Information Security & Data Governance Manager

Joe Gibbs Racing, Inc

  • Mooresville, NC
  • 7 days ago

    Highlights

    Position Summary: The Information Security & Data Governance Manager is responsible for protecting JGR''s information assets by leading cybersecurity, data governance, incident response, business continuity, and technology risk management. Reporting to the Director of IT, this role works closely with the Sr Systems Administrator and business leaders to implement and maintain the company''s security program and governance framework.

    Numbers & Facts

    LocationMooresville, NC

    Description

    Position Summary: The Information Security & Data Governance Manager is responsible for protecting JGR''s information assets by leading cybersecurity, data governance, incident response, business continuity, and technology risk management. Reporting to the Director of IT, this role works closely with the Sr Systems Administrator and business leaders to implement and maintain the company''s security program and governance framework.

    This position establishes security policies and standards, manages organizational risk, strengthens identity and access governance, and helps ensure the confidentiality, integrity, and availability of enterprise systems and data while supporting JGR''s business objectives.

    Key Responsibilities

    Cybersecurity Operations: Lead the organization''s cybersecurity program including:

    • Vulnerability management and remediation oversight
    • Security monitoring and threat detection
    • Conditional Access policy design and governance
    • Security audits and compliance reviews
    • Penetration testing coordination and remediation tracking
    • Security awareness and training programs
    • Third-party and vendor security assessments
    • Cybersecurity roadmap development

    Data Governance & Data Security: Establish and maintain governance practices to protect company data assets. Responsibilities include:

    • Ownership of SharePoint and file share access governance
    • Data classification standards and enforcement
    • Microsoft Purview administration and policy management
    • Data retention and records management policies
    • Sensitive data identification and protection controls
    • Access review processes and certifications
    • Least-privilege access model implementation
    • Data governance committee participation and leadership
    • Internal data security policy development

    Incident Response & Business Continuity: Develop and maintain organizational readiness for security and operational incidents. Responsibilities include:

    • Incident Response Plan ownership and maintenance
    • Ransomware response playbook development
    • Security incident investigation and coordination
    • Executive communication procedures during incidents
    • Business Continuity and Disaster Recovery planning support
    • Cybersecurity tabletop exercises
    • Post-incident reviews and corrective action management
    • Coordination with legal, insurance, and external response partners

    Risk Management & Compliance:

    • Lead technology risk identification, assessment, and mitigation efforts
    • Technology risk register ownership
    • Third-party risk management program
    • Cyber insurance compliance requirements
    • Audit preparation and remediation management
    • Security policy development and governance
    • Regulatory and contractual security compliance support
    • Annual security strategy and roadmap development

    Leadership Expectations:

    • Serve as the organization''s security subject matter expert
    • Communicate security risks in business terms
    • Build strong partnerships across departments
    • Drive accountability for security and governance practices
    • Influence decision-making without direct authority
    • Promote a culture of security awareness and responsibility
    • Balance risk management with operational effectiveness

    Required Experience

    • 5-10 years of progressive IT and cybersecurity experience
    • Experience leading security initiatives and programs
    • Experience with Microsoft 365 security technologies
    • Experience developing policies, standards, and governance practices
    • Experience managing security incidents and investigations
    • Strong understanding of risk management frameworks

    Preferred Backgrounds

    • Security Engineer
    • Senior Security Analyst
    • Governance, Risk & Compliance (GRC) Analyst
    • Systems Engineer with significant security responsibilities
    • Infrastructure or Cloud Security professional

    Preferred Certifications

    One or more of the following:

    • CISSP (Certified Information Systems Security Professional)
    • CISM (Certified Information Security Manager)
    • CRISC (Certified in Risk and Information Systems Control)
    • Security+
    • Microsoft Security Certifications
    • Microsoft Purview Certifications
    • Azure Security Certifications

    How To Apply:

    • Please submit your resume and cover letter to careers@joegibbsracing.com with the subject line Information Security & Data Governance Manager.

    Similar Jobs

    See more jobs