Demo

Information Security Compliance & Risk Manager

firstPRO, Inc
Boston, MA Full Time
POSTED ON 4/25/2026
AVAILABLE BEFORE 6/20/2026

The Manager, Information Security Compliance and Risk is responsible for leading the firm’s Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and assurance activities that support client requirements and regulatory obligations.

This role also serves as the primary owner of Information Security AI governance, ensuring that the firm’s use of AI and machine learning technologies aligns with security, privacy, regulatory, and client expectations.

The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement.

Responsibilities:

Governance and Compliance Leadership

  • Own and maintain the firm’s information security governance framework, including policies, standards, and procedures.
  • Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking.
  • Ensure ongoing compliance with client, regulatory, and contractual information security requirements.
  • Manage policy exceptions, risk acceptances, and documentation of compensating controls.

Regulatory Authorization and Assurance

  • Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements.
  • Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments.
  • Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work.

AI Security Governance

  • Lead the Information Security AI governance program, ensuring secure, responsible, and compliant use of AI technologies across the firm.
  • Partner with Legal, Privacy, Compliance, and business stakeholders to define and maintain AI security requirements, risk assessments, and usage standards.
  • Establish and maintain security controls for AI-enabled tools, including data handling, access controls, model usage restrictions, and third-party AI risk.
  • Support client and regulatory inquiries related to AI security posture and governance practices.
  • Track emerging AI-related regulatory and security requirements and assess their impact on firm policies and controls.

Risk Management

  • Maintain and mature the enterprise information security risk register.
  • Facilitate periodic risk assessments, including risks associated with AI usage, data processing, and third-party technologies.
  • Develop and report meaningful risk metrics and dashboards for leadership review.
  • Translate technical and operational risks into clear business-impact language.

Third-Party and Emerging Risk Governance

  • Oversee third-party security risk management in partnership with Legal.
  • Lead structured reviews of vendor security posture, including AI and SaaS providers.
  • Track remediation plans and ongoing monitoring of third-party and AI-related risks.

Audit and Assurance Coordination

  • Serve as the primary liaison for internal and external audits related to information security.
  • Coordinate evidence collection across IT, Security Engineering, Privacy, and business stakeholders.
  • Track findings, corrective actions, and continuous improvement initiatives.

Team Leadership

  • Directly manage three Information Security Analysts.
  • Set priorities, provide mentorship, and support professional development.
  • Establish consistent processes, documentation standards, and performance expectations across the GRC function.

Cross-Functional Collaboration

  • Partner closely with Security Engineering and Operations to align governance requirements with technical controls.
  • Work with Legal, Compliance, Privacy, and Data Science teams on regulatory interpretation and AI governance requirements.
  • Support client security inquiries, assessments, and due diligence requests.

Expected Outcomes

  • Sustained audit readiness for SOC 2 and ISO 27001 with minimal disruption.
  • Clear, measurable visibility into information security and AI-related risk posture.
  • Consistent, scalable governance processes supporting firm growth and responsible AI adoption.
  • Strong alignment between governance requirements and operational security controls.

Qualifications & Skills

  • Bachelor’s degree required; degree in information security, risk management, or a related field preferred.
  • 7 to 10 years of experience in information security, GRC, audit, or risk management required.
  • Prior experience managing SOC 2 and or ISO 27001 programs required.
  • Demonstrated people management or team leadership experience.
  • Professional certifications such as CISSP, CISM, CRISC, CGRC, or ISO 27001 Lead Implementer or Auditor.
  • Experience with GRC platforms and risk management tooling.
  • Experience supporting AI governance, data governance, or emerging technology risk programs.
  • Experience supporting client-driven security assessments in a professional services environment.
  • An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
  • To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.

Salary : $175,000 - $200,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security Compliance & Risk Manager?

Sign up to receive alerts about other jobs on the Information Security Compliance & Risk Manager career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at firstPRO, Inc

  • firstPRO, Inc Burlington, MA
  • Title: Senior Revenue Accountant Location: Burlington, MA (2-3 days a week in office/hybrid) Company Info: 500m publicly held SaaS company. Rapidly growing... more
  • 1 Day Ago

  • firstPRO, Inc Bedford, MA
  • Title: Technical Accounting Manager Location: Primarily remote, office visits a few times a quarter/1x a month. Company Info/Industry: $2.5B Publicly Trade... more
  • 1 Day Ago

  • firstPRO, Inc Philadelphia, PA
  • We are seeking a Senior Project Manager for a hybrid (primarily remote) contract-to-hire opportunity. This individual will manage a portfolio of complex pr... more
  • 1 Day Ago

  • firstPRO, Inc Langhorne, PA
  • firstPRO is seeking a highly skilled Workday Integration Developer to support a fast-paced enterprise environment. This is a hands-on, contract role focuse... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Information Security Compliance & Risk Manager jobs in the Boston, MA area that may be a better fit.

  • Analysis Group Boston, MA
  • Overview Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North Ameri... more
  • 5 Days Ago

  • firstPRO, Inc Boston, MA
  • The Information Security Compliance and Risk Manager is responsible for overseeing and advancing the organization’s Governance, Risk, and Compliance functi... more
  • 6 Days Ago

AI Assistant is available now!

Feel free to start your new journey!