Manager, Information Security Governance, Risk, and Compliance

Steptoe LLP

Washington (District of Columbia)

Hybrid

USD 148,000 - 161,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401K Plan
Profit-Sharing
Paid Time-Off
Wellness Program

Job summary

Steptoe LLP in Washington, DC, seeks a Manager of Information Security Governance, Risk & Compliance to lead the firm’s GRC program. You will partner with the Director of Information Security, OGC, IT and risk teams to ensure policies, controls and regulatory obligations align with client expectations and business objectives.

The role requires deep knowledge of security frameworks, with experience in the legal or professional services sector, and the ability to translate regulatory requirements

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Systems or related discipline.
  • 7–10 years of information security experience, with at least 4 years in governance, risk and compliance.
  • Experience supporting an ISO 27001 certified organization.
  • Experience conducting enterprise security risk assessments and managing external audits.
  • Strong understanding of security governance in a regulated professional services environment.
  • Excellent written, presentation and stakeholder management skills.

Responsibilities

  • Maintain and improve the firm's ISMS.
  • Develop, review and maintain information security policies, standards, procedures and guidelines.
  • Manage the firm's security governance framework and policy lifecycle.
  • Prepare executive reporting and leadership-level metrics on cyber risk and compliance.
  • Lead enterprise information security risk assessments and analyses for new technologies.
  • Oversee third‑party risk assessments and vendor security reviews.
  • Coordinate compliance with frameworks such as ISO 27001, ISO 22301 and client requirements.
  • Coordinate internal and external audits and manage evidence collection.
  • Develop and manage security awareness programs and phishing simulations.
  • Collaborate with Security Operations, Security Engineering, Infrastructure and Legal teams to enforce controls and meet regulatory obligations.
  • Drive continuous improvements and automation of governance and compliance activities.

Skills

Governance
Risk management
Compliance
Stakeholder management
Audits
Security awareness
Vendor risk management

Education

Bachelor's degree in Information Security
Bachelor's degree in Computer Science
Bachelor's degree in Information Systems

Tools

GRC tools
CrowdStrike Next-Gen SIEM
Microsoft 365 security ecosystem
Identity and Access Management
Vendor risk management platforms

Job description

Position(s) I am Applying for

Manager, Information Security Governance, Risk, and Compliance

The Manager, Information Security Governance, Risk & Compliance (GRC) is responsible for leading the firm's information security governance, risk management and compliance program across all offices. Reporting to the Director of Information Security, the role ensures that the firm's security policies, controls, certifications and regulatory obligations support client expectations, business objectives and the firm's risk appetite.

This position works closely with the Office of General Counsel (OGC), IT leadership, business leadership, Risk Management, Procurement, HR and external assessors to maintain a mature, auditable and continuously improving information security program.

The successful candidate combines strong knowledge of security frameworks with practical experience in the legal or professional services sector and the ability to translate regulatory requirements into effective operational controls.

Essential Functions
Governance
  • Maintain and continuously improve the firm's Information Security Management System (ISMS).
  • Develop, review and maintain information security policies, standards, procedures and guidelines.
  • Manage the firm's security governance framework and policy lifecycle.
  • Coordinate governance committees with the Director such as the Information Security Management Committee.
  • Prepare executive reporting, dashboards and Leadership-level metrics on cyber risk and compliance.
  • Maintain the enterprise security risk register and oversee risk treatment plans.
Risk Management
  • Lead enterprise information security risk assessments.
  • Perform business impact and security risk analyses for new technologies and strategic initiatives.
  • Manage third-party technology risk assessments and vendor security reviews.
  • Partner with Procurement / Commercial Services and OGC during vendor due diligence and contract reviews.
  • Evaluate security risks associated with cloud services, SaaS providers and emerging technologies.
  • Track remediation activities and risk acceptance decisions.
Compliance

Lead and coordinate compliance with applicable security frameworks including:

  • ISO 27001
  • ISO 22301
  • Client security questionnaires
  • Outside counsel security assessments
  • Privacy and contractual security obligations
  • Emerging regulatory and client requirements such as CMMC, UK SRA cyber requirements and other regional obligations.

Responsibilities include:

  • Coordinating internal and external audits
  • Managing evidence collection
  • Monitoring corrective actions
  • Maintaining control documentation
  • Preparing certification renewals
Third-Party Security Management

Manage relationships with external security providers including:

  • ISO 27001 / ISO 22301 compliance consultants
  • Penetration testing providers
  • Security awareness training providers
  • Phishing simulation providers
  • Vendor risk assessment platforms

Monitor vendor performance, deliverables and continuous improvement activities.

