- Location
- USNC-Charlot15 (2476), United States of America
- Workplace
- Onsite
- Type
- Full-time
- Department
- Security
- Seniority
- Lead
- Experience
- 6+ years
- Education
- Bachelor
- Source
- Workday
Description
Accelerate your career at RXO
RXO is a leading provider of transportation solutions. With cutting-edge technology at the center, we're revolutionizing the industry with our massive network and commitment to finding solutions for every challenge. We create more efficient ways for shippers and carriers to transport goods across North America.
As a Lead Analyst, Information Security – Risk Governance you will be responsible for helping strengthen our security and risk management framework. In this role, you'll lead the administration and execution of our information security risk governance program, partnering with business and technology teams to identify, assess, monitor, and mitigate risks that could impact the organization. You'll play a key role in driving risk-informed decision making, enhancing governance processes, and ensuring security risks are managed in alignment with business objectives and regulatory expectations.
Work Location & Schedule: This position is based at RXO headquarters located at 11215 N Community House Road, Charlotte, NC 28277 and follows a 4 day onsite work schedule Monday through Thursday, and work from home on Fridays!
What your day-to-day will look like:
- Own and manage the end-to-end information security risk lifecycle, including risk identification, assessment, analysis, mitigation planning, acceptance, monitoring, and closure.
- Partner with business leaders, technology teams, security engineering, and operational stakeholders to identify and evaluate risks and ensure appropriate risk treatment plans are in place.
- Serve as the primary administrator and subject matter expert for AuditBoard, managing risk intake, issue tracking, risk reporting, and governance workflows.
- Maintain accurate and thorough documentation of risks, controls, mitigation activities, and exception processes to support audits, regulatory inquiries, and leadership reviews.
- Track remediation efforts and validate the effectiveness of corrective actions and risk treatment plans.
- Conduct and support periodic risk assessments and control reviews across key risk domains, including cloud security, identity and access management, third-party risk, artificial intelligence, and emerging threats.
- Develop dashboards, metrics, executive summaries, and governance reporting to communicate risk posture and trends to senior leadership.
- Translate complex technical risks into clear business impacts and recommendations for non-technical stakeholders.
- Drive continuous improvement initiatives related to risk governance processes, reporting, and technology platforms.
- Ensure alignment with internal policies, industry frameworks, and best practices, including NIST, ISO, COSO, and related standards.
- Mentor and provide guidance to junior team members while contributing to the overall maturity of the Governance, Risk, and Compliance (GRC) program.
What you'll need to excel:
At a minimum, you'll need:
- Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, Finance, or a related field, or equivalent combination of education and experience.
- 6+ years of experience in information security, risk management, governance, compliance, audit, or a related discipline.
- Experience managing and facilitating enterprise risk management processes and risk lifecycle activities.
- Strong analytical and problem-solving skills with the ability to assess and communicate risk effectively.
- Experience partnering with cross-functional stakeholders and influencing decisions in a matrixed environment.
- Ability to translate technical concepts into business-focused risk discussions and recommendations.
- Strong written, verbal, and presentation skills.
- Experience with Microsoft O365 applications.
It'd be great if you also have:
- Experience supporting or leading information security risk programs within a large, complex enterprise environment.
- Hands-on experience with AuditBoard or a comparable GRC platform.
- Knowledge of information security frameworks and standards, such as NIST, ISO 27001, COSO, or similar.
- Experience developing executive-level risk reporting, dashboards, and governance metrics.
- Familiarity with transportation, logistics, supply chain, or other highly regulated industries.
- Relevant certifications such as CRISC, CISA, CISSP, CGRC, or similar.
Does this sound like you? Check out what else RXO has to offer.
Why Join Us:
Our Benefits
Comprehensive medical, dental, and vision plans
401(k) retirement plan with up to 5% company match
Pre-tax accounts to help streamline eligible expenses
Company-paid disability and life insurance
Employee Assistance Program (EAP)
Career and Leadership Development Programs
Paid time off, company holidays, and volunteer days
Our Culture
Our values are the key to our unique culture and our ability to deliver for everyone we serve.
We do great things when we are inclusive and work together. To perform with excellence, we learn from one another, value diverse perspectives, operate safely and build strong relationships.
The Next Step
Ready to join our team? We'd love to hear from you. Fill out an application now and join our talent community to learn about future opportunities. We are proud to be an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. All applicants who receive a conditional offer of employment may be required to take and pass a pre-employment drug test. The above statements are not an exhaustive list of all required responsibilities, duties, and skills for this job classification. Review RXO's candidate privacy statement here and RXO's Privacy Notice to California Job Applicants here.