Salary 💰 $156,300 - $241,010 per year
Tech Stack Cyber Security ServiceNow
About the role Lead the organization’s efforts to identify, assess, manage, and mitigate cyber risks Oversee critical areas of risk management, including risk/issue management, GRC tooling, security policy development, and GRC reporting Implement and maintain processes for tracking, mitigating, and resolving risks and issues Develop frameworks for consistent risk classification, prioritization, and escalation Manage the implementation and ongoing maintenance of Governance, Risk, and Compliance (GRC) tooling Ensure GRC tools support risk management workflows, reporting, and compliance tracking Develop, implement, and maintain information security policies, standards, and procedures Oversee the creation and delivery of GRC reports to senior leadership, stakeholders, and regulatory bodies Manage the lifecycle of IT audit findings, ensuring timely remediation and closure Collaborate with IT and network teams to validate the security impact of proposed changes Manage the policy exception process, including intake, review, approval, and tracking Build and lead a high-performing team responsible for cyber risk management and GRC functions Requirements Bachelor’s degree in Cybersecurity, Information Security, Risk Management, Business Administration, or a related field (Master’s degree preferred) 10+ years of experience in cybersecurity, risk management, or governance roles, with at least 5 or more years in a leadership capacity Strong experience managing GRC tools (e.g., ServiceNow) and implementing risk management workflows Deep understanding of information security frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, CIS Controls) Proven ability to manage complex risk and issue management processes across large organizations Expertise in developing and maintaining security policies, standards, and procedures Strong analytical skills with the ability to interpret risk data and generate actionable insights Exceptional communication and interpersonal skills, with the ability to convey complex information to technical and non-technical audiences Experience managing audit findings, policy exceptions, and change control processes Familiarity with regulatory requirements and reporting standards (e.g., GDPR, CCPA, HIPAA) medical, dental, and vision care backup dependent care adoption assistance infertility coverage family building support behavioral health solutions paid parental leave paid caregiver leave training programs professional development resources mentorship programs employee resource groups volunteer activities Copy Applicant Tracking System Keywords Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills cybersecurity risk management GRC tooling information security policies risk classification risk prioritization risk escalation audit management data analysis security standards
Soft skills leadership communication interpersonal skills analytical skills collaboration problem-solving team building stakeholder management reporting presentation skills
Certifications Bachelor’s degree in Cybersecurity Bachelor’s degree in Information Security Bachelor’s degree in Risk Management Bachelor’s degree in Business Administration Master’s degree in Cybersecurity Master’s degree in Information Security NIST CSF certification ISO 27001 certification SOC 2 certification CIS Controls certification