$90K - 130K a year
Lead and execute the enterprise security GRC program including policy enforcement, risk management, compliance assessments, training, and vendor risk oversight.
7+ years in information security or governance with 4+ years leadership, strong knowledge of ISO 27001, NIST, SOC 2, CISSP/CISM/CISA certification preferred, and experience managing client assessments and GRC tools.
Manager – Security GRC LaSalle Network is hiring a Manager – Security GRC, a pivotal leadership role responsible for advancing cybersecurity governance, risk, and compliance across the enterprise. This is a high-impact opportunity for a strategic yet hands-on leader to define program direction, strengthen accountability, and drive measurable results in security resilience. As GRC Manager, you will oversee security policies, risk registers, vendor risk management, awareness training, and regulatory compliance initiatives, while also leading a talented team and collaborating across business units. Manager – Security GRC Responsibilities: - Define and execute the GRC strategy and roadmap, reporting program performance to leadership - Develop, maintain, and enforce security policies, standards, and exception management processes - Lead awareness and training programs, including phishing simulations and metrics tracking - Manage SOC 2, ISO 27001, and client assessments; oversee third-party vendor risk reviews - Maintain risk registers, lead internal control testing, and track remediation - Monitor regulatory changes, advising business leaders on compliance and security risk impacts - Act as a trusted advisor for both internal stakeholders and client-facing assessments Manager – Security GRC Requirements: - Bachelor’s degree preferred; CISSP, CISM, or CISA strongly preferred - 7+ years of experience in information security or governance, with 4+ years in leadership roles - Strong knowledge of frameworks such as ISO 27001, NIST, SOC 2, and related standards - Demonstrated success leading GRC programs, compliance assessments, and technical control testing - Strong written and verbal communication skills to simplify complex concepts for varied audiences - Familiarity with GRC platforms, IAM, SIEM, encryption, vulnerability management, and BI tools (Power BI, Tableau) - Skilled in managing client assessments with confidence and professionalism This is a rare opportunity to shape a mission-critical security function while building a culture of accountability, awareness, and excellence. Apply today to take the lead in securing the organization’s future. Andrew Gaeth Sr. Unit Manager LaSalle Network
This job posting was last updated on 10/23/2025