This role is not open to visa sponsorship or transfer of visa sponsorship including those on OPT and STEM-EXT OPT, nor is it available to work corp-to-corp.

As a Security GRC Manager, you will be a hands-on people leader responsible for our security governance, risk, and compliance programs in a technology-driven organization. Partnering with our technology, business and legal teams, you will play a key role in influencing the organization’s cybersecurity posture through assessing and driving remediation of security risks and ensuring compliance with relevant frameworks and contracts.  Your technical expertise of security frameworks and understanding of cloud infrastructure will be crucial in ensuring Red Ventures’ security posture aligns with industry best practices. This role offers the opportunity to make strategic decisions, provide valuable recommendations, and collaborate with a broad group of bright and energetic individuals throughout the company. This position will report to our Fort Mill, SC campus three days per week.

What You'll Do:

  • Lead and manage all aspects of applicable cybersecurity audits, such as scope definition/validation, audit readiness, walkthroughs, evidence collection, and liaising with external auditors
  • Drive adoption of relevant security compliance requirements through thorough analysis and prescriptive guidance
  • Define and lead security risk management process, leveraging automation and partnering with stakeholders to perform hands-on risk assessments
  • Oversee the policies and standards lifecycle process to ensure they address all relevant cybersecurity requirements
  • Define and lead cybersecurity awareness programs including annual training, topical awareness campaigns in partnership with corporate communications, and phishing simulations
  • Proactively identify compliance gaps through continuous monitoring, working closely with control owners to identify ways to effectively monitor compliance posture through automation
  • Document and report identified security or compliance issues and work with control owners on remediation requirements, strategy, and execution, providing recommendations that can be reasonably adopted
  • Regularly monitor remediation activities for noted findings, and escalate on remediation plans that are at-risk of being overdue
  • Develop and maintain security reporting to provide real-time and on-demand compliance status
  • Maintain an up-to-date understanding of emerging trends in information security risks; apply new techniques and trends, in-line with overall information security objectives
  • Establish partnerships with cross-functional teams such as IT, Legal, HR and Privacy to ensure they understand their roles when supporting the security GRC programs
  • Support the broader security team in establishing annual and long-term goals, objectives, metrics, and reporting mechanisms

What We're Looking For:

  • 5+ years of experience in technology audit, security risk management, and/or security compliance role, with at least 2-4 years implementing or auditing compliance with key cybersecurity standards (e.g., PCI DSS, ISO 27001, SOC2, etc.) in a cloud-first environment
  • Experienced with cloud infrastructure technologies and services (e.g., AWS, GCP, Azure) as well as various enterprise SaaS solutions 
  • Functional knowledge of multiple security domains and information security industry standards and best practices
  • Experienced with the implementation and/or use of control automation and compliance tools
  • Effective in building relationships with organizational leaders and influencing senior management
  • Excellent organizational skills, proactive and self-sufficient with a proven ability to work independently to effectively prioritize and execute tasks
  • Drive, determination, and the ability to overcome roadblocks and initial objections
  • Strong project management skills
  • Ability to work collaboratively with multiple stakeholders across different backgrounds and skill sets
  • Strong written, verbal communication, and presentation skills.
  • BS/BA in a related field (e.g., Computer Science, MIS) desirable, or equivalent relevant experience
  • Security-related or cloud-related certifications such as CISA, CISSP, AWS Solutions Architect, etc. is a plus

Additionally, the following benefits are provided by Red Ventures, subject to eligibility requirements.

  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Paid Time Off
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program

Who We Are

Founded in 2000, Red Ventures (RV) is home to a diverse portfolio of industry-leading brands and businesses, strategic partnerships and proprietary technology – including Bankrate, Lonely Planet, CNET, The Points Guy, BestColleges and more. Together, RV helps millions of people worldwide make life’s most important decisions, accelerates digital adaptation, and innovates the online consumer experience by improving every step of the consumer journey – from first discovery of information, throughout the decision-making process, to transactions. Headquartered south of Charlotte, NC, Red Ventures employs thousands of people across the US and Puerto Rico, with international offices in the UK and Brazil. For more information, visit https://redventures.com and follow @RedVentures on social platforms. 

We offer competitive salaries and a comprehensive benefits program for full-time employees, including medical, dental and vision coverage, paid time off, life insurance, disability coverage, employee assistance program, 401(k) plan and a paid parental leave program.

Red Ventures is an equal opportunity employer that does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or any other basis protected by law. Employment at Red Ventures is based solely on a person's merit and qualifications. 

We are committed to providing equal employment opportunities to qualified individuals with disabilities. This includes providing reasonable accommodation where appropriate. Should you require a reasonable accommodation to apply or participate in the job application or interview process, please contact accommodation@redventures.com

If you are based in California, we encourage you to read this important information for California residents linked here.

#li-hybrid #li-lm2

Click here for more details regarding the employee privacy policy: https://www.redventures.com/legal/us-emp-privacy-notice

Questions about this Privacy Notice can be directed to employeerights@redventures.com. Alternatively, you may raise any questions or concerns to your manager, HR Business Partner, or through the Privacy Team.

Apply for this Job

* Required
resume chosen  
(File types: pdf, doc, docx, txt, rtf)
cover_letter chosen  
(File types: pdf, doc, docx, txt, rtf)


Voluntary Demographic Questions

At Red Ventures we believe we can be the change we wish to see in the world. We believe that action expresses priorities, and we have a responsibility to interrupt injustice and indifference whenever we see it. By holding ourselves accountable to being open and inclusive teammates, community members, and leaders inside the walls of RV, we hope to set an example for others in the world to follow. With this in mind, we invite you to help inform us on how we can strengthen our hiring practices by identifying and mitigating unconscious bias from our hiring process.

Below is a set of voluntary demographic questions that are part of our Diversity and Inclusion strategy. We consider the responses to these questions as “sensitive” information. We will treat any personal information provided in response to these questions as “sensitive” under applicable law in accordance with that applicable law. If you choose to fill them out, the responses will be used (in aggregate only) to help us identify areas for improvement in our process. Your responses, or your choice to not respond,  will not be associated with your specific application and will not in any way be used in the hiring decision.

I identify my ethnicity as (mark all that apply): *











How do you currently describe your gender identity? (Select one) *






Do you consider yourself member of the LGBTQIA+ community? *



Have you been diagnosed with any disability or impairment? *



Do you identify as a military veteran or service member? *



Do you identify as transgender? (Select one) *




Enter the verification code sent to to confirm you are not a robot, then submit your application.

This application was flagged as potential bot traffic. To resubmit your application, turn off any VPNs, clear the browser's cache and cookies, or try another browser. If you still can't submit it, contact our support team through the help center.