Reeds
Manager of IT Risk and Compliance
Wilmington, North Carolina, United States · Full-time
Sponsorship not specifiedDetected 6 days ago
ComplianceAuditingSupply ChainLogisticsProcurementERPCorporate LawCustomer SupportLeadershipSarbanes-OxleyInternal AuditUnderwritingCISSP
About the role
- For 80 years, we've built a legacy of trust, exceptional customer service, and curated fine jewelry- offering our clients an elevated experience both in-store and online.
- We believe every milestone deserves to be marked with elegance, and every moment honored with meaning.
- What sets REEDS apart is our unwavering commitment to people and progress.
Responsibilities
- Financial Intelligence, Fraud Investigation & SAR Filing Incident Investigation: Lead technical forensic investigations into complex corporate fraud including: e-commerce account takeovers, gift card manipulation, and anomalous transactional behaviors across point-of-sale (POS) and omni-channel credit integrations.
- SAR Management & Filing: Own the end-to-end process of troubleshooting suspicious patterns, compiling narrative reports, and formally filing Suspicious Activity Reports (SARs) with the Financial Crimes Enforcement Network (FinCEN) in strict compliance with Bank Secrecy Act (BSA) rules for luxury retailers.
- Regulatory & Industry Compliance PCI-DSS Management: Own end-to-end compliance for PCI-DSS across all digital checkout touchpoints, POS systems, and multi-channel payment integrations.
- Financial & Corporate Governance: Manage and test IT General Controls (ITGC) to support Sarbanes-Oxley (SOX) audit readiness, ensuring tight segregation of duties (SoD) across financial and inventory systems (e.g., enterprise ERP and legacy AS400 databases).
- Risk Management & Third-Party Governance IT Enterprise Risk Register: Maintain and update the IT risk register, translating technical security findings and transaction fraud vectors into quantifiable business risks.
- Technology Vendor Risk Management (VRM): Architect and execute a robust third-party risk assessment program for SaaS providers, financial partners, supply chain logistics, and AI/analytics vendors.
- IT Policy Enforcement: Develop, update, and manage the lifecycle of corporate information security policies aligned with the NIST Cybersecurity Framework or ISO 27001.
- Own the end-to-end process of troubleshooting suspicious patterns, compiling narrative reports, and formally filing Suspicious Activity Reports (SARs) with the Financial Crimes Enforcement Network (FinCEN) in strict compliance with Bank Secrecy Act (BSA) rules for luxury retailers.
- Own end-to-end compliance for PCI-DSS across all digital checkout touchpoints, POS systems, and multi-channel payment integrations.
- Maintain and update the IT risk register, translating technical security findings and transaction fraud vectors into quantifiable business risks.
Requirements
- 3 to 5 years of progressive experience in IT audit, information security governance, or IT risk management.
- Deep working knowledge of American Disabilities Act (ADA), Data Protection Compliance, PCI-DSS, SOX, and consumer privacy laws.
- Required to demonstrate elite capability in managing enterprise security governance and risk.
- CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional): Required to demonstrate elite capability in managing enterprise security governance and risk.
- & Experience Experience: 3 to 5 years of progressive experience in IT audit, information security governance, or IT risk management.
Nice to have
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Business Administration, or a related field.
- Mandated Professional Certifications Candidates must possess at least two of the following certifications.
- Given the expanded investigative mandate, a combination of a technical security certification and a fraud/investigative certification is highly preferred:
- CRISC (Certified in Risk and Information Systems Control): Preferred for candidates specializing in designing and executing enterprise-level IT risk registers.
Benefits
- As one of the nation's largest family-owned jewelers, we are proud to pair a rich legacy with a modern vision for the future of luxury retail.
- REEDS Jewelers offers a comprehensive compensation program, merchandise discounts, 401(k), and paid time off.
Company info
- At REEDS Jewelers, we bring together the timeless values with the energy and innovation of a modern luxury retailer.
Equal opportunity
- REEDS Jewelers is an Equal Opportunity Employer.
This listing is sourced directly from Reeds's careers page and normalized into a canonical job model.