Demo

Manager, Information Security GRC

Sutton Bank
Columbus, OH Full Time
POSTED ON 8/20/2026
AVAILABLE BEFORE 10/30/2026

Summary:

The Information Security Governance, Risk, and Compliance (GRC) Manager is responsible for leading the development, implementation, and ongoing management of the organization's security governance framework. Responsible for the oversight of risk management activities, ensures compliance with applicable regulations and standards, and drives continuous improvement in the security program. The GRC Manager partners closely with technology, legal, audit, and business stakeholders to embed security into operations and support strategic objectives.

 

Qualifications:

 

Education: Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or related field. Master's Degree preferred.

 

Licenses/Certifications: Valid Driver's License, CISSP, CISA or CRISC.

Preferred: Relevant certifications such as CompTIA Security , Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or similar credentials.

 

Experience: Seven or more years of combined experience in information security, IT or risk management, preferably in a financial institution. Experience leading a team. Or equivalent combination of education and experience.

 

Essential Functions:

 

A: Job Specific:

  • Designs and executes end-to-end risk assessments that include internal, third party and fourth party vendors, identifying high-impact vulnerabilities, threats, and business risk across the enterprise.
  • Oversees compliance with security policies, industry standards, and regulations (e.g., NIST CSF, HIPAA, NIST 800-53, PCI-DSS, GDPR, GLBA or ISO 27001).
  • Develops and updates security policies, standards, and procedures to address evolving risk and regulatory requirements.
  • Leads audit preparation and response efforts, managing interactions with external auditors and ensuring timely resolution of findings.
  • Leads investigations into security incidents, performing detailed root cause analysis and impact assessments.
  • Designs and implements advanced security metrics and key risk indicators (KRIs) to measure and communicate risk posture.
  • Acts as a trusted advisor to senior management, providing insights on risk trends, mitigation strategies, and security investments.
  • Collaborates with business units, IT, legal and compliance teams to embed risk management into strategic initiatives and projects.
  • Leads and mentor junior analysts, providing guidance on technical skills, risk methodologies, and professional development.
  • Partners with HR to manage staff performance issues/concerns, develop/identify training needs, recruitment processes.

Knowledge/Skills/Abilities:

  • Excellent verbal and written communications at both business and deep technical levels.
  • Strong understanding of and experience with process improvement and process mapping.
  • Strong leadership skills, dependable, curious, matrix-oriented, a visionary, solution oriented, delivers exemplary customer service and quality focused.
  • Excellent interpersonal skills.
  • Self-directed and motivated.
  • The ability to manage multiple tasks.
  • Ability to read and comprehend instructions, correspondence, technical manuals and memos.
  • Ability to respond to common inquiries or complaints from employees, vendors and management staff.
  • Ability to effectively present information to individuals one-on-one or a small group setting.
  • Ability to articulate technical concepts to end-users.
  • Advanced knowledge of TPRM platforms and ability to optimize.
  • Proactive Mindset: Staying ahead of emerging threats and taking initiative in risk mitigation.
  • Strong analytical and problem-solving skills.
  • Attention to Detail: Ability to identify subtle security vulnerabilities and ensure accurate documentation.
  • Adaptability: Capacity to learn and adapt to rapidly evolving security threats and technologies.
  • Teamwork: Willingness to collaborate with other team members for effective risk mitigation.
  • Time Management: Skill in prioritizing tasks and managing workload in a fast-paced environment.

Sutton Bank is an Equal Employment Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, pregnancy, disability or protected veteran status.

 

Salary.com Estimation for Manager, Information Security GRC in Columbus, OH
$129,089 to $154,473
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Manager, Information Security GRC?

Sign up to receive alerts about other jobs on the Manager, Information Security GRC career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Sutton Bank

  • Sutton Bank Columbus, OH
  • Summary: Responsible for monitoring and testing the Payments Division Program risk-taking activities on an ongoing basis to ensure applicable regulatory re... more
  • 5 Days Ago

  • Sutton Bank Columbus, OH
  • Summary: Responsible for the monitoring and testing of payments programs within the First Line of Defense. Works to minimize risk through the continuous mo... more
  • 5 Days Ago

  • Sutton Bank Columbus, OH
  • Summary: Responsible for establishing, maintaining, and continuously improving the Payments Division's risk monitoring, control governance, testing, and va... more
  • 5 Days Ago

  • Sutton Bank Columbus, OH
  • Summary: Responsible for providing first-line risk oversight and governance for payment products, fintech partnerships, third-party relationships, and oper... more
  • 5 Days Ago


Not the job you're looking for? Here are some other Manager, Information Security GRC jobs in the Columbus, OH area that may be a better fit.

  • Deloitte Columbus, OH
  • SAP Security and GRC Manager / Engineering Manager II Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technolog... more
  • 23 Days Ago

  • Wells Fargo Columbus, OH
  • Why Wells Fargo Are you looking for more? Find it here. At Wells Fargo, we're more than a financial services leader -we're a global trailblazer committed t... more
  • 4 Days Ago

AI Assistant is available now!

Feel free to start your new journey!