Manager, Information Security Governance, Risk & Compliance (GRC)

Burtch Works

United States

Remote

USD 140,000 - 170,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health and wellness benefits
Remote, US-based work

Job summary

Burtch Works is assisting a large financial services organization in finding a Manager, Information Security GRC. This remote US role leads governance, risk, and assurance across regulatory compliance and technology risk, partnering with executives and auditors to strengthen control maturity and audit readiness.

You will guide the design and testing of ITGCs, application controls, and PCI DSS measures, while coaching a high‑performing team and driving measurable risk outcomes in a regulated

Qualifications

  • Bachelor's degree or equivalent professional experience in information security/related field.
  • 10+ years of progressive experience in GRC, cybersecurity, controls, or related disciplines.
  • Minimum 5 years of direct people leadership experience.
  • Demonstrated PCI DSS experience with scope definition, design, testing, remediation, and interaction with QSA/ISA.
  • Strong knowledge of NYDFS Part 500, NIST CSF, CIS Controls, and PCI DSS.

Responsibilities

  • Set multi‑year GRC strategy and roadmap for governance, risk, compliance, and assurance.
  • Lead design, testing, and remediation of ITGCs and application controls across enterprise.
  • Oversee PCI DSS engagement, scope, controls, evidence, and interaction with stakeholders.
  • Align controls with regulatory requirements and regulatory bodies; drive audit readiness.
  • Partner with auditors, regulators, and business leaders to defend risk decisions and remediation plans.
  • Advance GRC technology usage and automation for monitoring and evidence collection.
  • Coach and develop the information security and assurance team; manage performance.
  • Communicate complex risk and control topics to executives and cross‑functional teams.
  • Make defensible risk decisions and resource allocation for remediation and control coverage.

Skills

GRC leadership
Executive communication
Regulatory experience
People leadership

Education

Bachelor's degree in Information Security or related field

Tools

ServiceNow IRM
PCI DSS familiarity

Job description

Job Title: Manager, Information Security Governance, Risk & Compliance (GRC)
Location: Remote, United States

About The Company

Our client is a large, established financial services organization undergoing significant technology, cybersecurity, and risk transformation. The organization operates within a highly regulated environment and is investing in modern governance, risk, compliance, and cybersecurity assurance capabilities to strengthen enterprise controls, regulatory readiness, and information security risk management.

The organization offers a highly collaborative environment where senior leaders have the opportunity to influence enterprise security strategy, regulatory compliance, technology risk, assurance practices, and the continued maturation of the broader Information Security organization.

Job Summary

We are looking for a Manager, Information Security Governance, Risk & Compliance (GRC) to provide strategic and operational leadership across cybersecurity assurance, governance, controls, regulatory compliance, and technology risk.

This individual will lead a team while owning and advancing critical assurance capabilities across a highly regulated enterprise environment. The ideal candidate will combine deep GRC and cybersecurity controls expertise with strong people leadership, executive presence, regulatory experience, and the ability to personally engage in complex assurance and control activities when needed.

The Manager will work across Information Security, Technology, Risk, Audit, Legal, Compliance, and business leadership, establishing sustainable governance and assurance practices while improving control effectiveness, audit readiness, regulatory alignment, and measurable risk outcomes.

Key Responsibilities
  • GRC & Assurance Strategy: Establish and execute a multi-year vision and roadmap for information security governance, risk, compliance, controls, and assurance capabilities.
  • Cybersecurity Controls: Design, assess, test, document, and remediate IT general controls (ITGCs), application-level controls, and cybersecurity controls across complex enterprise environments.
  • PCI DSS Compliance: Provide leadership across PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and interaction with QSA/ISA stakeholders.
  • Regulatory & Framework Alignment: Apply frameworks and regulatory requirements including NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS to enterprise security and control environments.
  • Audit & Regulatory Readiness: Partner directly with internal and external auditors, regulators, and business stakeholders to explain and defend control design, risk decisions, remediation strategies, and supporting evidence.
  • GRC Technology & Automation: Advance the use of GRC platforms and automation to improve control monitoring, assurance testing, evidence collection, audit readiness, and overall program efficiency.
  • People Leadership: Lead, coach, develop, and manage information security and assurance professionals through performance management, workforce planning, stretch assignments, and structured talent development.
  • Executive & Stakeholder Communication: Communicate complex cybersecurity, control, compliance, and technology-risk topics to senior executives, business leaders, auditors, regulators, and other cross‑functional stakeholders.
  • Risk & Decision Ownership: Make and document defensible decisions regarding control design, exception treatment, risk acceptance recommendations, remediation priorities, and resource allocation.
  • Operational Leadership: Establish measurable outcomes across audit performance, control coverage, exemption rates, remediation, completion velocity, and other assurance‑program metrics while remaining hands‑on when senior‑level execution is required.
Requirements
  • Education: Bachelor's degree in Information Security, Computer Science, Information Systems, a related discipline, or equivalent professional experience.
  • Experience: Minimum 10 years of progressive experience across GRC, information security, technology risk, internal/external audit, controls, cybersecurity assurance, or closely related disciplines.
  • Leadership: Minimum 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development.
  • PCI DSS: Demonstrated experience operating within or directly supporting PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and QSA/ISA interaction.
  • Frameworks & Regulations: Strong working knowledge of NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS, including the ability to design and defend control rationale.
  • Controls: Demonstrated experience designing, testing, and remediating IT general controls (ITGCs) and application-level controls.
  • Executive Communication: Proven ability to communicate complex risk and control matters to executive audiences, audit committees, regulators, and cross‑functional stakeholders.
  • Other: Ability to operate independently under limited direction, prioritize competing demands, make defensible decisions, and consistently deliver results within ambiguous and fast‑moving environments.
Preferred Qualifications
  • Experience implementing or operating ServiceNow Integrated Risk Management (IRM) or comparable enterprise GRC platforms such as Archer, AuditBoard, OneTrust, or MetricStream is preferred.
  • Experience operating within a Product Operating Model, including roadmap planning, backlog grooming, sprint‑based delivery, feature commitment management, and metrics‑driven execution, is also preferred.
  • Experience within financial services, banking, or another highly regulated industry, including direct interaction with regulators such as state banking authorities, the OCC, FDIC, or NYDFS, is highly desirable.
  • Industry certifications including CISSP, CISA, CISM, CRISC, CGEIT, or CIA are preferred. Demonstrated success improving control automation, continuous control monitoring, assurance testing efficiency, audit‑readiness practices, and evidence‑as‑code approaches is also beneficial.
Benefits
  • Competitive Compensation: Competitive compensation commensurate with senior‑level GRC, cybersecurity assurance, and leadership experience.
  • Health and Wellness: Comprehensive health and wellness benefits.
  • Work‑Life Balance: Remote U.S.-based opportunity within a collaborative enterprise organization.
  • Professional Development: Opportunity to lead and develop assurance professionals while influencing enterprise cybersecurity, governance, regulatory compliance, and technology‑risk strategy.
  • Additional Perks: Opportunity to work directly with senior executives, cybersecurity leadership, auditors, regulators, and enterprise stakeholders while helping mature a critical Information Security assurance function.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
VP of Governance, Risk & Compliance
VP of Governance, Risk & Compliance

Tiro Security • Los Angeles (CA)

On-site
USD 200,000 - 280,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Information Security Governance, Risk & Compliance Manager
Information Security Governance, Risk & Compliance Manager

JustMarkets • United States

Remote
USD 120,000 - 190,000
20 vacation days
10 sick leave days
Public holidays per policy
+5
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Group • United States

Remote
USD 140,000 - 190,000