Company

The Hershey CompanySee more

addressAddressHershey, PA
salary Salary$133K - $168K a year
CategoryInformation Technology

Job description

Job Title: Senior Manager, IT Risk and Compliance GRC (Governance, Risk and Compliance)

Job Location: Hershey, PA

This position can be 100% remote


DESCRIPTION:

The Hershey Company is looking for a senior leader to advance the Governance, Risk and Compliance (GRC) function to ensure risk identification, assessment, reduction, and accountability; while driving compliance with standards, policies, and applicable regulations globally. A successful leader at The Hershey Company is collaborative, organized, and able to work well through change and ambiguity. You should have strong critical thinking skills, excellent communication skills, and a validated record of a direct approach to leading teams and maturing programs in at scale. This individual will be reporting directly to the Director Governance, Risk and Compliance within the Information Security team.
This job contributes to The Hershey Company’s success by safeguarding information and systems assets against unauthorized use, disclosure, modification, damage, or loss. Serves as the focal point for maintaining and overseeing enterprise-wide cybersecurity policies, standards, and compliance programs. Being successful in this role requires the desire and ability to influence, uplift, collaborate, and empower individuals that also includes a strong technical background.


As Senior Manager IT Risk & Compliance you will (SUMMARY):

  • Collaborate with the Director of GRC to develop, drive, and communicate the GRC program vision and set supporting objectives.
  • Develop and deliver on strategic roadmaps to develop a best in class GRC function - You will be responsible advancing, maintaining, and delivering on strategic initiatives within GRC and the Information Security organization.
  • Own, maintain, prioritize, and address GRC tooling backlog (issues, defects, enhancements, etc.).
  • Be a liaison between key partners (IT, Security, Privacy, Compliance, Legal, and Internal Audit), GRC systems & vendors.
  • Oversee management of security policies, standards, and guidelines. Ensure policies are reviewed and updated regularly.
  • Responsible for the management and governance of the Vulnerability management program.
  • Provide control and mitigation subject matter expertise for reduction of risks identified and mapped in risks assessments in coordination with Security, Technology and Business leaders.
  • Engage with key business partners to understand business processes, critical data and systems, security risk posture, and risk appetite.
  • Maintain comprehensive view of information security risk, communicate risk to stakeholders and drive compliance to policies and risk appetite.
  • Enable the business through continuous improvement opportunities within the risk and compliance toolset, program, and processes.
  • Lead, grow and develop GRC staff and perform talent development activities.

REQUIREMENTS:

  • Successful track record of building teams, mentoring, and developing talent.
  • Demonstrated ability to work successfully in a fast-paced, cross functional team environment.
  • 7 - 12 years Information Security, Audit or IT Risk & Compliance Management.
  • Extensive experience managing SOX controls programs and supporting SOX audits.
  • Thorough understanding of a broad range of technical concepts relevant to cloud computing environments: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy.

EDUCATION:

  • BS in Computer Science, Information Security or related field OR equivalent work experience (6 years of experience)
  • 5+ years of progressive experience leading highly skilled, diverse technical teams.

CERTIFICATIONS:

  • CISA, CISSP, CISM or other professional certifications a plus.

The Hershey Company is an Equal Opportunity Employer. The policy of The Hershey Company is to extend opportunities to qualified applicants and employees on an equal basis regardless of an individual's race, color, gender, age, national origin, religion, citizenship status, marital status, sexual orientation, gender identity, transgender status, physical or mental disability, protected veteran status, genetic information, pregnancy, or any other categories protected by applicable federal, state or local laws.


The Hershey Company is an Equal Opportunity Employer - Minority/Female/Disabled/Protected Veterans

If you require a reasonable accommodation as part of the application process, please contact the HR Service Center (askhr@hersheys.com).

Refer code: 8533128. The Hershey Company - The previous day - 2024-03-11 04:15

The Hershey Company

Hershey, PA
Jobs feed

Account Specialist II

Aon Corporation

Atlanta, GA

Wound Registered Nurse (RN) Case Manager - Now Hiring

Interim Healthcare

Colorado, United States

Class A CDL Truck Driver FLATBED - HIRING IMMEDIATELY Up to $100K!

Western Express

New Rochelle, NY

$100000+ per year

Entry Level CDL-A Truck Driver Training - Now Hiring

Class A Solutions

Yonkers, NY

Payroll Specialist (Toast Payroll) - Contract

Christlie G. Consulting Llc

Atlanta, GA

Cardiac Cath Lab - Cath Lab / Interventional Technologist

Trusted Health

New York, NY

$2680 per week

Client Service - Assistant Manager

Vca Animal Hospitals

Los Angeles, CA

Relief Associate Veterinarian - Orange Park, FL

Vca Animal Hospitals

Lorida, FL

Share jobs with friends

Related jobs

Sr Manager, It Risk & Compliance

2025 IT Risk Advisory Summer Intern

Schneider Downs

Pittsburgh, PA

4 months ago - seen

Information Risk Consultant

360 IT Professionals

Pittsburgh, PA

4 months ago - seen

Senior Analyst, Risk and IT Compliance

Quaker Houghton

Conshohocken, PA

4 months ago - seen

Principal, IT Risk Analyst

BNY Mellon

Pittsburgh, PA

4 months ago - seen

Senior Vice President, IT Risk Control Management

BNY Mellon

Pittsburgh, PA

5 months ago - seen