Risk and Compliance Manager
We continually strive for a workforce that reflects the growing diversity within the State of Illinois. A variety of employee backgrounds, perspectives, ideas and experiences are crucial to our ability to most effectively serve the public. Bilingual skills welcome.
The State of Illinois is committed to working with and providing reasonable accommodations to people with disabilities. Further, federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job, interview for a job, or for any other activity related to the hiring process. Examples of reasonable accommodation include, but are not limited to, making a change to the application process (if possible), providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. To be provided a Reasonable Accommodation during the hiring process, you will need to provide a certification of disability from a physician, psychiatrist, school official or an Illinois Department of Human Services (DHS) Division of Rehabilitation Services (DRS) Vocational Rehabilitation (VR) Counselor. Supporting documentation should be uploaded under My Documents ? Additional Documents section for each application. Any questions on Reasonable Accommodations can be directed to Central Management Services Disability Resource Center at CMS.DisabilityResCen@illinois.gov or call (217) 524-7514 for further information and to request or discuss an accommodation.
The State of Illinois does not provide sponsorship for employment visa status (e.g. H-1B visa status), nor is the State able to provide extensions of optional practical training (OPT) under the STEM-designated degree program for F-1 students. To be considered for permanent employment with the State of Illinois, applicants must be currently authorized to work in the United States on a full-time basis. In compliance with the Illinois Equal Pay Act, 820 ILCS 112/1 et seq., the State does not seek, request, or require a job applicant's wage or salary history. Employment decisions are not made based on an applicant's wage or salary history. To that end, please do not include wage or salary information in your resume or other profile or application materials.
Date: Jul 23, 2026 Location: Springfield, IL, US, 62704 Job Requisition ID: 57682 Agency: Board of Elections Closing Date/Time: Thursday, August 6th, 2026 at 11:59 p.m. Anticipated Starting Salary: $8,334 - $10,834 per month Full Range: $8,334 - $12,917 per month County: Sangamon Number of Vacancies: 1 FLSA Status: Exempt The SBE is a non-code agency. All applicants who want to be considered for this position MUST apply electronically through the illinois.jobs2web.com website. State of Illinois employees should click the link near the top left to apply through the SuccessFactors employee career portal. Applications submitted via email or any paper manner (mail, fax, hand delivery) will not be considered.
As a State of Illinois employee, you receive a comprehensive benefits package including: Competitive Group Insurance benefits including health, life, dental and vision plans Flexible work schedules (when available and dependent upon position) 10 -25 days of paid vacation time annually (10 days for first year of state employment) 12 days of paid sick time annually which carryover year to year 3 paid personal business days per year 13 paid holidays per year 12 weeks of paid parental leave Pension plan through the State Employees Retirement System Deferred Compensation Program voluntary supplemental retirement plan Optional pre-tax programs -Medical Care Assistance Plan (MCAP) & Dependent Care Assistant Plan (DCAP) Tuition Reimbursement Program and Federal Public Service Loan Forgiveness Program eligibility For more information regarding State of Illinois Benefits follow this link: Work Hours: 8:00 - 4:30 PM Monday - Friday Work Location: 2329 S. MacArthur Blvd, Springfield IL 62704 Agency Contact: dmartinez@elections.il.gov Posting Group: Science, Technology, Engineering and Mathmatics ****A RESUME IS REQUIRED FOR THIS JOB POSTING**** Please attach a DETAILED Resume/Curriculum Vitae (CV), a copy of your transcripts or diploma for all degrees earned, and a copy of any applicable professional licensures to the MY DOCUMENTS section of your application.
Why Work for Illinois? Working with the State of Illinois is a testament to the values of compassion, equity, and dedication that define our state. Whether you're helping to improve schools, protect our natural resources, or support families in need, you're part of something biggersomething that touches the lives of every person who calls Illinois home. No matter what state career you're looking for, we offer jobs that fit your life and your scheduleflexible jobs that provide the gold standard of benefits. Our employees can take advantage of various avenues to advance their careers and realize their dreams. Our top-tier benefits and great retirement packages can help you build a rewarding career and lasting future with the State of Illinois.
Functional Statement
Reporting to the Chief Information Security Officer (CISO), the Risk & Compliance Manager is responsible for:
- Designing, implementing, and leading a modern enterprise cybersecurity Governance, Risk, Compliance (GRC) program;
- Ensuring continuous improvements of governance, risk, and compliance capabilities;
- Ensuring cybersecurity risk is identified, measured, clearly understood, and managed in alignment with adopted frameworks, agency priorities, regulatory requirements, and overall technology strategy;
- Continuously monitor cybersecurity risk posture, perform gap analysis and provide recommendations for compensating technical, administrative, and physical controls;
- Tracking the agency's alignment to information security standards;
- Collaborating with agency stakeholders to develop prescriptive guidance to reduce risk;
- Reviewing policies, standards, procedures, controls documentation, and audit results;
- Managing third-party risk by maintaining an inventory of all technology providers and service organizations as well as performing continuous security posture monitoring;
- Overseeing the agency's security awareness program.
Essential Functions
The Risk & Compliance Manager will:
- Develop and implement risk management plans and processes that are aligned to business objectives and security requirements.
- Conduct third-party service organization risk assessments to ensure supply chain risk is managed throughout the business relationship lifecycle.
- Assist with the research, creation, maintenance, implementation and communication of Information Security policies, standards, controls, and procedures documentation.
- Develop and mature the agency's security awareness program.
- Continue education by attending training, seminars, conferences, and obtaining industry certifications.
Minimum Qualifications
The Risk & Compliance Manager must:
- Have a Bachelor's degree in a Cybersecurity or Information Technology field, and a minimum of 10 years in Information Technology roles including 5 years of combined professional experience in information security and risk management.
- Have advanced knowledge in information security technologies, design, and architecture in on-premises and cloud hosted environments.
- Have experience with the selection, implementation, and management of third-party GRC, exposure management, and awareness platforms.
- Have a solid understanding of cyber risk management, strategy, and security frameworks.
- Have excellent analytical and planning skills and be highly organized and detail oriented.
- Be able to write and communicate effectively with both technical and non-technical audiences.
- Be comfortable presenting to executive leadership.
- Be able to take unpopular positions when necessary to ensure risk is fully and accurately communicated to agency leadership.
- Possess the following professional certifications: ISACA Certified in Risk and Information Systems Control (CRISC), ISC2 Certified Information Systems Security Professional (CISSP), ISC2 Certified Cloud Security Professional (CCSP).
Preferred Qualifications
The Risk & Compliance Manager should also:
- Have the following professional certifications: EC Council Certified Ethical Hacker (CEH), CompTIA Project+, CompTIA Cloud+, ISC2 Certified in Governance, Risk and Compliance (CGRC), CompTIA Network+, COBIT: Control Objectives for Information and Related Technology, ITIL: Information Technology Infrastructure Library.
The State Board of Elections welcomes all and promotes workplace diversity. It is our individual traits, character, and experiences that make each of us special and unique. It is only when we bring that individualism together and work as a diverse team that we thrive. There is no place for discrimination based on race, religion, culture, sexual identity or orientation, age, or disability at the State Board of Elections.
APPLICATION INSTRUCTIONS Use the "Apply" button at the top right or bottom right of this