Sr. Manager, Governance, Risk, & Compliance
SpartanNashAbout the role
At SpartanNash, we deliver the ingredients for a better life through customer-focused innovation. We do this for our supply chain customers and U.S. military commissaries, retail store guests and, most importantly, our Associates. In fact, we see a day when each will say, “I can’t live without them.”
Our SpartanNash family of Associates is 20,000 strong, ranging from bakery managers to order selectors; from IT developers to vice presidents of finance; from HR Business Partners to export specialists. Each of them plays an integral role in SpartanNash’s People First culture, Operational Excellence and Insights that Drive Solutions. Ready to contribute to the success of our food solutions company? Apply now!
Location:
850 76th Street S.W. - Byron Center, Michigan 49315Job Description:
Position Summary:
This role is responsible for supporting the security direction of the business and elevating the company’s security posture. The role oversees the business’ security requirements and obligations mandated by standards and regulations such as the Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley Act (SOX), Health Information Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS).
Here's what you’ll do:
Lead a team of GRC Analysts to Conduct enterprise-wide, ongoing risk analysis in tandem with compliance and security and maintain oversight in a GRC-related platform.
Identify strengths and weaknesses in the security program as they relate to privacy, security, business resiliency and compliance frameworks.
Maintain strong oversight of third parties, vendors, and partners to safeguard against undue risk presented by external entities. Escalate to security management and business unit leads when points of weakness are discovered.
Analyze findings, and document, recommend and report program gaps to security leadership.
Work in tandem with security and audit leadership to perform ongoing security program assessments and participate in the creation of annual strategic technology and budgetary directives.
Monitor current and proposed security changes impacting regulatory, privacy and security industry best practice guidance.
Support audit practices and processes and work with the IT organization to ensure findings are remediated.
Work closely with legal, audit, and security leadership to ensure cybersecurity policies and practices are created, documented, implemented, measured and aligned within an appropriate level of risk.
Create, implement and measure procedures to support Cybersecurity policies and practices.
Enforce a strong security culture mindset set forth by risk management, ensuring uniformity across technical teams, business units, and employees.
All other duties as assigned
Here’s what you’ll need:
At least 8 years of IT or cybersecurity experience (or IT coupled with cybersecurity), with at least two years in an operationally focused IT Assurance or security practitioner role.
Experience with Payment Card Industry (PCI) assessments, PCI-P certification preferred.
Strong experience with NIST CSF and Risk Management Framework
Skilled at working with diverse teams and promoting enterprise-wide risk management rigor and a security-first culture.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s