Carters, Inc

Governance, Risk & Compliance Manager (IT)

Carters, Inc • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in a technical field (Mathematics, Computer Science, Accounting, etc.)
  • 7+ years in IT Governance Risk Compliance (GRC), information security, or risk management
  • 7+ years implementing IT Governance Risk Management programs
  • 2+ years directly involved in AI governance or AI tool security and compliance
  • Professional certification (CISSP, CISA, CISM, CGEIT, CRISC, AAIA, AAIR, or similar)
  • Knowledge of IT GRC frameworks: NIST CSF, ISO 27001, COBIT, SOX ITGC, PCI DSS, SOC 2
  • Working knowledge of AI technologies and vendor risk assessment

Responsibilities

  • Lead the development of Carter's AI Governance Framework and policies
  • Maintain an inventory of AI tools and connectors used in the enterprise
  • Conduct AI risk assessments to identify vulnerabilities and exposure risks
  • Define controls for AI connector permissions and data loss prevention
  • Monitor AI regulatory landscape and update policies accordingly
  • Ensure AI governance aligns with data privacy regulations
  • Support the Carters AI Center of Excellence (COE) team across departments

Benefits

  • Comprehensive health, dental, and vision insurance
  • 401(k) plan with company match
  • Generous paid time off policy
  • Flexible work arrangements
  • Professional development opportunities
Full Job Description
How you’ll make an impact:

As Carter's accelerates its use of AI technologies — including generative AI assistants, AI-enabled SaaS applications, MCP (Model Context Protocol) connectors, and agentic workflows — this role will ensure that AI adoption is governed with the same rigor applied to any other enterprise technology risk. The Manager will balance traditional IT GRC fundamentals with forward-looking AI governance leadership, making this a uniquely strategic position within the IT organization.

AI Governance & Emerging Technology Risk (YR 1 – approx. 60%)

  • Lead the development and implementation of Carter's AI Governance Framework, defining policies for acceptable use, data classification, model risk, vendor AI tools, and agentic workflows aligning with the company’s ERM program.
  • Maintain a comprehensive inventory of AI tools and connectors deployed across the enterprise, including MCP servers, generative AI platforms, and AI-enabled SaaS integrations (e.g., Atlassian, Microsoft 365, Snowflake, Adobe Analytics).
  • Conduct and oversee AI risk assessments covering data exposure (including PII), identify potential vulnerabilities, unauthenticated access risks, and potential risk exposure in MCP connector packages.
  • Define and enforce controls for AI connector permissions, least-privilege access, credential management, and data loss prevention in AI workflows.
  • Monitor the AI regulatory landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, state AI laws) and translate requirements into actionable controls and policy updates for Carter's.
  • Ensure AI governance aligns with data privacy obligations (e.g., CCPA, COPPA, GDPR) applicable to Carter's customer base, which includes children's products.
  • Provide support to the Carters AI COE team and assist with AI Governance across multiple departments.

 

Compliance & Regulatory Management (40%)

  • Oversee compliance with applicable regulatory frameworks and standards including SOX ITGC, PCI DSS, NIST (Cybersecurity and AI), and CCPA etc.
  • Manage the IT control testing calendar, coordinate evidence collection, and liaise with internal and external auditors throughout audit engagements.
  • Track remediation of audit findings and control deficiencies, providing regular status reporting to the Director of IT GRC and leadership.
  • Support enterprise IT privacy program activities in coordination with the Legal and IT teams, particularly where technology systems process personal data.

 

We’d Love to hear from you if: (Requirements section)

Must have:

  • At Least a bachelor’s degree in a technical field of studies (Mathematics, Computer Science, Accounting, etc.)
  • 7+ years of progressive experience in IT Governance Risk Compliance (GRC), information security, risk management, or a related discipline
  • 7+ years of experience related to building and implementing IT Governance Risk Management programs 
  • 2+ years of direct involvement in AI governance, AI risk assessment, or significant responsibility for AI tool security and compliance.
  • Professional certification (CISSP, CISA, CISM, CGEIT, CRISC, AAIA, AAIR or similar)
  • Strong foundational knowledge of IT GRC frameworks: NIST CSF, NIST AI, ISO 27001, COBIT, SOX ITGC, PCI DSS, and SOC 2.
  • Working knowledge of AI technologies, including generative AI tools, large language models, MCP (Model Context Protocol) server architectures, and agentic AI workflows.
  • Experience assessing AI and SaaS vendor risk, including security questionnaire review, CVE management, and third-party audit evaluation.
  • Understanding data privacy regulations applicable to Carter's: CCPA, CPRA, and GDPR.
  • Proven ability to manage cross-functional programs and influence stakeholders across IT, Legal, Finance, and business without direct authority.
  • Strong written and verbal communication skills; able to translate complex technical risk topics for executive and non-technical audiences.

 

 


About Carters, Inc

Carter's, Inc. operates as a children's apparel and accessories company in the United States and internationally. The company operates through three segments: U.S. Retail, U.S. Wholesale, and International. Its Carter's brand products include baby products, such as bodysuits, pants, dresses, knit sets, blankets, layette essentials, bibs, booties, sleep and play products, rompers, and jumpers; play clothes comprising knit and woven cotton apparel; sleepwear products consisting of pajamas in cotton, fleece, and ploy-jersey; and other products, including bedding, outerwear, swimwear, footwear, socks, diaper bags, gift sets, toys, and hair accessories. The company also provides products under the OshKosh brand name, which comprise play clothes in denim, fleece, and other fabrics for sizes newborn to 14. It sells its products through company-operated stores, department stores, and online, as well as through other retail outlets, such as specialty stores, national chains, and mass merchants. As of January 2, 2021, the company operated approximately 800 Carter's retail stores, 100 OshKosh retail stores, and its products were available in approximately 18,000 department stores and other retail outlets in the United States, Canada, and internationally. Carter's, Inc. was founded in 1865 and is headquartered in Atlanta, Georgia.
Learn more about Carters, Inc
Size
15,900 employees
Market Cap
$2.8 billion
Industry
Net Income
$109.7 million
Founded
1865
5 Year Trend
+1.7%
Revenue
$3 billion
NASDAQ

Similar Jobs

More Jobs at Carters, Inc

More Information Technology Jobs

Find similar Governance, Risk & Compliance Manager (IT) jobs: