Job Closed
This listing is no longer active.
YOU LIVE AND BREATHE SPORTS. SO DO WE.
Senior Manager, Information Security Risk Management
Location
United States
Posted
84 days ago
Salary
$95.2K - $158.8K / year
Seniority
Senior
Job Description
Senior Manager, Information Security Risk Management
DICK'S Sporting Goods
• Build and lead a high-performing GRC/risk team (analysts, engineers, control owners). • Own the selection, implementation, configuration, and continuous improvement of the GRC platform (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate, MetricStream, similar). • Establish a risk-based control testing and continuous control monitoring (CCM) program. • Design, implement, and mature an enterprise Information Security Risk Management (ISRM) program aligned to business strategy and regulatory requirements. • Act as a trusted advisor to senior leaders on risk appetite, emerging risks, and investment trade-offs. • Coordinate audit readiness and responses (internal audit, external audit, regulatory inquiries); ensure defensible evidence management.
Job Requirements
- 7-10 years progressive experience in Information Security, Risk, or Audit with 3–5+ years leading teams and/or owning a GRC platform.
- Bachelor's Degree: Information Systems, Computer Science, Cybersecurity, or related; or equivalent experience.
- Strong knowledge of risk and control frameworks and regulations: NIST CSF/800-53, ISO 27001, SOC 2, SOX/ITGC, PCI DSS, HIPAA, CIS, and data protection/privacy (e.g., GDPR, CCPA/CPRA).
- Hands-on experience designing automated workflows, building dashboards, and integrating GRC with IT/security tooling.
- Security or audit certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CISA.
- Experience with risk quantification approaches (e.g., FAIR) and board-level reporting.
- Background in cloud and modern engineering environments (AWS/Azure/GCP, DevSecOps, SaaS).
Benefits
- Health insurance
- 401(k) matching
- Paid time off
- Professional development opportunities
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Implement, maintain, and assess security controls for Azure and hybrid enterprise systems in accordance with organizational policies and applicable cybersecurity standards • Support security compliance and authorization activities, including preparation, review, and maintenance of required security documentation and artifacts • Conduct security control validation, vulnerability analysis, and risk assessment activities across systems and platforms • Monitor system security posture and coordinate with engineering teams to remediate identified vulnerabilities and findings • Provide IA guidance during system changes, deployments, and upgrades to ensure security controls remain effective and compliant • Support incident response and cybersecurity event handling, including analysis, containment support, and post-incident remediation activities • Review system configurations, architectures, and operational procedures to identify security gaps and risk areas • Collaborate with Senior Azure Systems & Platform Engineers and Azure Architects to ensure security requirements are integrated into system designs and implementations • Assist with continuous monitoring activities, including review of security-relevant logs, alerts, and assessment results • Support audits, inspections, and compliance reviews by providing technical input, evidence, and security expertise • Track and manage plans of action and milestones (POA&M) and remediation efforts, as applicable • Maintain accurate security documentation, including control implementations, assessment results, and remediation records • Ensure compliance with DoD 8140 / DCWF qualification requirements and maintain required professional certifications and continuing education
Content Marketing Writer – Cybersecurity, Developer
DXC TechnologyDelivering excellence for our customers and colleagues
• Primarily focus on writing high-quality, original and engaging content for developers. • This can be in the form of blogs (Think security checklists, explainers, comparison pieces, guides,...), whitepapers, web pages, docs, emails, etc... • You'll research & propose which areas or topics we need to provide content for. • Work closely with our designers to make sure all content has great visuals that enhance the reader's experience. • Work with our editor to ensure the copy meets our language, structure, tone of voice. • Continuously optimize our online content for SEO performance.
Senior Technical Consultant
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role offers the opportunity to be a key contributor in deploying, optimizing, and enhancing advanced cybersecurity platforms for a diverse client base. The Senior Technical Consultant will work hands-on with Palo Alto XSIAM, Cortex XDR, and XSOAR, implementing complex configurations, automation playbooks, and integrations that improve client security operations. You will collaborate closely with clients and internal teams to fine-tune deployments, troubleshoot challenges, and mentor junior consultants, all within a dynamic, client-focused, and technically advanced environment. This position combines deep technical expertise with strategic problem-solving to help organizations detect, respond, and automate effectively across their networks, endpoints, and cloud environments. - Lead end-to-end deployment, configuration, and customization of XSIAM, XSOAR, and XDR solutions for clients - Develop and implement custom content including correlation rules, data models, and automation playbooks to streamline SOC workflows - Integrate diverse data sources to provide comprehensive visibility across endpoints, network, cloud, and identity systems - Collaborate with clients to optimize and fine-tune platform performance and provide guidance on best practices - Act as a technical resource to troubleshoot and resolve complex issues during and post-implementation - Contribute to detection strategies, playbook development, and enhancement of client security posture - Maintain clear and comprehensive documentation, including solution designs and as-built configurations - Mentor junior consultants to develop technical skills and XSIAM expertise Qualifications - 3–5 years of dedicated cybersecurity experience with a strong background in SIEM, SOAR, EDR/XDR, or SOC operations - 2–4 years of threat intelligence and/or incident response experience - Minimum of 2 years directly implementing and configuring XSIAM or similar advanced SecOps platforms - Expertise in SIEM and SOAR development, including playbooks, log collection, parsing, and normalization - Experience with EDR/XDR deployment and management, including CrowdStrike, Cortex, and Cisco - Proficiency in XQL for data analysis and rule creation - Solid understanding of network security, cloud environments, identity systems, Linux, Mac, and Windows - Strong analytical, troubleshooting, and problem-solving skills - Effective communication skills to engage with clients and team members - Relevant certifications such as PCNSE, CISSP, CYSA, CEH, Security+, Pentest+, or OSCP are a plus Benefits - Competitive salary range of $130,000–$200,000 per year (including On-Target Earnings) - Comprehensive medical, dental, and vision insurance - 401(k) retirement plan - Paid company holidays and flexible paid time off - Paid parental and caregiver leave - Professional development, cross-department training, and sponsored certifications - Inclusive, diversity-driven culture with internal groups supporting career growth and community
Head of Platform, Security
CosunoManage your entire planning cycle with the Cosuno platform and benefit from our one-size-fits-all solution
• Complete our ISO 27001 certification and establish the processes to maintain it going forward • Take ownership of our Terraform configurations across AWS and GCP, improving structure and reliability • Respond to security questionnaires from enterprise customers, helping us close deals faster • Streamline employee IT onboarding and access management across our SaaS tooling stack



