Jobs and Careers
CE

Manager - Cybersecurity GRC & Data Privacy

Central Hudson
Poughkeepsie, United Statesfull_timeVerifiedPosted 8 Nov 2024
💰 $136,800/yr

About the role

Benefits:

  • Competitive compensation

  • Medical, Dental, and Vision insurance

  • 401(k) Retirement Savings Plan with substantial company match

  • Life and Travel Insurance

  • Tuition Assistance

  • Wellness Reimbursement Program

  • Paid Holidays and Vacation

What is a Manager - Cybersecurity Governance, Risk, & Compliance (GRC) & Data Privacy?

The Cybersecurity GRC & Data Privacy Manager is responsible for ensuring the organization complies with relevant regulatory, privacy, and security frameworks. This role oversees governance, risk management, and compliance (GRC) activities, while also ensuring data privacy policies and practices align with industry standards and legal requirements. The manager will collaborate across departments to identify risks, implement security controls, and foster a culture of compliance.

What does a Manager - Cybersecurity GRC & Data Privacy do?

The Cybersecurity GRC & Data Privacy Manager is responsible for the following:

Overall:

  • Aides in the development of the Cybersecurity roadmap and strategy

  • Responsible for the cybersecurity risk register

  • Responsible for GRC & data privacy programs, roadmaps, and operations

  • Responsible for creation, maintenance, and roadmap for all cybersecurity policies and process library

  • Responsible for records and information management

  • Responsible for SOX controls and audits

  • Communicates and ensures information security programs, and other assigned frameworks are in compliance with regulatory applicable laws, policies, organizational security policies and standards.

  • Lead efforts to establish and implement integrated cyber security and risk management solutions.

  • Aligns cyber strategies with the strategic direction of the organization.

  • Develop and monitor a strategic, comprehensive cyber security and risk management program (including strategy, policies, standards, processes, and guidelines) to ensure the integrity and confidentiality of information owned, controlled or processed by the organization.

  • Lead cross-functional teams to enhance the organization’s security posture and ensure compliance with legal and regulatory standards

  • Act as a point of contact for regulatory authorities and external stakeholders on cybersecurity and data privacy matters

  • Collaborate with IT, legal, and business units to ensure proper implementation of security controls and data privacy measures

  • Stay up to date on global data privacy regulations and GRC strategies and ensure the organization adapts to changes

  • Provides storm/emergency response support

Governance, Risk, and Compliance:

  • Develop, implement, and maintain GRC policies and programs, ensuring compliance with regulations (e.g., ISO 27001, NIST, NERC, GDPR)

  • Establishes information security baseline and advances information security maturity model (e.g. C2M2, NIST)

  • Conduct risk assessments to identify security gaps and vulnerabilities across the organization

  • Establish and enforce security frameworks, standards, and best practices

  • Collaborate with business units to ensure adherence to cybersecurity policies and practices

  • Oversee third-party risk management, ensuring vendors comply with security and privacy requirements

  • Lead audits (internal and external) and manage the remediation of non-compliant findings

  • Responsible for overall compliance of Cybersecurity program, remediation of assessment findings, and risk reduction strategy

  • Responsible for the cybersecurity risk register

  • Track and report on key cybersecurity and compliance metrics for executive leadership.

Data Privacy:

  • Oversee the development and implementation of data privacy policies and procedures to ensure compliance with relevant data protection laws

  • Ensure the proper handling of personal data and responding to data subject requests

  • Manage data privacy risk assessments and data protection impact assessments

  • Provide guidance on data privacy issues related to new projects, technologies, and partnerships

What does it take to be a Manager - Cybersecurity GRC & Data Privacy?

Required:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology or related field of study and 5 years of experience in Cybersecurity, GRC, data privacy or related. In lieu of a bachelor’s degree, an associate’s

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Central Hudson

View company profile →