Enable job alerts via email!

Sr Manager, InfoSec Compliance & Governance

Gap Inc.

United States

Remote

USD 80,000 - 120,000

Full time

10 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Sr Mgr Infosec Compliance Governance to ensure compliance standards and protect sensitive data across international operations. This pivotal role involves collaborating with technical experts and legal teams to drive compliance initiatives, develop IT security policies, and manage risk assessments. The ideal candidate will possess strong analytical skills and experience in a global retail environment, making a significant impact on the organization's compliance posture. Join a dynamic team where your expertise will help shape the future of data security and compliance in a rapidly evolving landscape.

Qualifications

  • 6+ years of experience in IT security compliance in a global retail environment.
  • Strong knowledge of compliance standards and risk management frameworks.

Responsibilities

  • Drive implementation of compliance programs and conduct audits.
  • Develop training programs to educate employees on security compliance.

Skills

GDPR
CCPA
PCI DSS
SOX
NIST
ISO 27001
AWS
Azure
Google Cloud
GRC platforms

Education

CISA
CISM
CISSP

Tools

FW/WAF
SIEM
DLP
IAM

Job description

About the Role

Role Overview: As a Sr Mgr Infosec Compliance Governance, you will play a critical role in ensuring our organization meets compliance standards and protects sensitive data across our international operations. You will work closely with technical experts, legal counsel, and other global stakeholders, applying analytical and interpersonal skills to bridge operational and technical gaps. You will deliver program activities on-time for successful assessments and audits.

Key Responsibilities:
  1. Compliance Management: Drive implementation and maintenance of our compliance programs across relevant regulatory standards (e.g., GDPR, CCPA, PCI DSS, SOX). Conduct audits and assessments to ensure compliance with both internal and external controls. Provide support for compliance activities and ensure compliance program activities are occurring as scheduled and effectively managed.
  2. Policy Development: Draft, update, and enforce IT security policies, procedures, and guidelines in line with global and regional regulations. Collaborate with business units to ensure policies are effectively communicated and implemented.
  3. Technical Control Implementation: Work with IT and development teams to implement and validate technical security controls. Evaluate technical solutions for compliance with regulatory requirements. Develop and maintain control testing procedures and schedules.
  4. Risk Management: Identify, assess, and mitigate IT security risks for infrastructure and systems.
  5. Third Party Risk Management: Develop and drive vendor security assessment processes. Review vendor security documentation and identify potential risks. Collaborate with procurement and legal teams on vendor contracts and security requirements.
  6. Collaboration: Liaise effectively with both technical teams (e.g., IT operations, cybersecurity), legal (e.g., compliance officers, external counsel), and business teams to align compliance initiatives. Direct contractors, personnel, leaders, and executives to streamline program activities in alignment with their own goals.
  7. Training & Awareness: Develop and deliver training programs to educate employees on security compliance and best practices.
  8. Documentation: Maintain accurate and up-to-date records of compliance activities, audits, and risk assessments.
  9. Continuous Improvement: Monitor and evaluate the effectiveness of compliance programs and recommend enhancements. Ensure findings or other corrective actions are closed within expectations.
  10. Technical Communication: Communicate technical and regulatory specifications and requirements to non-technical personnel in a clear and understandable manner.
What You'll Do

Qualifications:

  • Experience: 6+ years of experience in IT security compliance, preferably in a global retail or eCommerce environment, with a proven track record of creating and reviewing compliance policies.
  • Technical Skills:
    • Strong knowledge of compliance standards like GDPR, CCPA, PCI DSS, SWIFT, SOX.
    • Familiarity with risk management frameworks such as NIST, ISO 27001.
    • Experience with cloud security platforms (e.g., AWS, Azure, Google Cloud).
    • Proficiency in security tools and technologies (e.g., FW/WAF, SIEM, DLP, IAM).
    • Familiarity with engineering development toolchains and capabilities.
    • Experience with GRC platforms and processes.
  • Soft Skills:
    • Proactive problem-solver who can identify compliance gaps before they become issues.
    • Ability to navigate matrix organizations fluently.
    • Exceptional critical thinking and problem-solving abilities to analyze complex compliance issues and propose effective solutions.
    • Strong interpersonal and communication skills to build relationships with diverse stakeholders across technical, legal, and business audiences.
    • Ability to build relationships across departments and drive consensus.
    • Adaptability and cultural sensitivity, fostering collaboration in a global environment.
    • Proactive approach to identifying risks and opportunities for improvement.
    • Attention to detail with excellent organizational and time-management skills.
    • Ability to communicate technical specifications and compliance requirements to non-technical personnel in a clear and understandable manner.
Who You Are
  • Certifications: CISA, CISM, CISSP, or equivalent.
  • Additional Experience:
    • Experience with cloud security platforms (e.g., AWS, Azure, Google Cloud).
    • Knowledge of Japanese IT compliance standards is a plus.
    • Experience with data privacy regulations and frameworks (e.g., CCPA, GDPR, ISO 27701).
    • Familiarity with DevSecOps practices and tools.
About the company

Gap Inc. is the largest specialty retailer in the United States, and is 3rd in total international locations, behind Inditex Group and H&M. As of September 2008, the company has approximately 135,000 employees and operates 3,727 stores worldwide, of which 2,406 are located in the U.S.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Manager, InfoSec Compliance & Governance

Gap Inc.

Remote

USD 80,000 - 120,000

5 days ago
Be an early applicant