Security Awareness

Own the firm's security awareness programme by:

  • Developing annual awareness plans
  • Managing phishing simulations
  • Delivering executive and employee security education
  • Tracking participation and effectiveness
  • Supporting secure behavior across all offices
Collaboration

Partner closely with:

  • Security Operations on incident response lessons learned
  • Security Engineering on implementation of required controls
  • Infrastructure and Cloud teams on compliance requirements
  • Office of General Counsel regarding legal, contractual and regulatory obligations
  • Internal Audit and external auditors
Continuous Improvement
  • Monitor changes in regulatory requirements and industry standards.
  • Recommend improvements to governance processes and security controls.
  • Support maturity assessments against recognized security frameworks.
  • Drive automation of governance and compliance activities where practical.
Non-Essential Functions
  • Other duties may be assigned, as necessary.
Minimum Qualification
Required
  • Bachelor's degree in Information Security, Computer Science, Information Systems or related discipline.
  • 7-10 years of experience in information security, with at least 4 years in governance, risk and compliance.
  • Experience supporting an ISO 27001 certified organization.
  • Experience conducting enterprise security risk assessments.Experience managing external audits and client security assessments.
  • Strong understanding of security governance in a regulated professional services environment.
  • Excellent written, presentation and stakeholder management skills.
Preferred
  • Experience within an international law firm or other professional services organization.
  • Experience supporting global operations across North America, Europe and Asia.
  • Familiarity with legal industry client security requirements.
  • Experience with cloud security governance.
  • Experience supporting business continuity programmers.
Preferred Certifications

One or more of:

  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • CGRC (formerly CAP)
  • CISA
Technologies and Platforms

Working knowledge of technologies including:

  • CrowdStrike Next-Gen SIEM
  • Microsoft 365 security ecosystem
  • Identity and Access Management
  • Endpoint security technologies
  • Vendor risk management platforms
  • Governance, Risk and Compliance (GRC) tools
  • Security awareness platforms
  • Vulnerability management reporting
External Relationships

Manage relationships with organizations such as:

  • Active Cyber (ISO 27001 / ISO 22301)
  • Mitatech (vendor and product risk assessment)
  • KnowBe4
  • Black Hills Information Security
  • Client security assessors
  • External auditors
  • Cyber insurance assessors
Key Competencies
  • Governance and policy development
  • Enterprise risk management
  • Regulatory compliance
  • Executive communication
  • Audit management
  • Vendor risk management
  • Relationship management
  • Analytical thinking
  • Business judgment
  • Project management
  • Continuous improvement
  • Influencing without direct authority
Success Factors

Within the first 12-24 months, success will be measured by:

  • Successful maintenance of ISO 27001 and ISO 22301 certifications.
  • Improved security governance maturity.
  • Timely completion of client security assessments.
  • Reduced remediation backlog for audit findings.
  • Effective enterprise security awareness programme with measurable reductions in phishing susceptibility.
  • Timely completion of third-party security reviews.
  • Executive reporting that clearly communicates cyber risk and compliance posture.
  • Readiness for emerging compliance obligations such as CMMC, UK SRA requirements and evolving client cybersecurity expectations.
Work Environment
  • Non-smoking environment
  • Ability to maintain a flexible work schedule
  • Available to work 9:00 - 5:30 pm Monday through Friday
  • Hybrid work arrangements may be available for this position
  • Must be available to work beyond regular hours when necessary
  • Must have ability to work under tight deadlines
  • Must be able to work independently

The anticipated base salary range for this position is $148,000 - $161,000. The actual base salary offered will be dependent upon the applicant's experience and qualifications, as well as other job-related factors, including but not limited to, relevant skills, education, certifications or other professional licenses held, and if applicable, geographic location.

Steptoe offers a full range of benefits for you and your eligible dependents. Benefits currently include: medical, dental, vision, life, disability, dependent care, health care flexible spending accounts, 401K Plan, Profit-Sharing, Paid Time-Off and a robust Wellness Program.

Steptoe LLP is an equal opportunity employer EOE/Disability/Veteran. All qualified applicants will receive consideration without regard to race, color, religion, gender, national origin, sexual orientation, gender identity and expression, marital status, mental or physical disability, genetic information, or any basis proscribed by applicable statutes.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

Ice Miller LLP • Philadelphia

On-site
USD 75,000 - 100,000
Health insurance
Vision and Dental Insurance
401k (employer match)
+1
Manager, IT Commercial Services
Manager, IT Commercial Services

Steptoe LLP • Washington

Hybrid
USD 150,200 - 160,200
401K plan
Profit-sharing
Paid time-off
+2
IT Operations Engineer
IT Operations Engineer

Steptoe LLP • Chicago (IL)

Hybrid
USD 80,000 - 90,000
Medical insurance
Dental & Vision insurance
401K Plan
+1
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
IT Enterprise Risk Analyst
IT Enterprise Risk Analyst

Holland & Knight • Tampa (FL)

On-site
USD 85,000 - 110,000
Medical, dental and vision plans
401(k) and profit-sharing
Paid holidays and leave for new parents
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,000 - 169,000
Information Security GRC Leader
Information Security GRC Leader

Steptoe LLP • Washington

Hybrid
USD 148,000 - 161,000
Medical, Dental, Vision
401K Plan
Profit-Sharing
+2
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000