Manager Security Compliance and Risk Management

LexisNexis

Raleigh (NC)

On-site

USD 118,000 - 220,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

LexisNexis is seeking a Manager, Security – Security Compliance & Risk Management in Raleigh to lead the enterprise risk management program and drive compliance posture. You will own risk identification, scoring, and mitigation, while guiding business and technology leaders with clear, risk-based advice across the organization.

The role emphasizes staff development, audit coordination, and the creation of risk dashboards for executive leadership, with a focus on SOC 2, GDPR, and cloud risk

Qualifications

  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit with program ownership
  • 2–3 years of people management or formal team leadership experience
  • Deep knowledge of GRC disciplines across risk management, compliance, and control governance
  • Experience owning an enterprise risk register and producing executive risk reporting
  • Knowledge of NIST CSF and ISO 27001 with SOC 2 experience
  • Experience with regulatory obligations (SOC 2, GDPR, CCPA) and cloud risk
  • Experience with FedRAMP Continuous Monitoring
  • Proven ability to manage audit engagements end-to-end
  • Ability to translate risk into business language for leadership

Responsibilities

  • Own, operate, and continuously improve the enterprise security risk management program
  • Lead risk exception and acceptance processes with documentation and approvals
  • Escalate and resolve cybersecurity risks promptly across the organization
  • Advise business and tech stakeholders with pragmatic risk-based guidance
  • Manage, coach, and develop a security team including performance management
  • Set clear priorities and balance audit, compliance, and ConMon activities
  • Create metrics and dashboards for senior leadership and board materials
  • Communicate risk posture to both technical and non-technical audiences

Skills

Risk management
GRC
Audit management
Communication
Cloud risk (AWS/GCP/Azure)
Regulatory knowledge (SOC 2, GDPR, CCA
FedRAMP Monitoring
Program ownership
Leadership

Education

Bachelor’s degree in Information Security/Computer Science/Risk Management or related

Tools

ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Manager, Security – Security Compliance & Risk Management

Core Responsibilities
Risk Management
  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
People Leadership
  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities
  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
Reporting & Communication
  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program
Management Duties
  • Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.
  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.
  • Manage and encourage new ideas from staff to foster improvements through innovations.
  • Empower the staff to be accountable and responsible for their own actions and decisions.
  • All other duties as assigned.
Qualifications
Required
  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
  • 2–3 years of people management or formal team leadership experience, including performance management and team development
  • Deep, hands‑on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade‑offs in both technical and executive conversations
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands‑on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
  • Experience with technology‑sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end‑to‑end and interface directly with internal and external auditors
  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
Preferred
  • CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
  • Prior experience in a SaaS, cloud, or technology product company

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Manager, Information Security GRC
Manager, Information Security GRC

Sutton Bank • Columbus (OH)

On-site
USD 110,000 - 170,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
Sr. Staff Risk Management Analyst
Sr. Staff Risk Management Analyst

Jobgether • United States

On-site
USD 140,000 - 190,000
Medical, dental, and vision
401(k) retirement plan with company  匹
Flexible PTO
+5
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000