Manager, Security Compliance

CardWorks, Inc.

Orlando (FL)

On-site

USD 128,490 - 142,767

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Pay
401(k) Plan with Company Match
Paid Vacation, Sick Days and Bank Holidays
Wellness Programs

Job summary

A diversified financial service provider seeks a Security Compliance Manager to enhance their enterprise security compliance program. Responsibilities include managing compliance operations, tracking security exceptions, and overseeing documentation. The ideal candidate will have over 8 years of experience in information security or compliance, knowledge of security frameworks like NIST and PCI DSS, and be proficient in vulnerability management. The position is based in Orlando, FL, with options for hybrid or fully remote work.

Qualifications

  • Requires working knowledge of security frameworks like NIST CSF, PCI DSS.
  • Experience collaborating with diverse teams.
  • Strong understanding of security risk assessment methodologies.

Responsibilities

  • Manage compliance operations and execute assessments.
  • Track security exceptions and issue escalations.
  • Oversee information security documentation governance.

Skills

Information security
Risk management
Compliance
Analytical skills
Communication skills

Education

Bachelor’s degree in IT or related field
8+ years of experience

Tools

Vulnerability management
Encryption
Identity and access management

Job description

***Join our team - and take the next step in achieving a fulfilling career!*****What We Do**At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.**Who We Are**CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.Merrick Bank is an FDIC-insured Utah Industrial Loan Bank. Merrick operates three main business lines: credit cards, recreational lending, and merchant services.Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.**Position Summary:**The Security Compliance Manager is an individual contributor responsible for operationalizing, executing, and maturing the enterprise security compliance program. This role reports to the Director of Security Risk & Compliance and ensures that the organization’s security compliance strategy is translated into effective operational processes, assessments, and workflows. Core responsibilities include managing compliance operations, executing assessments, reviewing controls, supporting audit readiness, coordinating documentation and evidence, and ensuring accuracy and consistency across compliance systems and reporting.**Essential Functions:****Compliance Program Execution*** Execute and continuously improve enterprise security compliance processes and assessments, supporting the strategic direction established by the Manager.* Operate and maintain the security compliance technology platform, ensuring assessments, evidence collection, and issue tracking are completed accurately and on schedule.* Coordinate compliance assessment activities and ensure required documentation is complete and aligned with standards.* Create, manage, and maintain standardized templates, procedures, workflows, and reporting to support consistent compliance operations.**Security Exception Management*** Execute detailed assessments of security exception requests, documenting risks, mitigating controls, approvals, and expiration tracking, in accordance with governance defined by the Director.* Track exception approvals, expirations, and remediation requirements, ensuring timely reminders, escalations, and accuracy of exception data.**Security Issue Escalation & Tracking*** Manage execution of the Security Compliance Finding and Issue Escalation process, ensuring control gaps and audit findings are documented, monitored, and remediated on schedule.* Maintain and operationalize workflow steps aligned to governance requirements defined by the Director, ensuring appropriate escalation of overdue or high‐risk issues.* Align information security issue tracking with Enterprise Risk Management processes and escalate high‐risk issues through established governance forums.**Documentation Governance*** Oversee the Information Security documentation governance program, ensuring policies, standards, procedures, and guidelines are accurate, current, and aligned with regulatory, customer, and internal control requirements.* Implement and maintain the documentation lifecycle processes, including drafting, review, approval, publication, version control, retention, and retirement.* Coordinate updates to documentation to ensure alignment with applicable frameworks such as CRI, NIST CSF, PCI DSS, and CIS 18, reflecting changes in technology, controls, and risk posture.* Track documentation quality, exceptions, gaps, and remediation activities; prepare reports and metrics to support leadership visibility and compliance oversight.* Partner with security, risk, IT, and compliance stakeholders to ensure documentation supports audits, assessments, and ongoing control operation.**Education and Experience*** 8+ years of experience in information security, risk management, compliance, or related disciplines.* Bachelor’s degree in IT or related field preferred or equivalent work experience in lieu of degree.* Working knowledge of security frameworks such as Cyber Risk Institute, NIST CSF, CIS Controls, and PCI DSS along with experience applying these and other industry-specific regulations to projects and infrastructure.* Experience in collaborating across diverse teams, including IT, business units, and external stakeholders, to address security requirements and align with project objectives.* Strong understanding of security risk assessment methodologies, controls implementation, and process optimization, with a track record of successfully mitigating risks and enhancing security practices.**Summary of Qualifications:*** Strong working knowledge of major security frameworks and regulatory requirements, including CRI, NIST CSF, PCI DSS, and CIS Controls, with experience aligning compliance platforms to support assessments and evidence management.* Skilled in optimizing compliance workflows, dashboards, templates, and reporting to enhance operational efficiency and audit readiness.* Proficient with core security technologies such as vulnerability management, encryption, and identity and access management.* Strong analytical and communication skills, able to identify trends, explain complex technical and regulatory concepts, and support cross‐functional collaboration.* Highly organized, detail‐oriented, and capable of managing multiple priorities while improving processes, automation, and program scalability.Ideally, the qualified candidate will work at the following location(s): South Jordan, UT; Woodbury, NY; Horsham, PA; Pittsburgh, PA; Orlando, FL. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role. The salary range for this position, if located in NY Metro/NY State is $128,490 to $142,767. However, please note that the salary range will vary for other geographic areas.#INDHP**Our Employee Value Proposition*** Competitive Pay, including a Bonus Target or Variable Pay Incentive Program* Benefits Package -Medical, Dental, and Vision (plus much more)* 401(k) Plan with Company Match* Short- & Long-Term Disability* Wellness Programs* Group Life and AD&D Insurance* Paid Vacation, Sick Days and bank Holidays* Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition*We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.**We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic. We will conduct a thorough background check for all hires in compliance with applicable laws.*
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Assistant General Counsel
Vice President, Assistant General Counsel

