Security Policy and Compliance Manager - Virtual

AlightDeerfield, IL
$105,000 - $120,000Remote

About The Position

As a member of Alight Global Security’s Security & Compliance team, this position is responsible for the required updates, reviews, creation, and maturity of Alight’s security policies program. This role will be a subject matter expert for security policy helping inform colleagues and teams on required actions for Alight to remain in compliance with our policy and helping to track and manage any witnessed nonconformities. Additionally, this position will help manage audits and their applicable controls. That will include coaching colleagues on what they need to do to meet and demonstrate each control for an audit and help speak to and present collected evidence with various external auditors.

Requirements

  • Bachelor’s degree in Information Systems, Cybersecurity, or a related field and minimum 6 years of relevant experience. Additional years of relevant experience will be considered in lieu of a degree.
  • Experience with technical, procedural, or policy writing
  • Experience in audit frameworks (ie NIST/ISO)

Nice To Haves

  • Certifications in line with Cybersecurity and/or Project Management a plus
  • Demonstrated experience in working in a geographically dispersed team with global scope and responsibilities
  • Experience facilitating business process design as it relates to managing identities and access privileges
  • CISA certifications beneficial
  • Excellent collaboration skills – must be eager to work as part of a cohesive team and work as a partner to other teams within Alight., locally and globally
  • Exceptional communication skills, including the ability to gather relevant data and information, actively listen, dialogue freely, verbalize ideas effectively, negotiate tense situations successfully, and manage and resolve conflict
  • Adaptability, flexibility, and ability to work as part of a team across functional boundaries or in an individual capacity
  • Willingness to work outside of regular business hours as required which can include evenings, weekends, and holidays.
  • Ability to handle and maintain the integrity and confidentiality of highly sensitive material and information

Responsibilities

  • Help establish security policies, procedures, and guidelines on various information security controls
  • Partner with the global security teams to review, update, publish Alight’s global security polices and standards to continuously improve and mature Alight’s global security policy program
  • Identify security issues and gaps with security policies, standards, and procedures among employees, contractors, alliances, and other third parties.
  • Map legal and regulatory requirements and developments onto global policies/procedures and make suggestions where needed
  • Perform all audit attestation activities relating to aligned audits ensuring work and deliverables in accordance with agreed upon timeframes and organizational procedures, standards, and protocols
  • Interpret patterns of non-compliance discovered through audit to determine impact on levels of risk and work with the appropriate resources to drive higher levels of compliance.
  • Owns and manages any gaps coming from the policy or audit process through remediation with stakeholders reporting milestones and escalate when necessary
  • Work with internal subject matter experts to lead them in understanding the controls and required evidences
  • Partners cross-functionally, inter-departmentally and with the external auditor to understand the process from an end-to-end perspective and appropriately and effectively communicates with these partners
  • Works as part of a team and exhibits strong interpersonal and team skills
  • Ensures frequent communication of test and/or audit results and analysis on a timely basis to the appropriate stakeholders and senior management within the audit department
  • Through the advanced use of technology (i.e. MS Excel, Corporation’s Proprietary Insurance Enrollment & Administration System.) concisely measure, monitor and report metrics to senior management of the audit department and prepare snapshots of information in a synthesized and polished manner
  • Design, implement & mature security and risk management controls library, controls methodology & testing criteria;
  • Responsible for staying current on regulatory rules and changes within the industry
  • Leads and/or actively participates in meetings with business unit to discuss test and/or audit scoping, testing progress and results
  • Interacts and partners with senior management to understand the risks within the business, business changes and other significant events that could significantly impact the business and/or the audit plan
  • Communicates with regulators, external auditors, and various risk management committees within the Corporation as part of ongoing continuous monitoring which assists in managing the audit plan

Benefits

  • health, dental and vision coverages starting Day One
  • wellbeing programs
  • retirement plans with contribution matching
  • generous time off
  • parental leave
  • continuing education
  • career growth opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service