
Risk & Controls Manager
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Manage the risk register derived from the Security Programme threat model, which includes tracking treatment, making acceptance decisions, following up with owners, and maintaining the exceptions register.
• Ensure the ISMS and security policy library is up-to-date and draft security standards when requested.
• Utilize Drata as the control and evidence management system, covering the Statement of Applicability, framework crosswalk, and automation processes.
• Conduct critical control monitoring, perform health check-ins, manage drift flags, and oversee Drata automation.
• Keep evidence ready for Lead assessments and independent internal audits.
• Incorporate findings from threat assessments into the register and assign confidence ratings.
• Lead the coordination and preparation for ISO 27001 and SOC 2 audits, which includes ensuring ISMS readiness, preparing the team, compiling management review materials, and completing customer due diligence questionnaires.
• Organize the control register for red-team activities, tabletop exercises, and penetration testing.
• Implement security awareness initiatives and send weekly alerts.
• Monitor residual risks, exceptions, and the closure of gaps in relation to risk appetite.
• Report on the state of the register and the health of evidence to the Lead and Risk Committee.
• Maintain an up-to-date, defensible posture engine and ensure continuous evidence collection through Drata.
• Practical experience in managing a risk register, control library, and audit cycle (ISO 27001 and/or SOC 2).
• Familiarity with GRC platforms (such as Drata or similar) and the ability to convert monitoring into tangible evidence.
• Demonstrated capability to coordinate audits and customer questionnaires alongside designated control owners.
• Excellent writing skills; the quality of the register and Statement of Applicability is crucial.
• Strong stakeholder engagement skills with control owners and auditors.
• Hold a CISA, ISO 27001 Lead Implementer or Auditor certification, or an equivalent professional qualification.
• Candidates may need to undergo checks related to employment, education, criminal records, and other background and identity verifications.
• Applications from candidates residing in France, Italy, or Germany will not be accepted.
• Commitment to equal opportunity employment.
• Background and identity verification checks are mandatory as a condition of employment.
• A remote-friendly, remote-first work environment.
Horizon Connect @ Wall BCBSNJ
Experian
Ignition
Experian
Get handpicked remote jobs straight to your inbox weekly.