
Manager, Information Security – Risk Management
Grainger
full-time
Posted on:
Location Type: Hybrid
Location: Lake Forest • Illinois • United States
Visit company websiteExplore more
Salary
💰 $123,000 - $205,100 per year
Tech Stack
About the role
- Lead the Information Security Risk team in alignment with security strategy and regulatory or legal obligations.
- Manage and execute the security risk program in collaboration with Information Security teams and stakeholders.
- Management, alignment, mapping, continuous improvement of internal security controls framework and control owner relationships in conjunction with the compliance team.
- Integration expertise of vendor risk reviews, control exceptions, risk assessments, or security control requirement services.
- Subject Matter Expert to stakeholders and team in relation to the spirit of controls, associated security framework or regulation, and alignment to information security.
- Ensuring hiring, training, staff development, performance management and annual performance reviews are aligned and effectively executed to continue to grow skills and capabilities in accordance with Grainger’s strategic needs.
- Monitor external developments that may impact overall risk profiles, including emerging threats, technological developments, regulatory changes, etc.
- Manage the intake of third parties through the risk evaluation process to determine risk levels and priorities of vendors and mitigating any residual risks and/or risk acceptances.
- Report key operational, and program metrics designed to provide transparency of key attributes such as compliance readiness, security framework alignment, program maturity and operations.
Requirements
- Experience in managing regulatory, legal, and/or Information Security frameworks and obligations.
- Comprehensive understanding of the spirit behind controls and their respective frameworks, regulations, or laws.
- Experience in working with control owners to establish accountability, awareness, rationale, and relevance.
- Previous Risk Management experience preferred, with an emphasis on alignment to corporate risk appetite within the Cybersecurity discipline.
- One or more years of IT people management experience, preferably in Information Security.
- Written and verbal communication skills.
- Ability to communicate information security and risk-related concepts to technical and non-technical audiences at various hierarchical levels.
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework.
- Skills in financial/budget management, scheduling and resource management.
Benefits
- Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
- 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
- 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
- Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
- Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Information Security frameworksRisk ManagementISO/IEC 27001ITILCOBITNIST 800-53Cybersecurity Frameworksecurity controlsvendor risk reviewsrisk assessments
Soft skills
communication skillsstaff developmentperformance managementcollaborationaccountabilityawarenessrationalerelevancetrainingmonitoring