Manager of Information Security
Morningstar
Information Security Compliance Manager
The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity and availability of Morningstar information. The security team offers guidance and technical expertise in areas like application security, policies and procedures, disaster recovery and compliance/regulation. We analyze emerging security threats and conduct risk and vulnerability assessments to ensure that our information remains secure.
The IT Compliance Manager's primary focus is to lead and manage the Information Security Compliance team's effort and activities to ensure information security compliance, privacy and protection across Morningstar. This individual will act as a liaison between Information Security and the Business regarding compliance related issues and activities, execute compliance status reporting and metrics, lead the third-party risk management program, lead the internal and external IT auditing processes, monitor information security and IT processes for compliance and policy issues and collaborate on risk vulnerability assessments. Provides technical expertise in all aspects of enterprise information security compliance for all applicable regulations. This role requires an individual who is well rounded – an exceptional multitasker, an effective communicator, is proactive, analytical and detail-oriented, possessing both strong technical and business skills and, operates well under pressure. This position is based in either our Chicago or Toronto office.
Responsibilities
- Lead, manage and support Morningstar's current and future compliance related responsibilities (SOX, SOC2, PCI)
- Monitor and enforce compliance to information security and compliance policies and standards
- Execute audit tests; identify issues and areas for improvement in efficiency and effectiveness of information technology operations
- Document and manage security / policy / compliance exceptions where necessary
- Manage periodic reviews of security policies, processes and procedures
- Lead and manage the third-party risk management program
- Conduct relevant contract reviews for client security contracts
- Lead and directly manage a team of information security compliance analysts
- Liaise with Morningstar's third-party audit personnel including internal, external, and client auditors and facilitate audits as required
- Ensure Morningstar processes are efficient and effective, and procedures are up-to-date, relevant, and adhere to compliance standards
- Plan, present and drive the strategic information security compliance program for Morningstar
Requirements
- A bachelor's degree and 5+ years' experience in a risk, compliance or IT auditor role
- Strong leadership and team development skills, with experience managing cross-functional and global teams.
- Excellent communication skills and a familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR, SEC, etc.)
- Demonstrated knowledge and experience in the implementation of governance frameworks and security risk management processes, such as NIST, ISO, and COBIT guidelines and standards
- Strong organizational skills and the ability to multitask and switch priorities with short notice
- Strong business analysis, research and analytical skills
- Excellent communication skills and a strong understanding of information security fundamentals
- Availability to work off business hours as required
Preferred
- Relevant security certifications (CISSP, CISM, or CIPP)
- 3+ years' experience directly managing personnel, including hiring, developing, motivating, and directing people as they work
Total Cash Compensation Range (base + bonus): $147,550 - $265, 575
Compensation and Benefits
At Morningstar we believe people are at their best when they are at their healthiest. That's why we champion your wellness through a wide range of programs that support all stages of your personal and professional life. Here are some examples of the offerings we provide:
Financial Health
100% 401k match up to 6% of salary
Stock Ownership Potential
Company provided life insurance - 1x salary + commission
Physical Health
Comprehensive health benefits (medical/dental/vision) including potential premium discounts and company-provided HSA contributions (up to $500-$2,000 annually) for specific plans and coverages
Additional medical Wellness Incentives - up to $300-$600 annual
Company-provided long- and short-term disability insurance
Emotional Health
Trust-Based Time Off
6-week Paid Sabbatical Program
6-Week Paid Family Caregiving Leave
Competitive 8-24 Week Paid Parental Leave
Adoption Assistance
Leadership Coaching & Formal Mentorship Opportunities
Annual Flex Stipend - $1000 annually to cover personal education & well-being expenses
Tuition Reimbursement
Social Health
Charitable Matching Gifts program
Dollars for Doers volunteer program
Paid volunteering days
15+ Employee Resource & Affinity Groups
Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
$70.72k - $115.63k
