GRC & Information Security Manager

Lancesoft

California (MO)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lancesoft seeks a Manager of Governance, Risk, and Compliance (GRC) to oversee and support information security, IT regulatory, privacy risk, third-party risk, and compliance initiatives.

This role will work closely with internal stakeholders, external auditors, and third-party vendors to maintain security controls, manage risks, support regulatory compliance, and improve the organization's overall GRC processes.

Qualifications

  • Experience across Governance, Risk, and Compliance (GRC) and Information Security risk management.
  • Experience with SOX, ITGC controls, risk assessments, vendor/third-party risk management, and audit coordination.
  • Knowledge of PCI DSS, GDPR, CCPA, and NIST CSF compliance requirements.
  • Experience using ServiceNow Change Management to support ITGC and compliance.
  • Experience developing security policies, standards, procedures, risk metrics, and reporting.

Responsibilities

  • Perform Information Security, IT regulatory, and privacy risk assessments across cloud and internal technology environments and systems.
  • Lead the Vendor Risk Management / Third-Party Risk Management (TPRM) program, including security risk assessments of third parties and contract reviews to ensure appropriate security controls are in place.
  • Lead ongoing compliance activities for IT General Controls (ITGC) and SOX, coordinating with external auditors and internal stakeholders.
  • Lead the organization's Security Training and Awareness Program, including periodic security training for specific employee groups.
  • Manage the phishing awareness program, including organization-wide simulated phishing campaigns.
  • Manage and drive risk remediation activities with internal stakeholders and third parties.
  • Manage the ServiceNow Change Management module to support compliance with ITGC change management controls.
  • Develop and maintain internal information security policies, standards, and procedures.
  • Contribute to additional GRC and compliance programs, including: PCI DSS GDPR CCPA NIST Cybersecurity Framework (NIST CSF)
  • Build and maintain strong working relationships with internal stakeholders outside of Information Security.
  • Develop and maintain IT risk management metrics, dashboards, and reports.

Skills

GRC
InfoSec
IT risk assessment
SOX/ITGC
Vendor risk
Audit coordination
NIST CSF
PCI DSS/GDPR/CCPA
ServiceNow Change Mgmt
Policy development
Stakeholder mgmt

Job description

Lancesoft seeks a Manager of Governance, Risk, and Compliance (GRC) to oversee and support information security, IT regulatory, privacy risk, third-party risk, and compliance initiatives.

This role will work closely with internal stakeholders, external auditors, and third-party vendors to maintain security controls, manage risks, support regulatory compliance, and improve the organization's overall GRC processes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Manager: Risk, Compliance & Audit Lead
Senior GRC Manager: Risk, Compliance & Audit Lead

G2 • Chicago (IL)

On-site
USD 120,000 - 190,000
Manager of Governance, Risk, and Compliance
Manager of Governance, Risk, and Compliance

Lancesoft • California (MO)

On-site
USD 120,000 - 180,000
IT GRC Program Lead: Risk, Compliance & Policy
IT GRC Program Lead: Risk, Compliance & Policy

Cynosure IT Innovations LLC • Chicago (IL)

On-site
USD 120,000 - 160,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Director: Audit, Compliance & Risk Leadership
GRC Director: Audit, Compliance & Risk Leadership

Elise A.I. Technologies Corp. • San Francisco (CA)

On-site
USD 200,000 - 275,000
Equity in the company
Medical, Dental and Vision premiums ️
Fully paid parental leave
+6
Remote GRC Director — Federal Compliance & Risk
Remote GRC Director — Federal Compliance & Risk

Jobgether SRL • United States

Remote
USD 140,000 - 210,000
401(k) match
Health insurance (employee)
Paid time off 3 weeks
+3
Global InfoSec GRC Manager — Lead Compliance & Risk
Global InfoSec GRC Manager — Lead Compliance & Risk

Ivalua • New York (NY)

Hybrid
USD 112,000 - 208,000
Competitive salary
Healthcare benefits
Hybrid working model
+2
Senior GRC Leader: Risk, Compliance & IT Controls
Senior GRC Leader: Risk, Compliance & IT Controls

B12 Consulting • Houston (TX)

On-site
USD 147,050 - 230,850
Director of Information Security GRC & Risk
Director of Information Security GRC & Risk

Surescripts • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Healthcare
Paid time off
Parental leave
+3
GRC Lead: Security, Risk & Compliance
GRC Lead: Security, Risk & Compliance

Hansen Technologies • Columbia (SC)

On-site
USD 110,000 - 150,000