Manager, Information Security Governance and Compliance
Core
Establish an accountable GRC team to resolve friction between engineering and business leadership, preventing regulatory exposure through proactive audit leadership and policy governance.
Role type
Manager, Information Security Governance, Risk, and Compliance (GRC)
Builds
Enterprise policy lifecycle, formal exceptions architecture, and AI-first governance workflows
Domain
Cybersecurity, Regulatory Compliance, Telecommunications
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
People leadership, regulatory framework governance, audit defense, policy governance modeling, AI application for compliance, complex audit leadership
Preferred skills
NIST CSF or CIS Controls familiarity, CISM/CISA/CRISC certifications, telecommunications background
Technologies
PCI-DSS, NYDFS, CCPA, NIST CSF, CIS Controls, AI-enabled compliance tools
Responsibilities
Mentor and lead a dedicated team of GRC professionals to achieve departmental OKRs; Direct execution of continuous monitoring and annual certification lifecycles for PCI-DSS, NYDFS, CCPA; Serve as primary escalation leader for audit oversight and remediation; Oversee enterprise policy lifecycle and formal exceptions architecture; Guide deployment of enterprise-wide security awareness initiatives; Partner with peer security leaders to introduce AI-first governance workflows
Seniority
Manager, hands-on leadership