...Security Services Manager Ann & Robert H. Lurie Children's Hospital of Chicago provides superior pediatric care in a setting that offers the... ...are fulfilled to by others.• Ensures employees receive information needed to perform jobs including feedback to enhance performance...SuggestedHourly payFull timePart timeLocal areaAll shiftsFlexible hoursDay shift$200k - $220k
...Director of Information Security IL_Chicago_Office Position Overview: The Director of Information Security is responsible for the design... ...the highest-level technical expert and is responsible for managing the cybersecurity architecture and engineering functions....SuggestedWork at officeLocal areaRemote work$150k - $165k
...shape what comes next. What You'll Do The Director of Security will lead and modernize security across our Azure-based SaaS platform... ...security operations, incident response, and vulnerability management. Own risk, compliance, and audit readiness (SOC2, GDPR,...SuggestedContract workTemporary workWork experience placementWork at officeImmediate startRemote workWorldwideFlexible hours2 days per week- The Illinois Secretary of State is seeking a Securities Department Director in Chicago. This full-time, in-office position requires administering... ...experience in securities or finance. The role involves budget management, enforcement action direction, and collaboration with legal...SuggestedFull timeWork at office
$88k - $93.5k
...Purpose The Assistant Director of Security will provide assistance and support to the... ...Provides oversight to Security Account Manager. Collaborates with Director of Security... ...critical security and life safety information to property management Collaborates on...SuggestedDaily paidContract workFor contractorsWork at officeLocal area- McDonald's Corporation is seeking a Director of Threat Operations & Offensive Security responsible for defining and leading a global cybersecurity program. You will manage a distributed team and set strategic direction to enhance risk reduction capabilities. This role requires...
- A leading global real estate firm is seeking an Assistant Director of Security in Chicago, IL. The role involves supporting the Director of Security in managing security operations and maintaining safety protocols in a high-rise building. Candidates should have significant...
$113k
...Assistance / Military Leave Key Responsibilities: Manage security program by partnering with IT and other departments to... ...certification preferred This position requires use of information which is subject to the International Traffic in Arms Regulations...Temporary workLocal areaFlexible hours- ...long term contract project immediately available for _*_**Manager, IT Security, Chicago, IL, _Onsite_** need submissions you please review... ...advisor on all matters, technical and otherwise involving the information security or privacy controls for systems.- Manage and...Long term contractFor contractorsWork at officeLocal areaImmediate startDay shift
$171k - $311k
...currently seeking a Director, KDN National IT Security Officer (NITSO) to join our KPMG... ...organization. Responsibilities: Lead the Information Security Organization and oversee the... ...(e.g. the Global Quality & Risk Management Manual); ensure appropriate Information...Work experience placementH1bLocal areaRemote work$160k - $180k
...Job Title: Director, Information & Technology Security Location: Hybrid - Chicago Salary: $160,000-$180,000 annually, eligible for annual... ...maintain conditional access, MFA, and privileged identity management Establish baseline access standards and least-...Temporary work$160k - $190k
...regulatory standing by ensuring compliance and exam readiness, managing regulatory risk. This is a high visibility/high impact role.... ...support, regulatory program compliance. The Sr Manager, Information Security Regulatory & Exam is responsible for regulatory exam support...Remote workFlexible hours- ...continuous learning. The Department of Information and Technology Services (ITS) works to... ...technology, maintain network infrastructure, security standards, and support other departments... ...information security violations and manage escalation of security events; assist...Full timeContract workPart timeFlexible hours
- ...retail/manufacturing organization in Chicago is seeking a senior security leader to own and evolve its cybersecurity program. This is a... ...role focused on enterprise security, compliance, and risk management within a modern ecommerce and internal systems environment. The...Full time
$179k - $246k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential... ...for candidates, interviewers, and hiring managers. Role: This is an opportunity to scale... ...that improve team performance and inform decision-making Partner with Finance and...Local areaWorldwideFlexible hours$97k - $189k
...vision, design, and implementation of data security controls for CNA. This position leads... .../Tokenization, Digital Rights Management, Data Protection, and Data Discovery across... ...legal and regulatory issues affecting information security and assesses their impact on CNA...Work experience placementLocal area$175k - $195k
