Encuentre un trabajo que le interese. Trabaje con personas
que se preocupan.

Mgr GRC Security - Remote

Detalles del trabajo

Recomendación de trabajo:
170540
Ubicación:
Providence, RI 02908
Flexibilidad de ubicación:
Remoto
Categoría:
IT
Tipo de Empleo:
Tiempo completo
Estado Laboral:
Exempt
Fecha prevista de cierre:
1 de julio de 2025
Base salarial
Yearly
Rango salarial
$114300.00 - $220500.00 Annually ($54.95 - $106.01 Hourly)
Otra compensación
Bonus Eligible
Marca
UNFI

PURPOSE:

The Manager, Security GRC is responsible for working across IT, with internal audit, external audit and other departments to develop a comprehensive IT compliance program. This role is responsible for coordinating and reporting on IT portions of internal and external audits, review findings and work with the impacted areas to develop, track, and complete remediation plans.

This position will also have responsibility for maintaining an access certification process in order to validate that access is assigned appropriately per corporate policies. The position will provide governance oversite to the IT Identity and Access Management team to ensure that appropriate processes are followed to protect the security and privacy of employee and customer information.

The Manager will provide management and direction to GRC team members. This position also regularly contributes to the identification and/or delivery of related functional area and process improvements, tool implementation, and automation to streamline the delivery of compliance activities.

JOB RESPONSIBILITIES:

  • Manage SOX, HIPAA, Internal and External audit compliance efforts in partnership with internal and external auditors.
  • Provide guidance and training in constructing controls and operating procedures. Provide assistance on remediation and response to compliance incidents.
  • Perform monthly access review across applications to help better understand where unauthorized access is granted and can be removed
  • Creates and maintains control matrix to address all corporate and regulatory compliance requirements.
  • Tracks and coordinates corporate, legal and regulatory IT compliance activities.
  • Establish and oversee formal risk analysis and self-assessments program for various Technology Services systems and processes.
  • Collaborates with Internal Audit, Corporate Compliance, Office of General Counsel and Enterprise Risk Management to remediate new and outstanding issues; track security-related issues in the electronic GRC system.
  • Works with all IT process owners to ensure effective risk and control management.
  • Promote and monitor the enterprise cyber security awareness program; ensure compliance across the organization.
  • Interfaces and coordinates with internal and external auditors and IT process owners to ensure timely delivery of audit requirements. Creates management responses to findings and coordinates in a timely manner with senior leadership.
  • Works with process owners to plan and track delivery of audit finding remediation.
  • Maintains expertise on security trends through training, research and development in order to mitigate potential security exposures.
  • Coordinate responses to customer / vendor security questionnaires.
  • In collaboration with the Director of Security GRC, develops the Identity and Access Governance (IAG) function and institute consistent IAG processes across the enterprise.
  • Manages team building and self-driven skill development activities through active participation (knowledge sharing, driving initiatives) in appropriate training and mentoring programs, and leads peer review feedback efforts to grow and develop analyst skills.
  • Leads interaction with business owners, subject matter experts and project team members, collaborating to identify, develop, and document potential business and technology solutions.
  • Establishes and builds critical relationships with senior business management, unit leadership, extended team
  • members, and other stakeholders across the functional domains.
  • Identifies opportunities and provides solutions for improvement to compliance processes, such as automation, as well IT processes.
  • Supervises and provides assistance to internal and external auditors.
  • Participates in department recruiting efforts as directed by management.
  • Make recommendations to regarding hiring, terminations, layoffs, performance, promotions and salary increases.

JOB REQUIREMENTS:

Education/Certification:

  • Bachelor's degree in Computer Information Systems, Information Technology, or related field is required
  • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications preferred
  • PCI Certified Internal Security Assessor (ISA) preferred

Experience:

  • 8-10 plus years of experience in IT risk and compliance, IT governance, IT auditing or IT related field required
  • Big 4 accounting firm experience is a plus.

