Enterprise Security Compliance Manager
555 West Fifth Street Suite 300 Los Angeles California 90013 United States los angeles, CA 90013 US
Job Description
The Enterprise Security Compliance Manager plays a key role within a global security and risk organization, with primary responsibility for overseeing third-party security compliance efforts. This position focuses on evaluating and managing vendor risk, including cloud and technology service providers, through structured audits and access reviews. Using a risk-based methodology, the role determines audit scope, leads assessments end-to-end, collaborates with legal, governance, and technology stakeholders, and delivers actionable recommendations to senior leadership.
This position is based in a centralized services office in a major metropolitan area and may support a hybrid working model.
Key Responsibilities
-
Facilitate and lead cross-functional vendor security review forums, coordinating assessments and incorporating subject matter expertise from internal stakeholders
-
Plan and manage external penetration testing and vulnerability assessments, including vendor selection, scheduling, negotiation, and follow-up on deliverables
-
Participate in contract review workflows to identify security risks and recommend appropriate contractual safeguards
-
Support client-driven security assessments as needed, managing the process from intake to completion, coordinating internal contributors, preparing documentation and responses, and leading discussions as required
-
Partner with information security leadership to analyze internal and third-party vulnerability scan results and coordinate remediation planning
-
Track and manage remediation commitments to ensure timely and effective resolution
-
Contribute to initiatives that strengthen the confidentiality, integrity, and availability of organizational data across all platforms
-
Maintain and update security documentation, standards, and procedures
-
Act as a trusted advisor on information security best practices, with particular emphasis on vendor risk and cloud security, and promote security awareness across the organization
-
Handle sensitive, confidential, and proprietary information with the highest level of care and discretion
Successful candidates will demonstrate:
-
Strong interpersonal skills with the ability to engage effectively with internal teams, external partners, and senior stakeholders
-
Clear and confident written and verbal communication abilities
-
Sound judgment and analytical thinking, with a practical approach to problem solving
-
Bachelor’s degree or equivalent professional experience in information security or technology; degrees in Computer Science, Information Systems, Engineering, or related fields are preferred
-
Industry-recognized security certification is a plus
-
5+ years of experience in information security
-
10+ years of experience in information technology or related disciplines
-
2+ years of experience applying project management methodologies
-
Prior experience in a legal, professional services, or similarly regulated environment is preferred
The Phoenix Group Advisors is an equal opportunity employer. We are committed to creating a diverse and inclusive workplace and prohibit discrimination and harassment of any kind based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. We strive to attract talented individuals from all backgrounds and provide equal employment opportunities to all employees and applicants for employment.