Echo Global Logistics

Echo Global Logistics

Cybersecurity GRC Program Lead

Chicago, IL

Sponsorship not specified$60k-$90kDetected 26 days ago
CybersecurityComplianceStakeholder ManagementAuditingLogisticsLeadershipCommunicationInternal AuditTransportation Management

About the role

  • This role is not limited to policy writing or audit coordination.
  • Justification Echo is reassessing its policy foundation, including formal expectations for information security governance, access control, supplier security, and compliance review.
  • What is needed now is a leader who can turn those policies into a durable governance operating system with clear ownership, evidence discipline, exception management, and measurable accountability.

Responsibilities

  • Lead selection, adoption, and operationalization of Echo's primary cybersecurity framework and related standards structure, with NIST CSF 2.0 as the likely management layer
  • Build and maintain a control ownership model across Technology, Engineering, Platform, Network, EUC, Asset, Data, Integrations, and Security
  • Partner with security architecture, engineering, and operations teams to ensure that governance expectations are practical, technically grounded, and enforceable
  • Drive enterprise risk and control assessments, including facilitating discussions on control design, effectiveness, and remediation priorities
  • Build an evidence library structure while defining repeatable collection, review, reuse, and freshness cadences
  • Partner with Internal Audit and business stakeholders on readiness efforts, compliance reviews, and operational audit support
  • Perform User Access Reviews compliant to SOX ITGC and SOC2/ISO27001
  • Lead the evolution to and support of continuous compliance capabilities to improve control visibility, evidence freshness, and audit readiness
  • Manage and evolve the organization's trust center, including published security documentation, customer-facing assurance materials, and the processes that keep content current and supportable

Requirements

  • 2+ years of GRC experience in a public company.
  • Experience with SOX ITGC controls.
  • Experience with risk assessments, control design reviews, exception management, and remediation tracking
  • Strong understanding of third-party risk, supplier security reviews, security questionnaires, and governance workflows that scale beyond one-off reviews
  • Experience partnering with technical teams to influence architecture, engineering, and operations outcomes in a practical, technically credible way
  • Ability to turn policy and framework language into concrete operating practices, ownership expectations, and measurable evidence
  • The employee is regularly required to sit, talk, or hear.
  • 5 + years in cybersecurity GRC, security risk, audit readiness, compliance operations, or related functions, with clear experience building or maturing governance operating models
  • Under standing of regulatory and SEC requirements for a public company.
  • Strong experience operationalizing NIST CSF and translating controls across frameworks such as ISO 27001, SOX, SOC 2, or similar frameworks
  • Experience building or maturing security governance programs in complex enterprise environments with multiple technical stakeholders
  • Strong writing, stakeholder management, and executive communication skills
  • Preferred qualifications

Nice to have

  • Experience supporting SOC 2, ISO 27001, CTPAT, SOX or similar audit/readiness efforts
  • Experience with evidence management, control testing, internal audit coordination, or related assurance processes
  • Experience with automated continuous compliance platforms, including evidence automation, control monitoring, and audit readiness workflows
  • Experience managing a trust center or similar customer assurance portal and keeping security documentation current and reusable
  • Familiarity with enterprise technology environments spanning cloud, identity, endpoint, network, and application security domains.
  • Knowledge of AI governance frameworks, e.g, NIST AI RMF, and ISO 42001.
  • GRC experience with a public company for SEC and regulatory reporting requirements, i.e. 10K, 8K.
  • Echo Global Logistics is a leading provider of technology-enabled transportation management services.

Skills

  • Own the automated CCM platform.
  • Justification
  • Hiring Requirements

Compensation

  • $112,498.00-163,571.00 per year

Benefits

  • For more information about our benefit offerings, please visit our careers page at https://www.echo.com/company/careers.
  • This role is eligible for a bonus that is based on a combination of personal and business performance.

This listing is sourced directly from Echo Global Logistics's careers page and normalized into a canonical job model.