Manager Security Compliance and Risk Management
LexisNexisAbout the role
Manager, Security – Security Compliance & Risk Management
Function: Information Security / Compliance & Risk
Location: [Raleigh / Hybrid]
About the Role
The Manager, Security – Security Compliance & Risk Management is responsible for leading the Security Compliance and Risk Management function within the Information Security organization. This role owns the frameworks, processes, and programs that provide structured oversight of technology and security risk across the company. This manager serves as a critical bridge between the security program and the business — translating risk into actionable insight for executives, boards, auditors, regulators, and customers.
This is a people manager role overseeing a team of security engineers responsible for the day-to-day operationalization of audit, compliance, control, and FedRAMP Continuous Monitoring activities. The right candidate is both a capable program builder and an engaged people leader who can develop talent, allocate work effectively, and drive consistent execution across the team.
Core Responsibilities
People Leadership
Manage, mentor, and develop a team of security engineers
Set clear priorities, delegate work effectively, and maintain team capacity across concurrent audit, compliance, and ConMon activities
Foster a culture of quality, accountability, and continuous improvement within the team
Risk Management
Own and operate the enterprise technology and security risk register, including risk identification, scoring, tracking, and reporting
Lead the risk exception and risk acceptance process, ensuring appropriate documentation, approvals, and periodic review
Drive identification, escalation, and resolution of cybersecurity risks and issues across the organization
Serve as a trusted advisor to business and technology stakeholders on compliance and risk matters
Provide risk-based reporting to support executive and board-level decision-making on the state of the security program
Compliance & Control Governance
Oversee enterprise control management activities, including control design, testing, effectiveness tracking, issue management, and remediation
Map controls to applicable frameworks including NIST CSF, ISO 27001, SOC 2, and other relevant technology-sector obligations
Support and maintain cybersecurity compliance certifications and initiatives (e.g., ISO 27001, SOC 2, Cyber Essentials)
Perform regulatory horizon scanning to identify emerging compliance requirements and assess organizational impact
Coordinate and monitor recurring security and compliance assessments, including intern
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s