Echo Global Logistics
Cybersecurity GRC Program Lead
Chicago, IL
Sponsorship not specified$60k-$90kDetected 26 days ago
CybersecurityComplianceStakeholder ManagementAuditingLogisticsLeadershipCommunicationInternal AuditTransportation Management
About the role
- This role is not limited to policy writing or audit coordination.
- Justification Echo is reassessing its policy foundation, including formal expectations for information security governance, access control, supplier security, and compliance review.
- What is needed now is a leader who can turn those policies into a durable governance operating system with clear ownership, evidence discipline, exception management, and measurable accountability.
Responsibilities
- Lead selection, adoption, and operationalization of Echo's primary cybersecurity framework and related standards structure, with NIST CSF 2.0 as the likely management layer
- Build and maintain a control ownership model across Technology, Engineering, Platform, Network, EUC, Asset, Data, Integrations, and Security
- Partner with security architecture, engineering, and operations teams to ensure that governance expectations are practical, technically grounded, and enforceable
- Drive enterprise risk and control assessments, including facilitating discussions on control design, effectiveness, and remediation priorities
- Build an evidence library structure while defining repeatable collection, review, reuse, and freshness cadences
- Partner with Internal Audit and business stakeholders on readiness efforts, compliance reviews, and operational audit support
- Perform User Access Reviews compliant to SOX ITGC and SOC2/ISO27001
- Lead the evolution to and support of continuous compliance capabilities to improve control visibility, evidence freshness, and audit readiness
- Manage and evolve the organization's trust center, including published security documentation, customer-facing assurance materials, and the processes that keep content current and supportable
Requirements
- 2+ years of GRC experience in a public company.
- Experience with SOX ITGC controls.
- Experience with risk assessments, control design reviews, exception management, and remediation tracking
- Strong understanding of third-party risk, supplier security reviews, security questionnaires, and governance workflows that scale beyond one-off reviews
- Experience partnering with technical teams to influence architecture, engineering, and operations outcomes in a practical, technically credible way
- Ability to turn policy and framework language into concrete operating practices, ownership expectations, and measurable evidence
- The employee is regularly required to sit, talk, or hear.
- 5 + years in cybersecurity GRC, security risk, audit readiness, compliance operations, or related functions, with clear experience building or maturing governance operating models
- Under standing of regulatory and SEC requirements for a public company.
- Strong experience operationalizing NIST CSF and translating controls across frameworks such as ISO 27001, SOX, SOC 2, or similar frameworks
- Experience building or maturing security governance programs in complex enterprise environments with multiple technical stakeholders
- Strong writing, stakeholder management, and executive communication skills
- Preferred qualifications
Nice to have
- Experience supporting SOC 2, ISO 27001, CTPAT, SOX or similar audit/readiness efforts
- Experience with evidence management, control testing, internal audit coordination, or related assurance processes
- Experience with automated continuous compliance platforms, including evidence automation, control monitoring, and audit readiness workflows
- Experience managing a trust center or similar customer assurance portal and keeping security documentation current and reusable
- Familiarity with enterprise technology environments spanning cloud, identity, endpoint, network, and application security domains.
- Knowledge of AI governance frameworks, e.g, NIST AI RMF, and ISO 42001.
- GRC experience with a public company for SEC and regulatory reporting requirements, i.e. 10K, 8K.
- Echo Global Logistics is a leading provider of technology-enabled transportation management services.
Skills
- Own the automated CCM platform.
- Justification
- Hiring Requirements
Compensation
- $112,498.00-163,571.00 per year
Benefits
- For more information about our benefit offerings, please visit our careers page at https://www.echo.com/company/careers.
- This role is eligible for a bonus that is based on a combination of personal and business performance.
Apply directly at Echo Global Logistics →Create a free account for alerts like thisView Echo Global Logistics immigration profile
This listing is sourced directly from Echo Global Logistics's careers page and normalized into a canonical job model.