Manager, IT Security, Governance, Risk and Compliance

Burlington Stores

Edgewater Park Township (NJ)

On-site

USD 115,000 - 168,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental and vision coverage
401(k) plan
Paid time off and holidays
Associate discount

Job summary

Burlington Stores is seeking a Manager of Governance, Risk and Compliance to lead the GRC program within Information Security. You will oversee risk assessments, policy implementation, and audit readiness while mentoring a security team.

You will collaborate with senior leadership and business units to translate risk into actionable mitigation, monitor regulatory changes, and drive continuous improvement of GRC processes across the enterprise.

Qualifications

  • 8+ years in security governance, risk, or compliance roles.
  • Demonstrated success in leading cross-functional projects.
  • Maintain certifications such as CISM, CISSP, or CISA.

Responsibilities

  • Lead enterprise-wide cybersecurity risk assessments across business units and IT domains.
  • Own risk register accuracy and maintenance with stakeholder input.
  • Define risk tolerance thresholds and translate findings into actionable recommendations.
  • Oversee audits and ensure SOX, PCI, and privacy compliance.
  • Manage policy lifecycle aligned with NIST/PCI DSS and educate staff on security culture.

Skills

Governance
Risk management
Regulatory knowledge
Stakeholder communication
Leadership

Education

Bachelor's degree in Information Systems or related field
Master's degree preferred

Tools

GRC tools

Job description

Position OverviewThe Manager of Governance, Risk and Compliance (GRC) plays a critical mid-level leadership role within the Information Security function, responsible for translating strategy into operational execution across the GRC program. Reporting to the Director of GRC, this role provides daily oversight of analysts and leads, drives process maturity, and ensures consistent delivery of risk, audit, policy, and continuity efforts. The Manager of GRC helps shape the enterprise’s risk posture while mentoring a high-performing team and fostering cross-functional collaboration. This role requires a deep understanding of regulatory frameworks and an ability to communicate complex risk concepts in clear, actionable terms. The ideal candidate will proactively identify control gaps, coordinate effective mitigation, and ensure security efforts remain aligned with evolving business needs.A Day in the LifeEnterprise Cyber Risk Management:Lead enterprise-wide cybersecurity risk assessments across business units and IT domains.Own the accuracy and ongoing maintenance of the enterprise risk register, ensuring it is consistently updated and informed by stakeholder input.Collaborate with business and IT leaders to define and apply enterprise risk tolerance thresholds.Translate technical risk findings into actionable, business-relevant recommendations.Identify and escalate systemic risks that could materially impact operations or compliance.Monitor industry trends, threat intelligence, and regulatory changes to adjust risk posture.Deliver clear, timely risk reports and dashboards to senior leadership and governance bodies.Implement structured risk governance processes, including review cycles and escalation protocols.Implement automated GRC tools and data analytics to improve cybersecurity risk management efficiency and accuracy.Develop KPIs and KRIs for the security organization and maintain tactical and strategic dashboards to monitor risk and compliance efforts.Management & Collaboration:Oversee GRC team operations, assigning work, setting priorities, and ensuring effective collaboration.Partner with senior leadership and business stakeholders to align GRC efforts with enterprise goals.Foster a high-performing, collaborative team culture through coaching, accountability, and career development.Vendor Risk Management:Partner with the procurement and legal teams to integrate cybersecurity function into the overall process, mitigating supply chain risks for the company.Manage third-party risk processes, including assessments and reviews. Continuously identify opportunities for improvement to enhance its effectiveness and efficiencyEscalate high-risk vendor issues to leadership and work with business stakeholders to develop and execute mitigation plans.Oversee monthly reporting on security assessments of AI vendors, provide expert analysis to leadership on AI-related risks and recommend strategic actions to resolve identified issues.Establish and manage a comprehensive set of criteria and assessment questions to support third-party risk management activities.Managed Security Service Provider (MSSP) and Third-Party Security Incidents:Own vendor incident response governance program and playbooks.Ensure vendors provide formal evidence of incident containment and remediation and ensure compliance with security requirements before closing a third incident.Consolidate third party incident and GRC-owned MSSP results into executive dashboards.Embed incident response obligations into contracts and procurement.Audit and Compliance:Oversee internal/external audit readiness and evidence collection.Ensure compliance with SOX, PCI, and privacy frameworks.Serve as audit liaison for the GRC function.Act as the primary contact for internal audit and take ownership of recreating risk and compliance assessment findings.Policy Implementation:Manage the policy lifecycle from creation through enforcement.Ensure policies align with frameworks like NIST and PCI DSS.Ensure the organization adheres to all relevant policies and standards.Cybersecurity Education:Manage company-wide security training programs.Strategically identify education and awareness needs based on enterprise-wide cybersecurity threats and business priorities.Establish metrics to evaluate the success of training initiatives, including trends in knowledge retention, behavior changes, and overall effectiveness of the security culture.Oversee continuous improvement of the training curriculum, ensuring it evolves to address new threats and compliance requirements.You'll Come With8+ years in security governance, risk, or compliance roles.Demonstrated success in leading cross-functional projects.Deep understanding of controls, audits, and frameworks.Maintain relevant certifications such as CISM, CISSP, or CISA.Communicate effectively with technical and non-technical stakeholders.Resolve conflicts and drive consensus across teams.Provided leadership and oversight for a cybersecurity team of 3+ membersMentor team members and model professional behavior.Bachelor's degree in Information Systems, Cybersecurity or related field required; Master's preferred.Target Pay Range: $115,000 – $167,500 annuallyThis position has a target starting salary range of $115,000 – $167,500 annually. Actual pay is determined by a variety of factors, including but not limited to, qualifications, education, job-related skills, relevant experience, and geographic location.#LI-JL2Come join our team. You’re going to like it here!You will enjoy competitive wages, flexible hours, and an associate discount. Burlington’s benefits package includes medical, dental and vision coverage including life and disability insurance. Full-time associates are also eligible for paid time off, paid holidays and a 401(k) plan.We are a rapidly growing brand and provide a variety of training and development opportunities so our associates can grow with us. Our teams work hard and have fun together! Burlington associates make a difference in the lives of customers, colleagues, and the communities where we live and work every day. Burlington Stores, Inc. is an equal opportunity employer committed to workplace diversityIndividual pay decisions will be based on a variety of factors, such as but not limited to, qualifications, education, job-related skills, relevant experience, and geographic location.-
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cybersecurity DevSecOps Engineer
Lead Cybersecurity DevSecOps Engineer

