We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Manager, Information Security Governance, Risk, and Compliance

Steptoe LLP
401(k)
United States, D.C., Washington
1330 Connecticut Avenue Northwest (Show on map)
Aug 17, 2026
Position(s) I am Applying for
Manager, Information Security Governance, Risk, and Compliance

The Manager, Information Security Governance, Risk & Compliance (GRC) is responsible for leading the firm's information security governance, risk management and compliance program across all offices. Reporting to the Director of Information Security, the role ensures that the firm's security policies, controls, certifications and regulatory obligations support client expectations, business objectives and the firm's risk appetite.

This position works closely with the Office of General Counsel (OGC), IT leadership, business leadership, Risk Management, Procurement, HR and external assessors to maintain a mature, auditable and continuously improving information security program.

The successful candidate combines strong knowledge of security frameworks with practical experience in the legal or professional services sector and the ability to translate regulatory requirements into effective operational controls.

Essential Functions

Governance

  • Maintain and continuously improve the firm's Information Security Management System (ISMS).
  • Develop, review and maintain information security policies, standards, procedures and guidelines.
  • Manage the firm's security governance framework and policy lifecycle.
  • Coordinate governance committees with the Director such as the Information Security Management Committee.
  • Prepare executive reporting, dashboards and Leadership-level metrics on cyber risk and compliance.
  • Maintain the enterprise security risk register and oversee risk treatment plans.

Risk Management

  • Lead enterprise information security risk assessments.
  • Perform business impact and security risk analyses for new technologies and strategic initiatives.
  • Manage third-party technology risk assessments and vendor security reviews.
  • Partner with Procurement / Commercial Services and OGC during vendor due diligence and contract reviews.
  • Evaluate security risks associated with cloud services, SaaS providers and emerging technologies.
  • Track remediation activities and risk acceptance decisions.

Compliance

Lead and coordinate compliance with applicable security frameworks including:

  • ISO 27001
  • ISO 22301
  • Client security questionnaires
  • Outside counsel security assessments
  • Privacy and contractual security obligations
  • Emerging regulatory and client requirements such as CMMC, UK SRA cyber requirements and other regional obligations.

Responsibilities include:

  • Coordinating internal and external audits
  • Managing evidence collection
  • Monitoring corrective actions
  • Maintaining control documentation
  • Preparing certification renewals

Third-Party Security Management

Manage relationships with external security providers including:

  • ISO 27001 / ISO 22301 compliance consultants
  • Penetration testing providers
  • Security awareness training providers
  • Phishing simulation providers
  • Vendor risk assessment platforms

Monitor vendor performance, deliverables and continuous improvement activities.

Security Awareness

Own the firm's security awareness programme by:

  • Developing annual awareness plans
  • Managing phishing simulations
  • Delivering executive and employee security education
  • Tracking participation and effectiveness
  • Supporting secure behavior across all offices

Collaboration

Partner closely with:

  • Security Operations on incident response lessons learned
  • Security Engineering on implementation of required controls
  • Infrastructure and Cloud teams on compliance requirements
  • Office of General Counsel regarding legal, contractual and regulatory obligations
  • Internal Audit and external auditors

Continuous Improvement

  • Monitor changes in regulatory requirements and industry standards.
  • Recommend improvements to governance processes and security controls.
  • Support maturity assessments against recognized security frameworks.
  • Drive automation of governance and compliance activities where practical.

Non-Essential Functions

  • Other duties may be assigned, as necessary.

Minimum Qualification

Required

  • Bachelor's degree in Information Security, Computer Science, Information Systems or related discipline.
  • 7-10 years of experience in information security, with at least 4 years in governance, risk and compliance.
  • Experience supporting an ISO 27001 certified organization.
  • Experience conducting enterprise security risk assessments.
  • Experience managing external audits and client security assessments.
  • Strong understanding of security governance in a regulated professional services environment.
  • Excellent written, presentation and stakeholder management skills.

Preferred

  • Experience within an international law firm or other professional services organization.
  • Experience supporting global operations across North America, Europe and Asia.
  • Familiarity with legal industry client security requirements.
  • Experience with cloud security governance.
  • Experience supporting business continuity programmers.

Preferred Certifications

One or more of:

  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Implementer
  • ISO 27001 Lead Auditor
  • CGRC (formerly CAP)
  • CISA

Technologies and Platforms

Working knowledge of technologies including:

  • CrowdStrike Next-Gen SIEM
  • Microsoft 365 security ecosystem
  • Identity and Access Management
  • Endpoint security technologies
  • Vendor risk management platforms
  • Governance, Risk and Compliance (GRC) tools
  • Security awareness platforms
  • Vulnerability management reporting

External Relationships

Manage relationships with organizations such as:

  • Active Cyber (ISO 27001 / ISO 22301)
  • Mitratech (vendor and product risk assessment)
  • KnowBe4
  • Black Hills Information Security
  • Client security assessors
  • External auditors
  • Cyber insurance assessors

Key Competencies

  • Governance and policy development
  • Enterprise risk management
  • Regulatory compliance
  • Executive communication
  • Audit management
  • Vendor risk management
  • Relationship management
  • Analytical thinking
  • Business judgment
  • Project management
  • Continuous improvement
  • Influencing without direct authority

Success Factors

Within the first 12-24 months, success will be measured by:

  • Successful maintenance of ISO 27001 and ISO 22301 certifications.
  • Improved security governance maturity.
  • Timely completion of client security assessments.
  • Reduced remediation backlog for audit findings.
  • Effective enterprise security awareness programme with measurable reductions in phishing susceptibility.
  • Timely completion of third-party security reviews.
  • Executive reporting that clearly communicates cyber risk and compliance posture.
  • Readiness for emerging compliance obligations such as CMMC, UK SRA requirements and evolving client cybersecurity expectations.

Work Environment

  • Non-smoking environment
  • Ability to maintain a flexible work schedule
  • Available to work 9:00 - 5:30 pm Monday through Friday
  • Hybrid work arrangements may be available for this position
  • Must be available to work beyond regular hours when necessary
  • Must be able to work under tight deadlines
  • Must have ability to work independently

The anticipated base salary range for this position is $148,000 - $161,000. The actual base salary offered will be dependent upon the applicant's experience and qualifications, as well as other job-related factors, including but not limited to, relevant skills, education, certifications or other professional licenses held, and if applicable, geographic location.

Steptoe offers a full range of benefits for you and your eligible dependents. Benefits currently include: medical, dental, vision, life, disability, dependent care, health care flexible spending accounts, 401K Plan, Profit-Sharing, Paid Time-Off and a robust Wellness Program.

Steptoe LLP is an equal opportunity employer EOE/Disability/Veteran. All qualified applicants will receive consideration without regard to race, color, religion, gender, national origin, sexual orientation, gender identity and expression, marital status, mental or physical disability, genetic information, or any basis proscribed by applicable statutes.

Applied = 0

(web-77cf7d65c7-zggqq)