Knowledge:

  • Must possess a high level of working knowledge in the following areas: operating systems (ZOS, UNIX, Linux, Windows), application development (COBOL, C, Java, PL/SQL, Visual Basic.net), , operations (batch processing, monitoring) networking and telecommunications, database (Oracle, DB2, SQL Server, etc), logical security (Active Directory, Unix, Mainframe -Top Secret/ACF2, Internet/Intranet), and web services
  • In-Depth knowledge of internal control concepts, principles, risk analysis, Sarbanes-Oxley Compliance, PCI Compliance, HIPAA, Privacy, process improvement and techniques, including COSO and COBIT frameworks

Skills/Abilities:

  • Must be able to work with all levels of individuals within the organization
  • Requires excellent analytical and communications skills to learn customer business objectives, evaluate risks and plan, supervise and control compliance and other activities
  • Must have excellent verbal, written and presentation skills, a high degree of personal integrity and ability to work under limited supervision. Supervisory skills, the ability to work well with others in a team environment and the ability to produce results through others is required
  • Must be capable of working under minimum supervision, planning and conducting compliance assignments and directing the activities of staff as required
  • Requires excellent analytical and communications skills to learn business objectives, evaluate risks, and controls and accurately document and support work performed, and conclusions reached
  • Must have excellent written and verbal communication skills, a high degree of personal integrity, attention to detail and strong investigative skills
  • Must be able to work in a fast-paced environment and manage multiple projects concurrently
  • Demonstrate advanced mentoring, teaching, and peer guidance skills
  • Good judgment is required for this position as there may be times when direct supervision may not be immediately available.

PHYSICAL ENVIRONMENT/ DEMANDS:

  • Some travel may be required
  • Incumbent may sit for long periods of time at desk or computer terminal

The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location.

All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, or protected veteran status. UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. - M/F/Veteran/Disability. VEVRAA Federal Contractor.

Empresa:
United Natural Foods Inc.

Indemnización laboral:

UNFI prevé pagar el salario mencionado (o dentro del rango salarial mencionado) para este puesto. El salario real, según corresponda, dependerá de ciertos factores; incluidos, entre otros, educación, experiencia laboral, formación y cualesquier requisitos previstos en los convenios laborales colectivos aplicables. UNFI está comprometida con la transparencia salarial, en virtud de la legislación estatal y local aplicable.

Beneficios:

En el caso de los puestos en Washington (o los puestos en los que se trabaje remotamente desde Washington), haga clic AQUÍ para conocer los detalles sobre el pago de licencias laborales específicas para Washington.

Los candidatos contratados para este puesto también serán elegibles para participar en los siguientes programas de beneficios: licencias pagadas; licencias por enfermedad; pago de vacaciones y licencia por maternidad/paternidad; Programa 401K; póliza con cobertura médica, odontológica, oftalmológica y seguro de vida, accidentes, muerte y pérdida de miembros; programa de seguro a corto y largo plazo por discapacidad; cuenta con gastos flexibles, cuenta de ahorro sanitario o ambas; sujeto al cumplimiento de los requisitos de elegibilidad y los términos y condiciones de dichos programas, y sujeto a cualquier requisito previsto en los convenios laborales colectivos aplicables.

Solamente puestos de Ventas: en el caso de los puestos de ventas con base en comisiones, el rango mencionado representa un estimado de la compensación potencial por comisiones durante el primer año de un asociado; pero UNFI ofrece un mínimo de $680 a la semana para el periodo inicial. Después del periodo inicial, por tratarse de un puesto basado totalmente en comisiones, no hay un salario fijo. Los planes de comisiones de UNFI no tienen tope y las ganancias promedio dependen del territorio y de las ventas logradas, entre otros factores.

Las políticas de UNFI referentes a la compensación, los beneficios y las licencias pagadas están sujetas a cambios por decisión exclusiva de la compañía y acorde a la legislación aplicable. El aviso de empleo disponible no debe interpretarse como una oferta de empleo con ciertos términos, así como tampoco debe interpretarse como un mínimo garantizado.

Las solicitudes calificadas con antecedentes de arresto o condena se considerarán para empleo de acuerdo con la Ordenanza de Oportunidades Justas del Condado de Los Ángeles y la Ley de California Fair Chance Act.

Conoce más sobre nuestras marcas:

Unete a Nuestra Red De Talento