
Security Policy and Compliance Manager
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Illinois.
• Develop and implement security policies, procedures, and guidelines for information security measures.
• Review, revise, publish, and enhance Alight’s global security policies and standards.
• Identify security vulnerabilities and gaps in policies, standards, and procedures among employees, contractors, partnerships, and third parties.
• Align legal and regulatory requirements and updates with global policies and procedures.
• Conduct audit attestation activities and ensure timely delivery of work in accordance with organizational protocols.
• Analyze patterns of audit non-compliance to evaluate risk and promote better compliance practices.
• Oversee and address policy and audit discrepancies through remediation, tracking milestones, and escalating issues as needed.
• Guide internal subject matter experts in comprehending controls and necessary evidence.
• Collaborate cross-functionally and with external auditors to grasp processes comprehensively and communicate effectively.
• Relay test and audit findings and analyses to stakeholders and senior audit management.
• Utilize MS Excel and proprietary insurance enrollment and administration tools to assess, track, and report metrics.
• Design, implement, and enhance the security and risk management controls library, methodologies, and testing criteria.
• Remain updated on regulatory regulations and industry developments.
• Lead or engage in business-unit meetings concerning audit scope, testing advancements, and outcomes.
• Collaborate with senior management to comprehend business risks, changes, and events influencing the audit plan.
• Engage with regulators, external auditors, and risk management committees as part of ongoing monitoring and audit-plan management.
• Bachelor’s degree in Information Systems, Cybersecurity, or a related discipline, along with a minimum of 6 years of pertinent experience; additional relevant experience may be accepted in lieu of a degree.
• Certifications in Cybersecurity and/or Project Management are advantageous.
• Proficiency in technical, procedural, or policy documentation.
• Familiarity with audit frameworks such as NIST/ISO.
• Proven experience working within a geographically distributed team with global responsibilities.
• Experience in facilitating business process design concerning identity and access management.
• CISA certification is a plus.
• Strong collaboration abilities.
• Outstanding communication skills, including data gathering, active listening, dialogue, articulating ideas, negotiating difficult situations, and resolving conflicts.
• Ability to adapt and be flexible across functional areas or work independently.
• Availability to work evenings, weekends, and holidays as needed.
• Capability to manage and uphold the integrity and confidentiality of highly sensitive materials and information.
• Must reside in one of the 50 United States or the District of Columbia.
• Proof of U.S. citizenship is required upon hiring.
• Must possess work authorization that does not require visa sponsorship now or in the future in the United States.
• Successful completion of a background check in accordance with Alight’s employment policies.
• Virtual interviews are to be conducted via video.
• Health, dental, and vision insurance starting on Day One.
• Wellbeing programs.
• Retirement plans with contribution matching.
• Generous paid time off.
• Parental leave.
• Opportunities for continuing education.
• Career advancement potential.
• Flexible work arrangements.
• Occasional travel to physical office locations.
• Competitive total rewards package.
• Background checks and employment screenings as applicable.
• Reasonable accommodations for individuals with disabilities and sincerely held religious beliefs.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.