Manager, Information Security Governance, Risk, and Compliance

Steptoe LLP
Washington, DC, United States
18 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$148,000.0 - $161,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Software as a Service Cloud Computing Cloud Computing Security Cyber Security Information Systems Identity and Access Management Information Security Management IT Management Cloud Services Phishing
+4 more
Security Information and Event Management Software Vulnerability Management Information Security Management System Information Technology

Job description

Manager, Information Security Governance, Risk, and Compliance

The Manager, Information Security Governance, Risk & Compliance (GRC) is responsible for leading the firm’s information security governance, risk management and compliance program across all offices. Reporting to the Director of Information Security, the role ensures that the firm’s security policies, controls, certifications and regulatory obligations support client expectations, business objectives and the firm’s risk appetite.

This position works closely with the Office of General Counsel (OGC), IT leadership, business leadership, Risk Management, Procurement, HR and external assessors to maintain a mature, auditable and continuously improving information security program.

The successful candidate combines strong knowledge of security frameworks with practical experience in the legal or professional services sector and the ability to translate regulatory requirements into effective operational controls.

Essential Functions

Governance

  • Maintain and continuously improve the firm’s Information Security Management System (ISMS).
  • Develop, review and maintain information security policies, standards, procedures and guidelines.
  • Manage the firm’s security governance framework and policy lifecycle.
  • Coordinate governance committees with the Director such as the Information Security Management Committee.
  • Prepare executive reporting, dashboards and Leadership-level metrics on cyber risk and compliance.
  • Maintain the enterprise security risk register and oversee risk treatment plans.

Risk Management

  • Lead enterprise information security risk assessments.
  • Perform business impact and security risk analyses for new technologies and strategic initiatives.
  • Manage third-party technology risk assessments and vendor security reviews.
  • Partner with Procurement / Commercial Services and OGC during vendor due diligence and contract reviews.
  • Evaluate security risks associated with cloud services, SaaS providers and emerging technologies.
  • Track remediation activities and risk acceptance decisions.

Compliance

Lead and coordinate compliance with applicable security frameworks including:

  • ISO 27001
  • ISO 22301
  • Client security questionnaires
  • Outside counsel security assessments
  • Privacy and contractual security obligations
  • Emerging regulatory and client requirements such as CMMC, UK SRA cyber requirements and other regional obligations.

Responsibilities include:

  • Coordinating internal and external audits
  • Managing evidence collection
  • Monitoring corrective actions
  • Maintaining control documentation
  • Preparing certification renewals

Third-Party Security Management

Manage relationships with external security providers including:

  • ISO 27001 / ISO 22301 compliance consultants
  • Penetration testing providers
  • Security awareness training providers
  • Phishing simulation providers
  • Vendor risk assessment platforms

Monitor vendor performance, deliverables and continuous improvement activities.

Security Awareness

Own the firm’s security awareness programme by:

  • Developing annual awareness plans
  • Managing phishing simulations
  • Delivering executive and employee security education
  • Tracking participation and effectiveness
  • Supporting secure behavior across all offices

Collaboration

Partner closely with:

  • Security Operations on incident response lessons learned
  • Security Engineering on implementation of required controls
  • Infrastructure and Cloud teams on compliance requirements
  • Office of General Counsel regarding legal, contractual and regulatory obligations
  • Internal Audit and external auditors

Continuous Improvement

  • Monitor changes in regulatory requirements and industry standards.
  • Recommend improvements to governance processes and security controls.
  • Support maturity assessments against recognized security frameworks.
  • Drive automation of governance and compliance activities where practical.

Non-Essential Functions

  • Other duties may be assigned, as necessary., * Mitratech (vendor and product risk assessment)
  • KnowBe4
  • Black Hills Information Security
  • Client security assessors
  • External auditors
  • Cyber insurance assessors

Key Competencies

  • Governance and policy development
  • Enterprise risk management
  • Regulatory compliance
  • Executive communication
  • Audit management
  • Vendor risk management
  • Relationship management
  • Analytical thinking
  • Business judgment
  • Project management
  • Continuous improvement
  • Influencing without direct authority

Success Factors

Within the first 12-24 months, success will be measured by:

  • Successful maintenance of ISO 27001 and ISO 22301 certifications.
  • Improved security governance maturity.
  • Timely completion of client security assessments.
  • Reduced remediation backlog for audit findings.
  • Effective enterprise security awareness programme with measurable reductions in phishing susceptibility.
  • Timely completion of third-party security reviews.
  • Executive reporting that clearly communicates cyber risk and compliance posture.
  • Readiness for emerging compliance obligations such as CMMC, UK SRA requirements and evolving client cybersecurity expectations.

Work Environment

  • Non-smoking environment
  • Ability to maintain a flexible work schedule
  • Available to work 9:00 - 5:30 pm Monday through Friday
  • Hybrid work arrangements may be available for this position
  • Must be available to work beyond regular hours when necessary
  • Must be able to work under tight deadlines
  • Must have ability to work independently

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Systems or related discipline.
  • 7-10 years of experience in information security, with at least 4 years in governance, risk and compliance.
  • Experience supporting an ISO 27001 certified organization.
  • Experience conducting enterprise security risk assessments.
  • Experience managing external audits and client security assessments.
  • Strong understanding of security governance in a regulated professional services environment.
  • Excellent written, presentation and stakeholder management skills.

Preferred

  • Experience within an international law firm or other professional services organization.
  • Experience supporting global operations across North America, Europe and Asia.
  • Familiarity with legal industry client security requirements.
  • Experience with cloud security governance.
  • Experience supporting business continuity programmers.

Preferred Certifications

One or more of:

  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • CGRC (formerly CAP)
  • CISA

Technologies and Platforms

Working knowledge of technologies including:

  • CrowdStrike Next-Gen SIEM
  • Microsoft 365 security ecosystem
  • Identity and Access Management
  • Endpoint security technologies
  • Vendor risk management platforms
  • Governance, Risk and Compliance (GRC) tools
  • Security awareness platforms
  • Vulnerability management reporting

Benefits & conditions

The anticipated base salary range for this position is $148,000 - $161,000. The actual base salary offered will be dependent upon the applicant’s experience and qualifications, as well as other job-related factors, including but not limited to, relevant skills, education, certifications or other professional licenses held, and if applicable, geographic location.

Steptoe offers a full range of benefits for you and your eligible dependents. Benefits currently include: medical, dental, vision, life, disability, dependent care, health care flexible spending accounts, 401K Plan, Profit-Sharing, Paid Time-Off and a robust Wellness Program.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all