**
DICK'S Sporting Goods is seeking a Senior Manager for Information Security Risk Management to lead and enhance their enterprise risk management program and Governance, Risk, and Compliance (GRC) platform. The role involves overseeing risk identification, assessment, and treatment while also managing a team and serving as a trusted advisor to senior leaders on risk-related matters.
**
Job Summary
The Senior Manager, Information Security & Risk Management is responsible for building, leading, and maturing the enterprise information security risk management program and the Governance, Risk, and Compliance (GRC) platform.
This role owns the people, process, and technology underpinning risk identification, assessment, treatment, reporting, and assurance.
The company is committed to creating an inclusive and diverse workforce, reflecting the communities we serve.
Matching Summary
Match Score: 75
**
DICK'S Sporting Goods is seeking a Senior Manager for Information Security Risk Management to lead and enhance their enterprise risk management program and Governance, Risk, and Compliance (GRC) platform. The role involves overseeing risk identification, assessment, and treatment while also managing a team and serving as a trusted advisor to senior leaders on risk-related matters.
**
Salary
Base: $95,200.00 - $158,800.00; Bonus/Equity: Incentive, equity; Benefits: Generous suite of benefits
Skills & Requirements
Must-have
Information Security Risk Management program
GRC platform ownership
risk identification and assessment
control assurance and testing
policy and standards framework
third-party risk management
Nice-to-have
culture of accountability
continuous improvement
risk quantification approaches
cloud and modern engineering environments
Key Requirements
7-10 years progressive experience in Information Security, Risk, or Audit
3-5+ years leading teams and/or owning a GRC platform
Bachelors Degree in Information Systems, Computer Science, Cybersecurity, or related; or equivalent experience
Security or audit certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CISA