Skip to content

Open nowPosted 80 days ago

Director of IT Risk and Compliance

Workable (global search)108,016 open roles

Where
Wilmington, NC, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector of IT Risk and ComplianceWorkable (global search) · Wilmington, NC, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 80 days ago

Workable (global search) median: 7 days open

The posting

Luxury. Innovation. Opportunity.

At REEDS Jewelers, we bring together the timeless values with the energy and innovation of a modern luxury retailer. For 80 years, we’ve built a legacy of trust, exceptional customer service, and curated fine jewelry- offering our clients an elevated experience both in-store and online. We believe every milestone deserves to be marked with elegance, and every moment honored with meaning. As one of the nation’s largest family-owned jewelers, we are proud to pair a rich legacy with a modern vision for the future of luxury retail.

What sets REEDS apart is our unwavering commitment to people and progress. We stay true to our roots while constantly evolving, embracing new technology, premium brands, and forward-thinking practices to lead in the world of luxury retail. Here, you’ll find more than a job, you’ll find a career with purpose, growth, and lasting impact.

Overview

The Director of IT Risk and Compliance will design, implement, and oversee the enterprise-wide IT governance, procurement, risk management, and compliance (GRC) framework for REEDS Jewelers. This strategic leader will ensure that our retail stores, corporate infrastructure, and e-commerce platform are secure, resilient, and fully compliant with all applicable regulatory, financial, and industry standards.

Additionally, this role serves as a critical point of escalation for specialized financial intelligence. The Director will independently investigate, troubleshoot, and formally file Suspicious Activity Reports (SARs) to mitigate risks associated with multi-channel point-of-sale fraud, e-commerce identity theft, credit underwriting anomalies, and anti-money laundering (AML) compliance.

Key Responsibilities

1. Financial Intelligence, Fraud Investigation & SAR Filing

  • Incident Investigation: Lead technical forensic investigations into complex corporate fraud including: e-commerce account takeovers, gift card manipulation, and anomalous transactional behaviors across point-of-sale (POS) and omni-channel credit integrations.
  • SAR Management & Filing: Own the end-to-end process of troubleshooting suspicious patterns, compiling narrative reports, and formally filing Suspicious Activity Reports (SARs) with the Financial Crimes Enforcement Network (FinCEN) in strict compliance with Bank Secrecy Act (BSA) rules for luxury retailers.
  • Executive Briefings: Provide the CIO and executive leadership with confidential intelligence briefs regarding internal or external fraud investigations, exposure assessments, and structural vulnerabilities.

2. Regulatory & Industry Compliance

  • PCI-DSS Management: Own end-to-end compliance for PCI-DSS across all digital checkout touchpoints, POS systems, and multi-channel payment integrations.
  • Financial & Corporate Governance: Manage and test IT General Controls (ITGC) to support Sarbanes-Oxley (SOX) audit readiness, ensuring tight segregation of duties (SoD) across financial and inventory systems (e.g., enterprise ERP and legacy AS400 databases).
  • Data Privacy & AML Regulations: Monitor and enforce compliance with data privacy frameworks (including CCPA/CPRA) and specialized AML regulations impacting loyalty databases, high-value cash/financing transactions, and digital marketing.

3. Risk Management & Third-Party Governance

  • IT Enterprise Risk Register: Maintain and update the IT risk register, translating technical security findings and transaction fraud vectors into quantifiable business risks.
  • Technology Vendor Risk Management (VRM): Architect and execute a robust third-party risk assessment program for SaaS providers, financial partners, supply chain logistics, and AI/analytics vendors.

4. IT Audit Coordination & Policy Lifecycle

  • IT Audit Liaison: Act as the primary point of contact for internal and external IT auditors, coordinating evidence collection and owning the tracking and remediation of all audit findings.
  • IT Policy Enforcement: Develop, update, and manage the lifecycle of corporate information security policies aligned with the NIST Cybersecurity Framework or ISO 27001.

Requirements

Required Qualifications & Experience

  • Experience: 3 to 5 years of progressive experience in IT audit, information security governance, or IT risk management.
  • Industry Background: Proven experience in a multi-channel retail, e-commerce, banking, or consumer-facing environment with heavy transactional volumes.
  • Framework Expertise: Deep working knowledge of American Disabilities Act (ADA), Data Protection Compliance, PCI-DSS, SOX, and consumer privacy laws.
  • Education: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Business Administration, or a related field.

Mandated Professional Certifications

Candidates must possess at least two of the following certifications. Given the expanded investigative mandate, a combination of a technical security certification and a fraud/investigative certification is highly preferred:

  • CISA (Certified Information Systems Auditor): Highly valued for leading internal audit readiness and ITGC/SOX evaluations.
  • CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional): Required to demonstrate elite capability in managing enterprise security governance and risk.
  • CRISC (Certified in Risk and Information Systems Control): Preferred for candidates specializing in designing and executing enterprise-level IT risk registers.

Benefits

REEDS Jewelers offers a comprehensive compensation program, merchandise discounts, 401(k), and paid time off. Full-time team members are also eligible for our benefits program including health/dental/life/LTD insurance, and more!

REEDS Jewelers is an Equal Opportunity Employer. We value the diversity of our team, and employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law. REEDS provides a smoke and drug-free environment.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.