Manager Security Compliance and Risk Management

RELX

Raleigh (NC)

On-site

USD 118,300 - 219,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual incentive bonus

Job summary

RELX in Raleigh, NC seeks a seasoned leader to own and operate the enterprise technology and security risk management program. You will drive risk identification, escalation, and resolution, while serving as a trusted advisor to business and tech stakeholders.

You will manage a team of security engineers, guide audits and compliance efforts, and deliver dashboards and board-ready materials. This role emphasizes continuous improvement, audit-readiness, and pragmatic risk guidance at senior levels.

Qualifications

  • 6–8 years of progressive information security compliance, risk management, or IT audit with program ownership
  • 2–3 years of people management or formal team leadership experience
  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance
  • Experience owning an enterprise risk register and producing executive risk reporting
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001; SOC 2 required
  • Experience with regulatory obligations (SOC 2, GDPR, CCPA) and cloud risk implications
  • Experience with FedRAMP Continuous Monitoring and audit engagements end-to-end
  • Proven ability to design or mature a compliance program across people, processes, and controls
  • Strong communication skills to translate risk for senior leadership
  • Bachelor’s degree or equivalent practical experience

Responsibilities

  • Own and operate the enterprise technology and security risk management program
  • Lead risk exception and acceptance process with documented approvals
  • Drive timely identification, escalation, and resolution of cybersecurity risks
  • Provide risk-based guidance to stakeholders to unblock decisions
  • Manage, coach, and develop a team of security engineers
  • Set priorities and manage capacity across audits, compliance, and ConMon
  • Produce risk dashboards and senior leadership reporting
  • Support the CISO with board materials and executive communications
  • Foster audit-readiness and evidence quality as ongoing standards
  • Drive improvements through staff ideas and innovation

Skills

Information security
Risk management
Auditing
Leadership
Communication

Education

Bachelor’s degree in Information Security, Computer Science, Risk Management, or related field

Tools

ServiceNow GRC
Archer
OneTrust
LogicGate

Job description

Core Responsibilities
Risk Management
  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register
  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced
  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization
  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns
People Leadership
  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring
  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities
  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles
Reporting & Communication
  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics
  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps
  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program
Management Duties
  • Carry out management responsibilities in accordance with the organization’s policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.
  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.
  • Manage and encourage new ideas from staff to foster improvements through innovations.
  • Empower the staff to be accountable and responsible for their own actions and decisions.
  • All other duties as assigned.
Qualifications
Required
  • 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with demonstrated ownership of program-level responsibilities — not just participation
  • 2–3 years of people management or formal team leadership experience, including performance management and team development
  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations
  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle and producing risk reporting for executive audiences
  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping, identifying gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience required
  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements
  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations
  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors
  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls
  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level
  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences
  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field — or equivalent practical experience
Preferred
  • CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to demonstrate equivalent depth through experience
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate
  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)
  • Prior experience in a SaaS, cloud, or technology product company

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus • Neenah (WI)

On-site
USD 112,000 - 169,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000