waypointjobs

Signet Jewelers

InfoSec GRC Manager

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

We have many opportunities available on our other career site pages. Click here to link to our careers page!

Signet Jewelers is the world's largest retailer of diamond jewelry, operating more than 2,800 stores worldwide under the iconic brands: Kay Jewelers, Zales, Jared, H.Samuel, Ernest Jones, Peoples, Banter by Piercing Pagoda, Rocksbox, JamesAllen.com and Diamonds Direct. We are a people-first company and this core value is at the heart of everything we do, from empowering our valued team members, to collaborating with our customers, to fostering the communities in which we live and serve. People – and the love their actions inspire – are what drive us. We’re not only proud of the love we inspire outside our walls, we’re especially proud of the diversity, inclusion and equity we’re inspiring inside. There are dynamic career paths awaiting you – rewarding opportunities to impact the lives of others and inspire love. Join us!

InfoSec GRC Manager

Remote

POSITION SUMMARY:

The Information Security GRC Manager is responsible for leading the organization’s governance, risk management, and compliance initiatives related to information security. This role ensures that security policies, standards, and controls align with regulatory requirements and business objectives, while effectively managing risk across the enterprise.

RESPONSIBILITIES:

Plan and execute compliance readiness, and certification assessments (e.g., SOX, PCI-DSS, NIST CSF, ISO 27001)

Serve as the primary point of contact for external assessors and auditors

Ensure ongoing compliance with applicable regulatory and contractual requirements

Coordinate internal and external audits, including SOX-related security controls where applicable

Lead enterprise risk assessments, including identification, analysis, prioritization, and mitigation of security risks

Define and monitor Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)

Drive risk-based decision-making across security and business stakeholders

Track remediation activities, ensuring timely closure and proper documentation

Drive continuous improvement of control effectiveness and assurance processes

Partner with IT, Legal, Privacy, and business teams to embed security and compliance into operations

Provide regular reporting on risk posture, compliance status, and program maturity to senior leadership

Maintain and evolve security policies, standards, procedures, and risk methodologies

Develop, maintain, and continuously enhance the enterprise information security governance framework

Develop and deliver security awareness programs related to risk and compliance

Promote a strong culture of security and accountability across the organization

POSITION QUALIFICATIONS:

Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Business, or related field

10+ years of experience in information security, IT risk, or compliance, with 2–3+ years in GRC-focused role

Strong knowledge of industry frameworks and standards (e.g. NIST, ISO 27001, COBIT)

Proven experience managing assessments and working with external regulators and assessors

Demonstrated ability to manage multiple concurrent initiatives and remediation efforts

Preferred Certifications:

Experience implementing and maturing cybersecurity compliance programs

Relevant certifications (e.g., CISSP, CISM, CRISC, CISA)

Experience with SOX and PCI ITGC controls and audit coordination

Familiarity with GRC tools (e.g., Optro (AuditBoard), ServiceNow GRC, OneTrust)

Key Skills:

Audit management and coordination

Risk assessment and mitigation

Regulatory compliance management

Cross-functional collaboration

Leadership and team management

Strong written and verbal communication

BENEFITS & PERKS:

Comprehensive healthcare, dental, and vision insurance to keep you and your family covered that is active on day 1 of employment

Generous 401(k) matching after just one year to help secure your financial future

Ample paid time off, plus seven holidays to recharge and unwind

Exclusive discounts on premium merchandise just for you

Dynamic Learning & Development programs to support your growth

And more!

The salary range for this opportunity is $125,000-$150,000. Base pay offered may vary depending on geographic region, internal equity, job related knowledge, skills and experience, among other factors. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job