Senior Security Engineer II

RELX Group plc
Raleigh, NC, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Software as a Service Cloud Engineering Cyber Security Information Systems Systems Integration Information Technology Data Analytics

Job description

We are seeking a Senior Security Engineer to design and implement a scalable Governance, Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on standardizing controls, improving ownership visibility, and enabling automated evidence collection to support continuous compliance across SOC 2, ISO 27001, Cyber Essentials, and related frameworks. This is a transformation-focused role. The successful candidate will partner with compliance, security, and engineering teams to move the organization from a manual, audit-driven model to a structured, automation-enabled GRC program.

Responsibilities

GRC Platform Implementation & Automation

  • Lead implementation and administration of a GRC platform (e.g., Vanta)

  • Configure controls, evidence mapping, and integrations (AWS, identity systems, etc.)

  • Establish automated evidence collection and continuous monitoring

  • Reduce reliance on manual evidence gathering

Control Framework Development

  • Develop and maintain a unified control framework aligned to SOC 2, ISO 27001, and other standards

  • Define control statements, evidence requirements, and testing expectations

  • Map controls across frameworks to reduce duplication

  • Maintain traceability between controls and evidence

Ownership & System Mapping

  • Establish team-based ownership model for controls

  • Align systems and services to responsible teams

  • Maintain lightweight system inventory

  • Improve ownership visibility to reduce audit coordination overhead

Audit Enablement

  • Support audit readiness through well-defined and monitored controls

  • Partner with compliance team to streamline audits

  • Enable evidence reuse across frameworks

Process Standardization & Continuous Improvement

  • Standardized documentation and workflows

  • Improve efficiency and reduce audit fatigue

  • Support policy and standards development

  • Define and track compliance metrics, leveraging automation and data analytics to support continuous audit readiness and control effectiveness

  • All other duties as assigned

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Information Systems, or a related technical field, or equivalent practical experience

  • 5+ years of experience in security, compliance, or audit-focused roles

  • Proven experience leading ISO/IEC 27001 and SOC 2 audits end-to-end

  • Hands-on experience with a GRC platform (AuditBoard, Drata, Vanta, or similar) - required

  • Strong understanding and experience with control frameworks

  • Ability to translate technical implementations into audit-ready controls and documentation

  • Strong stakeholder management and auditor-facing communication skills

  • Experience in cloud-native or SaaS environments (AWS, Azure, or GCP preferred)

Preferred Qualifications

  • Experience with automation and continuous compliance

  • Certifications such as CISSP, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor

  • Multi-framework experience

  • Experience scaling compliance programs in high-growth environments

About the company

LexisNexis, a part of RELX, is a leading global provider of legal, regulatory, and business information. We help customers increase productivity and improve decision-making and outcomes. Our 10,500 experts and innovative tools help us shape a better world for our customers and communities., LexisNexis Legal & Professional is proud to be an equal-opportunity employer. We are committed to equal opportunity employment regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Together, we are building a diverse and inclusive workplace.

Working for you

We believe in a healthy work/life balance. We know that your well-being and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer:

  • Comprehensive, multi-carrier health plan benefits - Disability insurance - Dependent care and commuter spending accounts - Life and accident insurance - Retirement benefits (salary investment plan/employer stock purchase plan) - Modern family benefits, including adoption and surrogacy

About our Team

LexisNexis is a data and analytics company with 10,500 colleagues serving customers in more than 150 countries. We’re one of the largest information and analytics companies on the planet. We design solutions that help our customers increase productivity, improve decision-making and outcomes, and be more successful., RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.

Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.

Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all