> Markdown version of [/jobs/ext/2083278-information-security-grc-manager](https://www.wearedevelopers.com/jobs/ext/2083278-information-security-grc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security GRC Manager - **Company:** Signet Jewelers Limited - **Location:** Akron, OH, United States (Remote available) - **Experience:** Experienced - **Salary:** $45,000.0 - $71,550.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, PCI Data Security Standards, Smartsuite, IT General Controls (ITGC), Information Technology, Servicenow - **Published:** August 16, 2026 - **Apply:** https://www.careerjet.com/job/usda2c0cdd2eb08e1161c8f0a1e463844e/eaa ## About the Role * Bachelor's degree in Information Security, Cybersecurity, Computer Science, Business, or related field (Master's preferred) * 10+ years of experience in information security, IT risk, or compliance * 2-3+ years of hands-on experience in a GRC-focused role * Strong knowledge of frameworks and standards (e.g., NIST, ISO 27001, COBIT) * Experience managing audits and working with external regulators or assessors * Excellent communication skills, with the ability to engage both technical and business stakeholders * Strong project management skills and ability to manage multiple initiatives simultaneously Nice to Have: * Relevant certifications (e.g., CISSP, CISM, CRISC, CISA) * Experience with SOX ITGC controls and audit coordination * Familiarity with third-party/vendor risk management programs * Experience with GRC tools (e.g., Optro (AuditBoard), ServiceNow GRC, OneTrust) ## Description We are seeking an experienced Information Security GRC Manager to lead our governance, risk, and compliance (GRC) program. This role is critical in ensuring our information security practices align with regulatory requirements, industry standards, and business objectives. As a key member of the security leadership team, you will drive enterprise risk management, oversee compliance initiatives, and provide clear, actionable insights on our security posture to senior leadership. RESPONSIBILITIES: Lead Governance & Security Programs * Develop and maintain the enterprise information security governance framework * Establish and lead cross-functional governance forums (e.g., compliance working groups, risk committees) * Oversee security policies, standards, procedures, and risk methodologies Drive Risk Management * Lead enterprise-wide risk assessments, including identification, analysis, and mitigation of security risks * Define, track, and report on Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) * Partner with stakeholders to support risk-based decision-making Own Compliance & Certifications * Plan and execute compliance and readiness assessments (e.g., PCI-DSS, NIST CSF, ISO 27001) * Serve as the primary liaison for external auditors and assessors * Ensure ongoing adherence to regulatory and contractual requirements Manage Audit & Assurance Activities * Coordinate internal and external audits, including SOX-related controls where applicable * Oversee remediation tracking and ensure timely resolution of findings * Continuously improve control effectiveness and assurance processes Partner Across the Business * Collaborate with IT, Legal, Privacy, and business teams to embed security into operations * Translate complex security and compliance requirements into business-friendly language * Provide regular reporting on risk posture and compliance to senior leadership Promote Security Awareness * Develop and deliver training and awareness programs related to risk and compliance * Foster a culture of security and accountability across the organization, Job Description Supervises customer service associates and designated hitters. Responsible for managing front end of the store and making recommendations on the overall operation… + 4 days ago + ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why SmartGit Is More Than a Git Client](https://www.wearedevelopers.com/magazine/689-why-smartgit-is-more-than-a-git-client) - [Best Companies to Work For in The UK: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/186-best-companies-to-work-for-in-the-uk-top-25-companies-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)