Burlington Stores • Edgewater Park Township (NJ)

On-site
USD 135,000 - 195,000
Associate discount
401(k) plan
Paid time off
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Manager, Linux Platform
Manager, Linux Platform

Burlington Stores • Edgewater Park Township (NJ)

On-site
USD 115,000 - 150,000
Competitive wages
Associate discount
Benefits package including medical, d
+1
Senior DevSecOps Architect — Hybrid Secure Delivery
Senior DevSecOps Architect — Hybrid Secure Delivery

Burlington Stores, Inc. • Beverly (NJ)

On-site
Director, Store Technology Operations & Deployment
Director, Store Technology Operations & Deployment

Burlington Stores • Edgewater Park Township (NJ)

On-site
USD 135,000 - 175,000
Associate discount
Competitive wages
Flexible hours
+5
Senior Analyst, Customer Experience Reporting & Analytics
Senior Analyst, Customer Experience Reporting & Analytics

Burlington Stores • Burlington (NJ)

On-site
USD 80,000 - 105,000
Associate discount
Flexible hours
Competitive wages
BCDR Program Lead - Strategy, Testing & Recovery
BCDR Program Lead - Strategy, Testing & Recovery

Burlington Stores, Inc. • Beverly (NJ)

On-site
USD 95,000 - 150,000
Competitive wages
Flexible hours
Associate discount
+3
Senior Linux Platform Engineer
Senior Linux Platform Engineer

Burlington Stores • Edgewater Park Township (NJ)

On-site
USD 115,000 - 150,000
Medical, dental, and vision coverage
401(k) plan
Paid time off
+1
Manager, Linux Platform
Manager, Linux Platform

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental and vision insurance
Life and disability insurance
401(k) plan
+2
Regional HR Manager
Regional HR Manager

Burlington Stores • Ontario (CA)

On-site
USD 121,000 - 149,000
Associate discount
Medical insurance
Dental insurance
+6