Information Security GRC Leader

Steptoe LLP

Washington (District of Columbia)

Hybrid

USD 148,000 - 161,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401K Plan
Profit-Sharing
Paid Time-Off
Wellness Program

Job summary

Steptoe LLP in Washington, DC, seeks a Manager of Information Security Governance, Risk & Compliance to lead the firm’s GRC program. You will partner with the Director of Information Security, OGC, IT and risk teams to ensure policies, controls and regulatory obligations align with client expectations and business objectives.

The role requires deep knowledge of security frameworks, with experience in the legal or professional services sector, and the ability to translate regulatory requirements

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Systems or related discipline.
  • 7–10 years of information security experience, with at least 4 years in governance, risk and compliance.
  • Experience supporting an ISO 27001 certified organization.
  • Experience conducting enterprise security risk assessments and managing external audits.
  • Strong understanding of security governance in a regulated professional services environment.
  • Excellent written, presentation and stakeholder management skills.

Responsibilities

  • Maintain and improve the firm's ISMS.
  • Develop, review and maintain information security policies, standards, procedures and guidelines.
  • Manage the firm's security governance framework and policy lifecycle.
  • Prepare executive reporting and leadership-level metrics on cyber risk and compliance.
  • Lead enterprise information security risk assessments and analyses for new technologies.
  • Oversee third‑party risk assessments and vendor security reviews.
  • Coordinate compliance with frameworks such as ISO 27001, ISO 22301 and client requirements.
  • Coordinate internal and external audits and manage evidence collection.
  • Develop and manage security awareness programs and phishing simulations.
  • Collaborate with Security Operations, Security Engineering, Infrastructure and Legal teams to enforce controls and meet regulatory obligations.
  • Drive continuous improvements and automation of governance and compliance activities.

Skills

Governance
Risk management
Compliance
Stakeholder management
Audits
Security awareness
Vendor risk management

Education

Bachelor's degree in Information Security
Bachelor's degree in Computer Science
Bachelor's degree in Information Systems

Tools

GRC tools
CrowdStrike Next-Gen SIEM
Microsoft 365 security ecosystem
Identity and Access Management
Vendor risk management platforms

Job description

Steptoe LLP in Washington, DC, seeks a Manager of Information Security Governance, Risk & Compliance to lead the firm’s GRC program. You will partner with the Director of Information Security, OGC, IT and risk teams to ensure policies, controls and regulatory obligations align with client expectations and business objectives.

The role requires deep knowledge of security frameworks, with experience in the legal or professional services sector, and the ability to translate regulatory requirements

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Information Security Governance, Risk, and Compliance
Manager, Information Security Governance, Risk, and Compliance

Steptoe LLP • Washington

Hybrid
USD 148,000 - 161,000
Medical, Dental, Vision
401K Plan
Profit-Sharing
+2
Senior InfoSec GRC Manager | Risk, Compliance & Governance
Senior InfoSec GRC Manager | Risk, Compliance & Governance

Sutton Bank • Columbus (OH)

On-site
USD 110,000 - 170,000
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
GRC Strategy Lead, Information Security & Compliance
GRC Strategy Lead, Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
GRC Specialist: ISO 27001, Risk & Audit Readiness
GRC Specialist: ISO 27001, Risk & Audit Readiness

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Cybersecurity & GRC Program Leader
Cybersecurity & GRC Program Leader

Riveron • United States

Remote
USD 100,000 - 130,000
Medical insurance
401(k) with company match
Paid Time Off (PTO)
Security GRC Leader: Governance, Risk & Compliance
Security GRC Leader: Governance, Risk & Compliance

Quiet Capital • Colorado

On-site
USD 270,000 - 290,000
Medical insurance
Dental insurance
Vision insurance
+7
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Global InfoSec GRC Manager — Lead Compliance & Risk
Global InfoSec GRC Manager — Lead Compliance & Risk

Ivalua • New York (NY)

Hybrid
USD 112,000 - 208,000
Competitive salary
Healthcare benefits
Hybrid working model
+2