Manager Security Compliance and Risk Management

RELX Inc. Company

North Carolina

On-site

USD 118,000 - 220,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

LexisNexis Legal & Professional seeks a Manager, Security – Security Compliance & Risk Management to own the enterprise risk program, identify and track risks, and guide leadership on risk posture. You will lead audits, compliance activities, and a team of security engineers to strengthen controls and evidence quality.

You will produce dashboards and reports for senior leadership, support board materials, and advance the security program across people, processes, and technology.

Qualifications

  • 6–8 years of progressive experience in information security compliance and risk management.
  • 2–3 years of people management or formal team leadership experience.
  • Deep knowledge of GRC disciplines and control governance across risk and compliance.
  • Experience owning an enterprise risk register and reporting to executives.

Responsibilities

  • Own and operate the enterprise security risk management program with risk scoring and a maintained risk register.
  • Lead risk exception and acceptance processes with documented approvals and reviews.
  • Escalate and resolve cybersecurity risks across the organization.
  • Serve as trusted advisor translating risk into actionable steps for stakeholders.

Skills

Security leadership
Risk management
GRC frameworks
Stakeholder comms
Audit & compliance

Education

Bachelor's degree in Information Security

Job description

Manager, Security – Security Compliance & Risk Management

Core Responsibilities
  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
People Leadership
  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities
  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
Reporting & Communication
  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program
Management Duties
  • Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws.
  • Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.
  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible.
  • Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.
  • Manage and encourage new ideas from staff to foster improvements through innovations.
  • Empower the staff to be accountable and responsible for their own actions and decisions.
  • All other duties as assigned.
Qualifications
  • Required 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
  • 2–3 years of people management or formal team leadership experience, including performance management and team development
  • Deep, hands‑on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade‑offs in both technical and executive conversations
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands‑on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC2 experience required
  • Experience with technology-sector regulatory obligations (e.g., SOC2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
Preferred
  • CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
  • Prior experience in a SaaS, cloud, or technology product company

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers: EEO Know Your Rights.

LexisNexis Legal & Professional is a leading global provider of legal, regulatory and business information and analytics that help customers increase productivity, improve decision-making and outcomes, and advance the rule of law around the world. We help lawyers win cases, manage their work more efficiently, serve their clients better and grow their practices. We assist corporations in better understanding their markets and preventing bribery and corruption within their supply chains. We partner with leading global associations and customers to help collect evidence against war criminals and provide tools to combat human trafficking. We endeavour to advance the rule of law across the world.Our teams are combining unparalleled legal and business information with analytics and technology to advance what’s possible for the way our customers work and to advance what’s possible in the world by strengthening the rule of law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Cheyenne (WY)

Remote
USD 115,000 - 192,000
Annual incentive bonus
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Salt Lake City (UT)

Remote
USD 115,000 - 192,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Bozeman (MT)

Remote
USD 115,000 - 192,000
Annual incentive bonus
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Carson City (NV)

Remote
USD 115,000 - 192,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Salem (OR)

Remote
USD 115,000 - 192,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Augusta (ME)

Remote
USD 115,000 - 192,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

RELX INC • Montpelier (VT)

Remote
USD 115,000 - 192,000