Risk and Compliance Manager

State of IllinoisSpringfield, IL
$8,334 - $12,917Onsite

About The Position

Reporting to the Chief Information Security Officer (CISO), the Risk & Compliance Manager is responsible for designing, implementing, and leading a modern enterprise cybersecurity Governance, Risk, Compliance (GRC) program. This role ensures continuous improvements of governance, risk, and compliance capabilities, and that cybersecurity risk is identified, measured, clearly understood, and managed in alignment with adopted frameworks, agency priorities, regulatory requirements, and overall technology strategy. The manager will continuously monitor the cybersecurity risk posture, perform gap analysis, and provide recommendations for compensating technical, administrative, and physical controls. They will track the agency's alignment to information security standards, collaborate with agency stakeholders to develop prescriptive guidance to reduce risk, and review policies, standards, procedures, controls documentation, and audit results. Additionally, this role manages third-party risk by maintaining an inventory of all technology providers and service organizations, performing continuous security posture monitoring, and overseeing the agency's security awareness program.

Requirements

  • Bachelor’s degree in a Cybersecurity or Information Technology field
  • A minimum of 10 years in Information Technology roles including 5 years of combined professional experience in information security and risk management.
  • Advanced knowledge in information security technologies, design, and architecture in on-premises and cloud hosted environments.
  • Experience with the selection, implementation, and management of third-party GRC, exposure management, and awareness platforms such as Bitsight, Knowbe4, ServiceNow, Netwrix, Qualys, and Tenable.
  • Solid understanding of cyber risk management, strategy, and security frameworks such as: NIST, CIS, OWASP, COSO, ISO, FAIR, etc.
  • Must have excellent analytical and planning skills and be highly organized and detail oriented.
  • Possesses the ability to write and communicate effectively with both technical and non-technical audiences.
  • Comfortability presenting to executive leadership.
  • Ability to take unpopular positions when necessary to ensure risk is fully and accurately communicated to agency leadership.
  • ISACA Certified in Risk and Information Systems Control (CRISC)
  • ISC2 Certified Information Systems Security Professional (CISSP)
  • ISC2 Certified Cloud Security Professional (CCSP)

Nice To Haves

  • EC Council Certified Ethical Hacker (CEH)
  • CompTIA Project+
  • CompTIA Cloud+
  • ISC2 Certified in Governance, Risk and Compliance (CGRC)
  • CompTIA Network+
  • COBIT: Control Objectives for Information and Related Technology
  • ITIL: Information Technology Infrastructure Library

Responsibilities

  • Develops and implements risk management plans and processes that are aligned to business objectives and security requirements.
  • Collaborates with agency stakeholders and control owners to develop and implement testing and evidence gathering methodologies.
  • Analyzes and interprets audit results and provides recommendations to system owners and senior leadership to reduce risk.
  • Serves as risk management subject matter expert in support of agency projects.
  • Leverages GRC, vulnerability management, and service desk tools to track progress and distribute compliance and risk remediation task assignments.
  • Conducts third-party service organization risk assessments to ensure supply chain risk is managed throughout the business relationship lifecycle.
  • Establishes and maintains relationships with third-party vendors.
  • Continuously monitors third-party risk by periodically gathering and analyzing vendor documentation such as System and Organization Controls (SOC2 Type II), International Organization for Standardization (ISO 27001), technical diagrams, penetration test results, continuity plans, etc.
  • Reports on the benefits and risks for the agency as well as requirements for service provider compliance.
  • Creates, maintains, and distributes third-party vendor security questionnaires.
  • Serves as the agency's liaison to ensure successful external third-party risk and vulnerability assessments.
  • Communicates assessment results to leadership, business stakeholders, and program managers.
  • Documents Corrective Action Plans (CAP) as needed and assists with the creation of agency Plan of Action & Milestones (POA&M).
  • Assists with the research, creation, maintenance, implementation and communication of Information Security policies, standards, controls, and procedures documentation.
  • Evaluates and documents technical, administrative, and physical controls to ensure the agency demonstrates compliance and meets the requirements of its regulatory obligations.
  • Leads efforts to remediate control gaps and presents findings to leadership.
  • Facilitates data collection and eDiscovery efforts to support investigations of policy violations.
  • Collaborates with the Information Security Operations team and other agency stakeholders to analyze security incidents and provide recommendations to reduce risk.
  • Establishes and maintains a detailed risk register for the organization.
  • Oversee organization-wide Business Impact Analysis (BIA) processes.
  • Collaborate with agency stakeholders to establish and maintain Continuity of Operations Planning (COOP) and Disaster Recovery Planning (DRP).
  • Develops and matures the agency's security awareness program.
  • Utilizes a combination of third-party education resources and services, threat intelligence, and industry trends to create and distribute annual and supplemental security awareness trainings.
  • Periodically provides agency staff with additional education opportunities such as presentations or workshops that are focused on information security, risk, and compliance.
  • Continues education by attending training, seminars, conferences, and obtaining industry certifications.
  • Maintains a current understanding of the threat landscape by monitoring online information security related websites, blogs, articles, reports, as well as other security intelligence sources to remain current on the latest threats, indicators of compromise (IOCs) and trends.
  • Participates in cybersecurity focused organizations.
  • Performs other duties as required or assigned which are reasonably within the scope of the duties enumerated above.
  • Provides off-hours support as required.

Benefits

  • Competitive Group Insurance benefits including health, life, dental and vision plans
  • Flexible work schedules (when available and dependent upon position)
  • 10 -25 days of paid vacation time annually (10 days for first year of state employment)
  • 12 days of paid sick time annually which carryover year to year
  • 3 paid personal business days per year
  • 13 paid holidays per year
  • 12 weeks of paid parental leave
  • Pension plan through the State Employees Retirement System
  • Deferred Compensation Program – voluntary supplemental retirement plan
  • Optional pre-tax programs -Medical Care Assistance Plan (MCAP) & Dependent Care Assistant Plan (DCAP)
  • Tuition Reimbursement Program and Federal Public Service Loan Forgiveness Program eligibility
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service