Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details
Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

NOCDOC

Compliance & Risk Manager

Career Insights for Compliance Manager

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on North Carolina data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Compliance Manager tracks employer compliance with laws and regulations, particularly for organizations in business and health care. Creates company policies, reviews departmental functions and protocol, follows developments in law and regulations affecting the industry

$160,642 / year median in North Carolina

+5% projected growth

Explore Career

Job Description

Compliance & Risk Manager NOCDOC Winston-Salem, NC Job Details Full-time 21 hours ago Benefits Health insurance Dental insurance 401(k) Vision insurance Life insurance Qualifications Project team coordination Customer communication Risk management compliance audits Internal controls Information security audit implementation Technical documentation Task prioritization Technical writing Managing projects Cross-functional collaboration Cross-functional team management Information security auditing Project stakeholder communication Cross-functional communication Audit support IT risk management Full Job Description Winston-Salem, North Carolina | On-Site / Hybrid / Remote | U.S.-Based Only | Full-Time Position Overview NOCDOC is seeking a Compliance & Risk Manager to establish, maintain, and continuously improve the organization's compliance, governance, and risk management program. This role serves as the central owner for compliance strategy, audit readiness, risk management, policy governance, and client-facing compliance requirements. The Compliance & Risk Manager ensures NOCDOC maintains a mature, transparent, and scalable compliance program aligned with applicable frameworks, contractual obligations, and industry expectations. The Compliance & Risk Manager manages compliance activities across applicable standards and regulations, including
SOC 2, ISO
27001, HIPAA, PCI, and other relevant requirements. This role coordinates policy management, evidence collection, risk assessments, vendor security reviews, audit preparation, and compliance communications. The Compliance & Risk Manager is the single point of ownership for client-facing compliance deliverables, ensuring consistent communication and accurate representation of NOCDOC's compliance posture regardless of whether supporting activities are performed by Security Operations, Network Operations, Field Engineering, Service Desk, or other operational teams. Key Responsibilities Compliance Program Ownership Own the organization's compliance program strategy, roadmap, and maturity improvements Establish, maintain, and improve compliance policies, standards, procedures, and governance documentation Manage compliance activities across applicable frameworks, regulations, and contractual requirements Translate compliance requirements into practical operational expectations Maintain awareness of evolving regulatory, industry, and customer compliance expectations Provide leadership visibility into compliance posture, risks, and improvement initiatives Framework Management & Audit Readiness Lead preparation for compliance assessments, audits, and certification activities Manage compliance frameworks including
SOC 2, ISO
27001, HIPAA, PCI, and other applicable standards Coordinate evidence collection, control validation, documentation review, and audit responses Maintain ongoing audit readiness through continuous monitoring and improvement Track remediation activities and ensure identified gaps are appropriately addressed Coordinate with internal stakeholders and external auditors as required Risk Management Own organizational risk management processes, including identification, assessment, tracking, and reporting Maintain risk registers and coordinate remediation activities Evaluate business, operational, security, and compliance risks Provide guidance on risk-based decision-making and control prioritization Escalate significant risks and recommend mitigation strategies Support leadership decisions through risk visibility and reporting Vendor Security Reviews Own the vendor security review process for third-party providers and partners Evaluate vendor security documentation, certifications, compliance posture, and risk implications Coordinate security questionnaires, assessments, and supporting evidence requests Maintain vendor risk records and review schedules Partner with internal teams to support informed vendor risk decisions Client-Facing Compliance Support Serve as the primary owner for client compliance requests, security questionnaires, evidence packages, and compliance documentation Ensure responses are accurate, consistent, complete, and delivered within required timelines Coordinate with technical teams to gather supporting evidence and validate control implementation Translate technical controls and operational practices into clear business-facing documentation Maintain client confidence through professional and transparent compliance communications Cross-Functional Control Coordination Partner with SOC, NOC, Field Engineering, Service Desk, IT & Security Administration, and other teams to ensure effective control operation Define compliance requirements while allowing technical teams to own execution within their areas of responsibility Establish accountability for evidence quality, control operation, and continuous improvement Promote a culture of compliance, security awareness, and operational discipline Documentation & Continuous Improvement Maintain compliance policies, procedures, control narratives, evidence repositories, and governance documentation Improve compliance workflows to increase efficiency and audit readiness Identify opportunities to automate and streamline compliance activities Maintain reporting on compliance posture, risks, remediation efforts, and program maturity Required Qualifications Experience managing compliance, governance, risk, or security programs Strong understanding of security control frameworks and risk management principles, including CIS Controls, NIST Cybersecurity Framework, SOC 2, ISO 27001, or similar standards Experience preparing for audits, assessments, and client compliance reviews Strong documentation and organizational skills Experience coordinating across technical and business teams Ability to communicate compliance concepts effectively to technical and non-technical audiences Strong project management and prioritization skills Preferred Qualifications Experience managing compliance programs within managed services, technology services, cybersecurity, healthcare, financial services, or regulated industries Experience supporting customer security reviews and compliance questionnaires Experience with Governance, Risk, and Compliance (GRC) platforms Experience managing third-party risk programs Experience developing policies, procedures, and control documentation Preferred Certifications (preferred but not required; equivalent combinations of education, certifications, and relevant experience will be considered) Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Security Professional (CISSP)
ISO 27001
Lead Implementer
ISO 27001
Lead Auditor Certified in Governance, Risk and Compliance (CGRC) CompTIA Security+ Technical Skills Compliance, Governance & Frameworks SOC 2 framework / Trust Services Criteria
ISO 27001
framework and control concepts HIPAA requirements PCI DSS requirements CIS Controls NIST Cybersecurity Framework (CSF) Policy development Audit preparation Evidence management and control mapping Risk assessment methodologies Risk Management Risk assessments Risk registers Control evaluation Remediation tracking Third-party risk management Vendor security reviews Security & Technology Concepts Security controls Identity and access management concepts Endpoint security concepts Network security concepts Security operations concepts Cloud security concepts Compliance Tools & Documentation GRC platforms Documentation management systems Evidence repositories Audit tracking tools Reporting dashboards Professional Skills Communication Documentation discipline Attention to detail Organization Stakeholder management Problem solving Project management Ability to influence without direct authority Continuous improvement mindset Success Measures Success in this role will be demonstrated through: Maintained audit readiness and successful completion of compliance assessments Clear ownership and maturity of NOCDOC's compliance program Timely and accurate completion of client compliance requests Improved visibility into organizational risks and remediation efforts Strong vendor risk management practices Consistent alignment between documented controls and operational execution Increased client confidence in NOCDOC's compliance posture Career Growth Opportunity This role provides opportunities to grow into Director of Compliance, Governance Risk & Compliance leadership, Security Governance leadership, or broader operational risk management roles as the organization expands. Schedule This position operates during standard business hours and may require flexibility during audit periods, client assessments, and compliance activities.
Benefits Benefits include:
Medical insurance Dental insurance Vision insurance 401(k) Life insurance Remote and hybrid work opportunities About
NOCDOC NOCDOC
is a U.S.-based technology operations company with more than 35 years of experience delivering Security Operations Center (SOC), Network Operations Center (NOC), Service Desk, Network Engineering, Automation, and Managed Security Services. Supporting organizations across North America and internationally, NOCDOC delivers responsive, customer-focused technology operations that help businesses improve reliability, security, and operational efficiency. At NOCDOC, we invest in our people through continuous learning, mentorship, and career development, providing opportunities to grow into advanced engineering, automation, architecture, and technical leadership roles.
Work Location:
Hybrid remote in Winston-Salem, NC 27101