HarleyDavidson, Inc

Manager, Governance Risk and Compliance

HarleyDavidson, Inc$138K — $220K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in business management, information systems, or related field; Master's Degree preferred
  • 8+ years of experience in IT compliance and auditing frameworks
  • Expertise in regulatory frameworks like SOX, COBIT, NIST CSF, and PCI DSS
  • Strong leadership and team management skills, with a focus on continuous improvement
  • Excellent communication skills, capable of simplifying complex details for varied audiences
  • Experience with Third Party Risk Management (TPRM) and vendor assessment processes

Responsibilities

  • Build strong partnerships with senior leadership on GRC concepts and business practices
  • Develop processes for mapping IT controls to GRC standards for efficient monitoring
  • Oversee audit testing of IT controls, and guide management action on deficiencies
  • Manage processes for handling HR, Legal, and Ethics IT/Security investigations
  • Identify and assess significant IT security risks and ensure resources for remediation

Benefits

  • Annual bonus programs
  • Health insurance benefits
  • 401k program
  • Onsite fitness centers and employee stores
  • Employee discounts on products and accessories
  • Domestic relocation assistance available
Full Job Description
Auto req ID: 59839
Title: Manager, Governance Risk and Compliance
Job Function: Information Technology
Location: JUNEAU
Workplace Category: Onsite
Company: Harley-Davidson Motor Company
Full or Part-Time: Full Time
Shift: SHIFT1


Job Summary

The Manager of Harley-Davidson, Inc's Technology Governance, Risk and Compliance (GRC) reports to the Chief Information Security and Privacy Officer and leads Harley-Davidson's global information risk management and IT compliance program. The GRC leader is accountable for overseeing and coordinating the IT and cybersecurity program objectives needed to achieve and maintain HDI's compliance with regulatory requirements. The position serves as a key interface among internal and external compliance bodies, auditors, technology teams, and business functions to ensure HDI's IT general control environment is documented and operating effectively, and that information risks are reported to management for decision-making and action when necessary.

Job Responsibilities
  • Build and maintain strong business partnerships across key areas at a senior leadership level, bridging their understanding of GRC concepts and requirements with an understanding of regional and global business practices
  • Develop and implement processes to map IT general controls to established GRC standards and frameworks enabling efficient monitoring and reporting of regulatory compliance and risks.
  • Oversee audit testing of general IT controls, report on identified exceptions and deficiencies, guide the development of management action plans and escalate priority issues.
  • Manage and facilitate a secured process for all HR/Legal/Ethics IT/Security-related Investigations
  • Work with IT Senior Leadership to identify, assess, and bring visibility to the most significant IT security risks across the GIS organization while ensuring the appropriate resources are assigned to remediate risks.

Education Requirements
  • High School Diploma or Equivalent Required


Education Specifications
  • Bachelor's Degree in business management, information systems or a related discipline
  • Master's Degree in related field is Preferred
  • Industry-recognized certification such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent is preferred


Experience Requirements

Required
  • Typically requires a minimum of 8 years of related experience.
  • Subject matter expert in IT compliance and auditing frameworks, practices, policies, standards, and procedures:
    • Sarbanes-Oxley Act of 2002 (SOX)
    • Control Objectives for Information and Related Technologies (COBIT)
    • National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
    • System and Organization Controls (SOC) 1 and 2
    • Payment Card Industry Data Security Standard (PCI DSS)
      ISO 27001/2, or equivalent
    • Three Lines of Defense Model
  • Demonstrated experience working in an enterprise-level Information Security
  • Office with global accountabilities. Direct experience leading GRC processes with business leaders and managers.
  • Ability to define and establish comprehensive procedures that integrate with key business processes to ensure cybersecurity standards and best practices are part of compliance and risk management by design
  • Excellent communication and presentation skills with demonstrated skill in presenting complex detail around regulations clearly and to a variety of audience members
  • Familiarity with data flows and experience with scoping general IT controls to applicable compliance requirements.
  • Experience participating in or overseeing Third Party Risk Management (TPRM) programs, supplier risk assessment processes and vendor scorecards.
  • Proven ability to develop frameworks, strategies and roadmaps and to provide direction across all areas of accountability as well as to work closely with the
  • Corporate Information Security Office (CISO) organization where dependencies exist
  • Strong leadership, organization, communication, and process management skills; ability to lead and manage high-performing teams, and an ability to develop a continuous improvement mentality in all operational activities


Preferred
  • Experience in building and leading a team with a proven ability in developing capabilities, attracting and retaining a core team of collaborative professionals and creating an organization viewed as a highly attractive place to work.
  • Understanding of Payment Card Industry Data Security Standards (PCI DSS) Compliance requirements, the Attestation process, and working with business leaders to redesign business processes as needed


The pay range shown represents the national average pay range for this role. Your pay may be more or less than the stated range and is dependent on your geographic location and level of experience.

We offer an inclusive compensation package for all full-time salaried employees including, but not limited to, annual bonus programs, health insurance benefits, a 401k program, onsite fitness centers and employee stores, employee discounts on products and accessories, and more. Learn more about Harley-Davidson here.

Direct Reports: Yes
Travel Required: 0 - 10%
Pay Range: $138,100 - $220,900

Visa Sponsorship: This position is not eligible for visa sponsorship or visa transfer
Relocation: This position is eligible for domestic relocation assistance (within posted country)

About HarleyDavidson, Inc

Harley-Davidson, Inc. is a motorcycle manufacturer that produces heavyweight motorcycles and a line of motorcycle parts, accessories, and general merchandise. The company was founded in 1903 and is headquartered in Milwaukee, Wisconsin. Harley-Davidson has a loyal customer base and a strong brand image. The company has faced challenges in recent years due to declining sales and an aging customer base. Harley-Davidson has responded by introducing new models and expanding its product line to appeal to younger riders. The company also has a strong presence in the international market.
Learn more about HarleyDavidson, Inc
Size
5,800 employees
Market Cap
$5.9 billion
Industry
Net Income
$1.3 million
5 Year Trend
-2.3%
Revenue
$4 billion
NASDAQ

Similar Jobs

More Jobs at HarleyDavidson, Inc

More Information Technology Jobs

Find similar Manager, Governance Risk and Compliance jobs: