ForgeApply
Try it free

ForgeApply · Job listing

Manager Security Compliance and Risk Management

RELX (LexisNexisLegal)

Raleigh, NC, US$118k – $220konsite

Tailor your resume for this RELX (LexisNexisLegal) job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for RELX (LexisNexisLegal)'s site. Free trial, no card required.

About this role

Manager, Security – Security Compliance & Risk Management  

Core Responsibilities  

Risk Management  

• Own and   operate   the enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register  

• Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced  

• Drive   timely   identification, escalation, and resolution of cybersecurity risks and issues across the organization  

• Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns  

People Leadership  

• Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring  

• Set clear priorities, delegate work effectively, and   maintain   team capacity across concurrent audit, compliance, and   ConMon   activities  

• Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles  

Reporting & Communication  

• Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics  

• Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps  

• Support the CISO in preparing board and executive committee materials on the state of the security and compliance program  

Management Duties  

• Carry out management responsibilities   in accordance with   the organization’s policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.  

• Ensure all staff   is   provided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staff   is   provided with frequent feedback and coaching   in order to   meet and exceed individual and team performance goals consistently.  

• Manage and encourage   new ideas   from staff to foster improvements through innovations.  

• Empower the staff to be accountable and responsible for their own actions and decisions.  

• All other duties as assigned.  

Qualifications  

Required  

• 6–8 years of progressive experience in information security compliance, risk management, or IT audit, with   demonstrated   ownership of program-level responsibilities — not just participation  

• 2–3 years of people management or formal team leadership experience, including performance management and team development  

• Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations  

• Demonstrated experience   owning an enterprise risk register and managing the full risk lifecycle   and producing risk reporting for executive audiences  

• Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping,   identifying   gaps, and translating framework requirements into actionable compliance activities; SOC 2 experience   required  

• Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements  

• Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations  

• Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors  

• Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls  

• Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level  

• Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences  

• Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection  

• Bachelor’s degree in Information Security , Computer Science, Risk Management, or a related field — or equivalent practical experience  

Preferred  

• CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus — candidates without a relevant certification should be prepared to   demonstrate   equivalent depth through experience  

• Experience with GRC platforms such as ServiceNow GRC, Archer,   OneTrust , or   LogicGate  

• Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)  

• Prior experience in a SaaS, cloud, or technology product company  



U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates.



This job is eligible for an annual incentive bonus.





 We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form  or pleas

Salary insight

The midpoint of this range ($169k) is about 21% above the median disclosed salary for Raleigh-Durham roles listed on ForgeApply ($140k across 155 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this RELX (LexisNexisLegal) role before you apply.

Tailor my resume for this job

Similar jobs

More like this: More jobs at RELX (LexisNexisLegal) · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)