Grainger

Manager, Information Security – Risk Management

Grainger

full-time

Posted on:

Location Type: Hybrid

Location: Lake ForestIllinoisUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $123,000 - $205,100 per year

Tech Stack

About the role

  • Lead the Information Security Risk team in alignment with security strategy and regulatory or legal obligations.
  • Manage and execute the security risk program in collaboration with Information Security teams and stakeholders.
  • Management, alignment, mapping, continuous improvement of internal security controls framework and control owner relationships in conjunction with the compliance team.
  • Integration expertise of vendor risk reviews, control exceptions, risk assessments, or security control requirement services.
  • Subject Matter Expert to stakeholders and team in relation to the spirit of controls, associated security framework or regulation, and alignment to information security.
  • Ensuring hiring, training, staff development, performance management and annual performance reviews are aligned and effectively executed to continue to grow skills and capabilities in accordance with Grainger’s strategic needs.
  • Monitor external developments that may impact overall risk profiles, including emerging threats, technological developments, regulatory changes, etc.
  • Manage the intake of third parties through the risk evaluation process to determine risk levels and priorities of vendors and mitigating any residual risks and/or risk acceptances.
  • Report key operational, and program metrics designed to provide transparency of key attributes such as compliance readiness, security framework alignment, program maturity and operations.

Requirements

  • Experience in managing regulatory, legal, and/or Information Security frameworks and obligations.
  • Comprehensive understanding of the spirit behind controls and their respective frameworks, regulations, or laws.
  • Experience in working with control owners to establish accountability, awareness, rationale, and relevance.
  • Previous Risk Management experience preferred, with an emphasis on alignment to corporate risk appetite within the Cybersecurity discipline.
  • One or more years of IT people management experience, preferably in Information Security.
  • Written and verbal communication skills.
  • Ability to communicate information security and risk-related concepts to technical and non-technical audiences at various hierarchical levels.
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework.
  • Skills in financial/budget management, scheduling and resource management.
Benefits
  • Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
  • 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
  • 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
  • Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
  • Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.

Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard skills
Information Security frameworksRisk ManagementISO/IEC 27001ITILCOBITNIST 800-53Cybersecurity Frameworksecurity controlsvendor risk reviewsrisk assessments
Soft skills
communication skillsstaff developmentperformance managementcollaborationaccountabilityawarenessrationalerelevancetrainingmonitoring