Hiring.Camp

Information Security GRC Manager

Signetjewelers

·

May 26, 2026

Location
Support Center - Akron, OH, United States of America
Workplace
Remote, Hybrid
Type
Full-time
Department
Security
Seniority
Manager
Experience
10+ years
Source
Workday

Description

We have many opportunities available on our other career site pages. Click here to link to our careers page!

Signet Jewelers is the world's largest retailer of diamond jewelry, operating more than 2,800 stores worldwide under the iconic brands: Kay Jewelers, Zales, Jared, H.Samuel, Ernest Jones, Peoples, Banter by Piercing Pagoda, Rocksbox, JamesAllen.com and Diamonds Direct. We are a people-first company and this core value is at the heart of everything we do, from empowering our valued team members, to collaborating with our customers, to fostering the communities in which we live and serve. People – and the love their actions inspire – are what drive us. We’re not only proud of the love we inspire outside our walls, we’re especially proud of the diversity, inclusion and equity we’re inspiring inside. There are dynamic career paths awaiting you – rewarding opportunities to impact the lives of others and inspire love. Join us!

Information Security GRC Manager 

Location: Dallas, TX or Akron, OH (Hybrid) Preferred

Open to remote

POSITION SUMMARY:

We are seeking an experienced Information Security GRC Manager to lead our governance, risk, and compliance (GRC) program. This role is critical in ensuring our information security practices align with regulatory requirements, industry standards, and business objectives.

As a key member of the security leadership team, you will drive enterprise risk management, oversee compliance initiatives, and provide clear, actionable insights on our security posture to senior leadership.

RESPONSIBILITIES:

Lead Governance & Security Programs

  • Develop and maintain the enterprise information security governance framework
  • Establish and lead cross-functional governance forums (e.g., compliance working groups, risk committees)
  • Oversee security policies, standards, procedures, and risk methodologies

Drive Risk Management

  • Lead enterprise-wide risk assessments, including identification, analysis, and mitigation of security risks
  • Define, track, and report on Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
  • Partner with stakeholders to support risk-based decision-making

Own Compliance & Certifications

  • Plan and execute compliance and readiness assessments (e.g., PCI-DSS, NIST CSF, ISO 27001)
  • Serve as the primary liaison for external auditors and assessors
  • Ensure ongoing adherence to regulatory and contractual requirements

Manage Audit & Assurance Activities

  • Coordinate internal and external audits, including SOX-related controls where applicable
  • Oversee remediation tracking and ensure timely resolution of findings
  • Continuously improve control effectiveness and assurance processes

Partner Across the Business

  • Collaborate with IT, Legal, Privacy, and business teams to embed security into operations
  • Translate complex security and compliance requirements into business-friendly language
  • Provide regular reporting on risk posture and compliance to senior leadership

Promote Security Awareness

  • Develop and deliver training and awareness programs related to risk and compliance
  • Foster a culture of security and accountability across the organization

POSITION QUALIFICATIONS:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Business, or related field (Master’s preferred)
  • 10+ years of experience in information security, IT risk, or compliance
  • 2–3+ years of hands-on experience in a GRC-focused role
  • Strong knowledge of frameworks and standards (e.g., NIST, ISO 27001, COBIT)
  • Experience managing audits and working with external regulators or assessors
  • Excellent communication skills, with the ability to engage both technical and business stakeholders
  • Strong project management skills and ability to manage multiple initiatives simultaneously

Nice to Have:

  • Relevant certifications (e.g., CISSP, CISM, CRISC, CISA)
  • Experience with SOX ITGC controls and audit coordination
  • Familiarity with third-party/vendor risk management programs
  • Experience with GRC tools (e.g., Optro (AuditBoard), ServiceNow GRC, OneTrust)

BENEFITS & PERKS:

  • Competitive healthcare, dental & vision insurance
  • 401(k) matching after one year of employment
  • Generous time off + company holidays
  • Merchandise discount
  • Learning & Development programs
  • Much more!

Skills

ServiceNowCybersecuritySOXRisk ManagementComplianceProject ManagementISO 27001CISSP

Similar Jobs

22

Lead, Information Security GRC Automation

Pru · Wash, 213 Washington St., Newark, NJ, United States of America · Remote, Hybrid, Onsite

4 days ago

CIT Information Security & GRC, Lead

Talentmanagementsolution · Markham, Ontario - CAN, Canada

6 days ago

Senior Engineer, Information Security GRC

Ice · Atlanta, GA, US

6 days ago

Senior Information Security GRC Specialist

Reconomy · Bucharest

1 week ago

I&T GRC Information Security Specialist

Dssmith · Krakow Global Business Services Center - IP (POL), Poland · Hybrid

3 months ago

Information Security GRC Analyst

Verisure · ES - Central Priégola - Pozuelo Headquarters, Spain · Hybrid

3 months ago

Information Security GRC Analyst

Verisure · ES - Central Priégola - Pozuelo Headquarters, Spain · Hybrid

3 months ago

Engineer, Information Security GRC

Ice · Atlanta, GA, US

3 months ago

TPDD Analyst, Information Security GRC

Ice · Jacksonville, FL, US

4 months ago

Information Security GRC Consultant

Bdobelgium · Zaventem, VBR, BE

10 months ago

Senior Information Security Manager (GRC)

Deepl · Munich +2

1 week ago

Grupo QuintoAndar | Information Security Manager - GRC

Grupo QuintoAndar · Brasil

1 week ago

Senior Information Security Analyst, GRC/Responsible AI

SanDisk · Irvine, CA, United States · Onsite

3 weeks ago

Senior GRC Analyst & Information Security Officer

Northlandpower · Warsaw Office, Poland · Remote, Onsite

1 month ago

Information Security Engineer - GRC

Global Ice · London, UK

1 month ago

Senior Information Security Analyst, GRC

Fieldnation · Dhaka · Hybrid

4 months ago

Information Security Engineer - GRC & Infosec

Bureau · Bangalore

8 months ago

Senior GRC Consultant (Cyber & Information Security)

Implement Consulting Group · Hellerup, Denmark

1 week ago

Information Security Analyst for GRC

Jci · Bratislava Business Center JCI, Slovakia · Onsite

4 months ago

Information Security Governance, Risk, Compliance (GRC) Supervisor

ARUP Laboratories · Salt Lake City, UT

2 months ago

Information Security Intern – Governance, Risk & Compliance (GRC)

Cc · LONDON BOND STREET HOUSE, United Kingdom

3 weeks ago

Information Security Analyst 5, Governance, Risk & Compliance (GRC)

SanDisk · Batu Kawan, Penang, Malaysia

1 month ago