Senior Manager of Risk and Compliance
ptr globalEl Paso (TX)
About the role
Senior Manager of Risk and Compliance
Job Summary:
This position is a hands-on leader responsible for the execution and operational delivery ofsecurity compliance, risk management, and audit functions. This positionoversees a team of compliance analysts and works cross-functionally with stakeholders toensure security controls and compliance objectives are met. They areresponsible for managing day-to-day security risk activities, responding to client audit andassessment requests, overseeing third-party vendor reviews, and leading internalassessments and risk treatment tracking. The ideal candidate combines deep operationalknowledge with the ability to mentor and guide a growing team.
Essential Duties and Responsibilities:
- Designs and leads the information security risk assessment strategy, methodology, and process.
- Coordinates the execution of enterprise-wide information security riskassessments, including the reporting and oversight of risk treatment plans toaddress findings.
- Perform internal control reviews, gap assessments, and documentation ofcompliance with applicable security and privacy regulations (e.g. HIPAA, SOC 2, NIST, ISO 27001)
- Manage risk and compliance resources for team execution.
- Oversee the development and maintenance of security policies, standards, andprocedures aligned with leading frameworks.
- Support contract and vendor reviews by assessing third-party risk and advising onrisk acceptance / treatment in conjunction with Vendor managementprocesses.
- Deliver regular reporting on metrics, KPI’s, risk posture, exceptions, remediation andaudit status to appropriate parties.
- Provide approved responses to client inquiries and maintain library of records, documentation, and responses.
- Ensure key security controls are identified, implemented, tested, and remediated asrequired.
- Evaluate and advise on security control recommendations to mitigate informationsecurity risks.
- Evaluate and advise on implementation and eWectiveness of security controls forcompliance with applicable information security laws, regulations, and policies.
- Work with business partners, global risk management, IT risk, product and datasecurity, and outside consultants on required information security risk assessmentsand audits.
- Respond to security assessments, questionnaires and audits from regulators, clients and third-party business partners.
- Work directly with clients to provide advisory services and guidance that will reduceorganizational risk, improve their overall security posture, and achieve compliance.
- Prepare reports and other deliverables that contain strategy, technical analysis, findings, and recommendations.
- Other duties as assigned. Supervisory Responsibility This position manages employees and is responsible for the performance managementand hiring of the employees. Education Minimum/Preferred Education Description Minimum 4 Year / Bachelors Degree Information Security, Information Systems or related FieldMinimum Certification CISAPreferred Certification CISSP, CRISC, CISM, or other equivalents ExperienceMinimum Years of Experience Description 5+ years management In Information Security with combinations in operational security, risk management, IT, Compliance and Audit 5+ years Specific to security risk management and compliance programs, process, andexecution Knowledge, Skills, and Abilities
- Ability to write solution workflow diagrams, system documentation, playbooks, etc.
- Strong analytical skills
- Excellent written and verbal communications skills, including presentational skills
- Understanding of or experience with industry and regulatory standards, includingNIST 800-53, HIPAA Security Rule, ISO 2700x, AICPA SOC 2, PCI DSS, GDPR, CCPA
- Prior experience auditing and performing quality control actions of audits.
- Hands-on experience with GRC platforms and work management tools (e.g. Jira, Confluence)
- Demonstrated experience in curating cyber security strategies and programs forlarge and complex organizations
- Proven ability to operate independently, manage multiple priorities, and driveresults in a deadline-driven environment.
- Proven track record in defining, developing, and implementing cyber riskmanagement structures, governance models, organizational transformations in theareas of cyber security
- Strong domain expertise and understanding of five or more of following areas:
- Cyber risk program management and delivery
- Security architecture
- Security technologies (e.g., firewalls, security event monitoring, intrusion detectionand prevention, malware detection)
- Data protection (application security/SDLC)
- Third party risk management
- Cloud security
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