...Huron is seeking a senior-level AI Security Architect to help clients design, secure... ...facing advisory, focusing on security, risk management, and governance across the AI lifecycle... ...wellness programs. The salary range information provided is in accordance with applicable...Local areaImmediate start$130k - $175k
...National Security Risk Analyst Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results... ...agility to design and execute compliance risk mitigation and information security solutions that are adaptive to client risks and...Part timeWork at officeFlexible hours$155k - $410k
...design for the most important business, security and compliance processes for our clients... ...stakeholders, compliance functions, and Information Technology teams to assist in understanding... ...to improve end user experiences while managing risk. Our team helps companies manage...Full timeH1b$120k - $175k
A leading retail real estate company in Chicago seeks a Director of Corporate Security to oversee security operations across its properties. The role involves managing vendor performance, responding to crises, and enhancing security programs. Ideal candidates should have...- ...Director, Information Security Architect, Chicago, IL We have an opening for a Director, Information Security Architect, to join the... ...capabilities, including areas such as CSPM (Cloud Security Posture Management) and SSPM (SaaS Security Posture Management). - Architect...Temporary workFlexible hours
- ...Network Security Controls Senior Manager The Boeing Company is currently seeking a Network Security Controls Senior Manager to join the team... ...visionary leader reporting directly to the Deputy Chief Information Security Officer (CISO), you will drive the design and delivery...Contract workRemote work
- ...Operations is responsible for the reliable, secure, and well-governed operation of the... ...environment, including infrastructure, vendor management, systems governance, device lifecycle... ...to reduce operational friction. Information Security & Compliance Oversee implementation...For contractorsWork experience placementWork at officeFlexible hours1 day per week
- ...as we are, join our team. KPMG is currently seeking a Manager, Security Posture Management Innovation Engineer to join our Global Technology... ...field such as Computer Sciences, Computer Engineering, Information Technology and Security or equivalent seven years work...Work experience placementH1bLocal area
$108.88k - $163.32k
...Digital and E-commerce, Technology and more. Overview The ADUSA Security Manager oversees the Security Patching team, with the primary goal... ...environment. Technical Undergraduate degree. Knowledge of information systems and security controls, of attack types and...Full timeWork experience placementWork at officeRemote workFlexible hoursWeekend work$161.5k - $299.7k
...Position Is Responsible for directing and managing the activities of the HCSC's Cyber... ...constantly improve the organization's Cyber Security Posture, ensuring the CFC is operating effectively... ...Degree and 12 years experience in Information Technology/Information Security OR 16...$172k - $250k
...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below... ...be responsible for establishing global delivery centers, managing internal and external audits, and ensuring the information security...InternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week$140k - $160k
...team presence to advance clients toward a secure digital enterprise. With a 30-year... ...delivers multi and hybrid cloud infrastructure managed services, consulting and advisory... ...Requirements ~ Bachelor's degree in Information Technology, Computer Science, or related...Contract workTemporary workApprenticeshipLocal area$137k - $219k
...JOB REQUISITION Oracle Cloud Data & Security - Senior Manager LOCATION CHICAGO ADDITIONAL LOCATION(S) ATLANTA - PEACHTREE RD, DALLAS, DENVER, HOUSTON, MIAMI, PHILADELPHIA, PRO TAMPA JOB DESCRIPTION You Belong Here The Protiviti Career...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours$160k - $180k
...fast-growing insurance agency is seeking a Director of Information & Technology Security to lead security initiatives at their Chicago office. The... ...integrity. The role requires a deep understanding of identity management, endpoint security, and incident response. Competitive...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager of Information Security. Be the first to apply!
- director of security Chicago, IL
- head of security Chicago, IL
- director of corporate security Chicago, IL
- chief security officer Chicago, IL
- information security compliance analyst Chicago, IL
- senior director information security Chicago, IL
- sr information security engineer Chicago, IL
- information security lead Chicago, IL
- data center security officer Chicago, IL
- entry level information security analyst Chicago, IL

