What are the responsibilities and job description for the Cybersecurity Risk & Compliance Manager position at Shtudy Careers?
Job Title: Cybersecurity Risk & Compliance Manager
Location: Remote (USA)
Job Type: Full-Time
Department: Information Security / GRC (Governance, Risk, and Compliance)
A top leading U.S based company is hiring an experienced and motivated Cybersecurity Risk & Compliance Manager to join the growing Information Security team. This fully remote role is responsible for developing, implementing, and maintaining our organization’s cybersecurity risk management and compliance programs. You will play a key role in ensuring that our security practices align with regulatory requirements, industry standards, and internal policies.
This position offers the flexibility of remote work and the opportunity to shape the risk and compliance landscape of a dynamic and fast-paced organization.
Risk Management
Lead the development and execution of the enterprise cybersecurity risk management framework.
Conduct regular risk assessments, threat modelling, and risk treatment planning across systems, processes, and vendors.
Identify, assess, and communicate risks to executive leadership and stakeholders with actionable recommendations.
Track and manage risk remediation efforts and risk register updates.
Compliance & Audit
Ensure compliance with relevant regulatory and industry frameworks such as NIST CSF, ISO 27001, SOC 2, PCI-DSS, HIPAA, GDPR, CCPA, and others as applicable.
Manage internal and external audits, including evidence collection, coordination with control owners, and auditor interactions.
Maintain and continuously improve cybersecurity policies, procedures, and standards.
Monitor changes in laws and regulations to ensure ongoing compliance.
Governance
Support the development and maintenance of GRC tools and platforms for managing risk, compliance, and audit activities.
Develop metrics and dashboards for reporting on cybersecurity risk and compliance posture.
Promote awareness and understanding of risk and compliance requirements across departments.
Third-Party Risk Management
Lead the vendor risk management process including security due diligence, risk assessments, and ongoing monitoring.
Review and assess third-party contracts and security documentation.
Requirements
Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field. A Master’s degree is a plus.
5 years of experience in cybersecurity, with at least 3 years in risk management and compliance roles.
Strong knowledge of regulatory frameworks and standards (e.g., NIST, ISO, SOC 2, PCI-DSS, HIPAA).
Experience with GRC platforms (e.g., ServiceNow, Archer, LogicGate, OneTrust).
Familiarity with cloud environments (e.g., AWS, Azure, GCP) and associated security and compliance requirements.
Strong analytical, organizational, and communication skills.
Ability to work independently and manage multiple priorities in a remote setting.
Benefits
100% remote work flexibility within the USA
Competitive salary and performance bonuses
Comprehensive health, dental, and vision insurance
401(k) with company match
Generous PTO, paid holidays, and parental leave
Professional development opportunities and certification reimbursement
A collaborative and innovative work culture
Equality Statement:
We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.