Manager Security Compliance and Risk Management

RELX Group plc

Raleigh, NC

JOB DETAILS
SALARY
$118,300–$219,800 Per Year
SKILLS
Auditing, Cloud Computing, Coaching, Communication Skills, Computer Science, Concrete, Customer Support/Service, Disciplinary Action, Documentation, Enterprise Protection, Establish Priorities, External Audit, Genetics, ISO (International Organization for Standardization), Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, Internet Security, Leadership, Maintain Compliance, Metrics, People Management, Performance Management, Performance Metrics, Presentation/Verbal Skills, Problem Solving Skills, Regulations, Regulatory Compliance, Reporting Dashboards, Risk, Risk Analysis, Risk Management, Security Compliance, Software as a Service (SaaS), Talent Management, Team Building, Team Lead/Manager, Time Management, Training/Teaching, U.S. National Institute of Standards and Technology (NIST), Writing Skills
LOCATION
Raleigh, NC
POSTED
4 days ago

Manager, Security Compliance & Risk Management

The Manager, Security Compliance & Risk Management, is responsible for leading the Security Compliance and Risk Management function within the Information Security organization. This role owns the frameworks, processes, and programs that provide structured oversight of technology and security risk across the company. This manager serves as a critical bridge between the security program and the business. The role will translate risk into actionable insight for executives, boards, auditors, regulators, and customers.

This is a people manager role overseeing a team of security engineers responsible for the day-to-day operationalization of audit, compliance, control, and FedRAMP Continuous Monitoring activities. The right candidate is both a capable program builder and an engaged people leader who can develop talent, allocate work effectively, and drive consistent execution across the team.

Core Responsibilities

Risk Management

  • Own and operate the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register

  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced

  • Drive timely identification, escalation, and resolution of cybersecurity risks and issues across the organization

  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns

People Leadership

  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring

  • Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities

  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles

Reporting & Communication

  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics

  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps

  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program

Management Duties

  • Carry out management responsibilities in accordance with the organization's policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.

  • Ensure all staff is provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff is provided with frequent feedback and coaching in order to meet and exceed individual and team performance goals consistently.

  • Manage and encourage new ideas from staff to foster improvements through innovations.

  • Empower the staff to be accountable and responsible for their own actions and decisions.

  • All other duties as assigned.

Qualifications

Required

  • 6-8 years of progressive experience in information security compliance, risk management, or IT audit

  • 2-3 years of people management or formal team leadership experience

  • Demonstrated experience owning an enterprise risk register and managing the full risk lifecycle

  • Hands-on experience with control frameworks including NIST CSF and ISO 27001; SOC 2 experience strongly preferred

  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA), depending on customer base

  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations

  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors

  • Strong written and verbal communication skills; ability to translate technical risk into business language for executive and non-technical audiences

  • Bachelor's degree in information security, Computer Science, Risk Management, or a related field - or equivalent practical experience

Preferred

  • Relevant certification: CRISC, CISA, CISSP, or CISM

  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or LogicGate

  • Experience supporting customer security reviews and trust/assurance programs

  • Prior experience in a SaaS, cloud, or technology product company

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates.

This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

About the Company

R

RELX Group plc