Cybersecurity Risk Manager

Jobright.ai

Chicago (IL)

On-site

USD 120,000 - 180,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive benefits starting day one

Job summary

Softchoice, a software-focused IT solutions provider in Chicago, seeks a Cybersecurity Risk Manager to identify, assess, and mitigate risks while building a robust risk program. You’ll lead risk governance, align with ISO 27001, guide audits, and drive remediation with cross-functional teams.

The role requires 10–15 years in IT security, hands-on governance, and strong leadership. You will report to senior leadership and shape enterprise-wide cybersecurity posture through proactive risk

Qualifications

  • 10-15 years' IT experience including security operations (SOC).
  • 5 years experience managing people directly and indirectly.
  • At least 5 years in cybersecurity governance, risk, and compliance (GRC).
  • Knowledge of risk management in cybersecurity, IT compliance, risk assessment, and control.
  • Understanding of security practices, trends, and compliance audits.
  • Auditing against information security management frameworks (SOC 2 Type 2, ISO 27001:2022).
  • Proven project management approach to drive outcomes.

Responsibilities

  • Take ownership for maturing our Risk Management governance/process and coordinate remediation.
  • Set strategic direction for cybersecurity risk management and related compliance initiatives.
  • Develop and maintain a cybersecurity risk framework aligned with ISO 27001.
  • Establish governance structures to oversee risk and compliance activities.
  • Guide the organization through audits and engagements with auditors.
  • Oversee risk assessments to define and analyze risks with a comprehensive approach.
  • Evaluate risk gravity by considering potential organizational impact.
  • Develop, prioritize, and lead execution of risk treatment plans and controls.
  • Monitor evidence-based implementation of controls to achieve compliance.
  • Drive process changes to mitigate potential risks and conduct access reviews.
  • Present risk score updates for ISMS committee and leadership review.
  • Define contingency plans and incident response playbooks for cyber crises.
  • Identify gaps in policies and drive adoption of improved cybersecurity policies.
  • Enhance employees' understanding of cybersecurity risks and best practices.
  • Provide strategic direction and mentorship to cross-functional teams.

Skills

Cybersecurity governance
Risk management
ISO 27001
Compliance audits
Security operations
Project management
Analytical skills
Research skills
Risk assessment
Policy development
Incident response
Employee training
Statistical Analysis Software
CISSP certification
CISM certification
CISA certification
CRISC certification
Professional Risk Manager
Leadership
Communication skills
Problem-solving
Team collaboration
Technical writing

Education

Bachelor's or master's degree in computer science, engineering, information security, or a related field

Tools

Statistical Analysis Software (SAS)

Job description

Softchoice is a software-focused IT solutions and services provider that helps organizations innovate and enhance their technology decisions. The Cybersecurity Risk Manager will identify, assess, and mitigate risks affecting the company's financial health and compliance, while leading the development of a robust cybersecurity risk management program.

Cloud Computing Enterprise Software Information Technology Collaboration

Responsibilities

Take ownership for, mature our Risk Management governance/process, and leverage the broader teams for execution of risk remediation based on priorities and risk appetite

Set strategic direction for cybersecurity risk management, and related compliance initiatives

Develop and maintain a cybersecurity risk framework aligned with ISO 27001

Establish robust governance structures to oversee risk and compliance activities

Guide the organization through compliance audits and engagements with auditors

Oversee risk assessments to define and analyze possible risks, ensuring a comprehensive approach to risk identification

Evaluate the gravity (risk score) of each risk by considering potential organizational impact

Develop, prioritize, and lead the execution of risk treatment plans and control measures

Monitor and ensure evidence-based implementation of controls to achieve compliance

Drive process changes to eliminate or mitigate potential risks

Drive the execution of appropriate technology platform access reviews

Present risk score updates for ISMS committee and recommendations for senior leadership review

Define and implement contingency plans and incident response playbooks to handle cybersecurity crises effectively

Assess existing policies and procedures, identifying gaps and opportunities for improvement as relates to risk management

Recommend and drive the adoption of improved policies to strengthen the organization's cybersecurity posture

Drive initiatives to enhance employees' understanding of cybersecurity risks and best practices

Provide strategic direction, mentorship, and guidance to cross-functional teams involved in cybersecurity risk activities

Lead, motivate, and develop direct and indirect reports to excel in their roles. (future once ICs added under)

Qualification

Cybersecurity governance Risk management ISO 27001 Compliance audits Security operations Project management Analytical skills Research skills Risk assessment Policy development Incident response Employee training Statistical Analysis Software CISSP certification CISM certification CISA certification CRISC certification Professional Risk Manager Leadership Communication skills Problem-solving Team collaboration Technical writing

Required

10-15 years' experience in IT including security operations (SOC)

5 years experience managing people directly and indirectly

At least 5 years working in cybersecurity governance, risk, and compliance (GRC)

Demonstrated knowledge of risk management in the context of cybersecurity, IT compliance, risk assessment, and control

Demonstrated understanding of security practices, trends, and compliance audits

Knowledge of auditing against information security management frameworks (SOC2T2, ISO 27001:2022)

Proven project management approach to drive outcomes is mandatory

Bachelor's or master's degree in computer science, engineering, information security, or a related field

Relevant certifications such as CISSP, CISM, CISA, CRISC

Analytical mind with problem-solving aptitude

Preferred

Experience as a Security Analyst and/or IT Infrastructure work is desirable

Familiarity with industry compliance standards and regulations (e.g., GDPR, Occupational Safety and Health Act)

Strong computer and research skills; knowledge of analysis software preferred (e.g., Statistical Analysis Software, or SAS)

Professional Risk Manager (PRM) certification is a plus

Competitive Benefits: Benefit from competitive perks that start on day one

IT solutions provider for cloud, AI, software, and digital workplaces.

Cybersecurity governance Risk management ISO 27001 Compliance audits Security operations

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap • Atlanta (GA)

On-site
USD 120,000 - 160,000
ISO 27001 Cyber Risk & Compliance Lead
ISO 27001 Cyber Risk & Compliance Lead

Jobright.ai • Chicago (IL)

On-site
USD 120,000 - 180,000
Competitive benefits starting day one
Information Security Manager
Information Security Manager

Arco Solutions • Kansas

On-site
USD 120,000 - 150,000
Flexible schedule
Health insurance