliance, and technology-risk strategy.
Additional Perks: Opportunity to work directly with senior executives, cybersecurity leadership, auditors, regulators, and enterprise stakeholders while helping mature a critical Information Security assurance function.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.