CardWorks, Inc. • Town of Woodbury (NY)

On-site
USD 210,000 - 250,000
Bonus Target / Variable Pay
Medical, Dental, Vision
401(k) Plan with Match
+3
Manager, Security Compliance
Manager, Security Compliance

CardWorks Servicing LLC • United States

On-site
USD 128,000 - 143,000
Competitive pay
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
+1
Director, Security Risk Management
Director, Security Risk Management

CardWorks, Inc. • Orlando (FL)

On-site
USD 120,000 - 160,000
Senior Specialist, Corporate Communications
Senior Specialist, Corporate Communications

CardWorks Financial Group • Syosset (NY)

On-site
USD 85,000 - 105,000
Medical, Dental, and Vision insurance
401(k) Plan with company match
Paid vacation and holidays
+1
Senior Privacy Analyst – Support & Governance
Senior Privacy Analyst – Support & Governance

CardWorks, Inc. • South Jordan (UT)

On-site
USD 90,000 - 125,000
Bonus Target
Medical, Dental, Vision
401(k) Match
+2
Analyst II Credit Card Compliance
Analyst II Credit Card Compliance

CardWorks, Inc. • South Jordan (UT)

On-site
USD 70,000 - 90,000
Competitive Pay
401(k) Plan with Company Match
Paid Vacation and Sick Days
Sr. Privacy Analyst, Support & Governance
Sr. Privacy Analyst, Support & Governance

Merrick-Bank • Lampton (UT)

On-site
USD 120,000 - 180,000
Bonus target
Medical, dental, vision
401(k) matching
+1
Associate I, Fraud Engagement
Associate I, Fraud Engagement

CardWorks Financial Group • Pittsburgh

On-site
USD 36,000 - 42,000
Bonuses
Benefits package
401(k) plan
+1
Lead Site Reliability Engineer
Lead Site Reliability Engineer

CardWorks Servicing • Pittsburgh

On-site
USD 146,000 - 163,000
Medical, Dental, and Vision benefits
401(k) Plan with Company Match
Paid Vacation and Sick Days
+1
Associate I, Fraud Engagement
Associate I, Fraud Engagement

CardWorks • Pittsburgh

On-site
USD 36,000 - 52,000
Competitive pay
Benefits package
401(k) Plan