Burlington Stores

Manager, IT Security, Governance, Risk and Compliance

Burlington Stores$115K — $167K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security governance, risk, or compliance roles
  • Demonstrated success in leading cross-functional projects
  • Deep understanding of controls, audits, and frameworks
  • Relevant certifications such as CISM, CISSP, or CISA
  • Effective communication with technical and non-technical stakeholders
  • Conflict resolution and team consensus-building skills
  • Leadership experience overseeing a cybersecurity team of 3+ members
  • Bachelor's degree in Information Systems, Cybersecurity or related field required; Master's preferred

Responsibilities

  • Lead enterprise-wide cybersecurity risk assessments
  • Maintain and update the enterprise risk register
  • Collaborate with leaders to define risk tolerance
  • Translate risk findings into business-relevant recommendations
  • Monitor trends in industry and adjust risk posture
  • Deliver risk reports to senior leadership
  • Implement risk governance processes
  • Automate GRC tools to improve risk management

Benefits

  • Competitive wages
  • Flexible hours
  • Associate discount
  • Medical, dental, and vision coverage
  • Life and disability insurance
  • Paid time off and holidays
  • 401(k) plan
  • Training and development opportunities
Full Job Description
Position Overview

The Manager of Governance, Risk and Compliance (GRC) plays a critical mid-level leadership role within the Information Security function, responsible for translating strategy into operational execution across the GRC program. Reporting to the Director of GRC, this role provides daily oversight of analysts and leads, drives process maturity, and ensures consistent delivery of risk, audit, policy, and continuity efforts. The Manager of GRC helps shape the enterprise's risk posture while mentoring a high-performing team and fostering cross-functional collaboration. This role requires a deep understanding of regulatory frameworks and an ability to communicate complex risk concepts in clear, actionable terms. The ideal candidate will proactively identify control gaps, coordinate effective mitigation, and ensure security efforts remain aligned with evolving business needs.

A Day in the Life

Enterprise Cyber Risk Management:

  • Lead enterprise-wide cybersecurity risk assessments across business units and IT domains.


  • Own the accuracy and ongoing maintenance of the enterprise risk register, ensuring it is consistently updated and informed by stakeholder input.


  • Collaborate with business and IT leaders to define and apply enterprise risk tolerance thresholds.


  • Translate technical risk findings into actionable, business-relevant recommendations.


  • Identify and escalate systemic risks that could materially impact operations or compliance.


  • Monitor industry trends, threat intelligence, and regulatory changes to adjust risk posture.


  • Deliver clear, timely risk reports and dashboards to senior leadership and governance bodies.


  • Implement structured risk governance processes, including review cycles and escalation protocols.


  • Implement automated GRC tools and data analytics to improve cybersecurity risk management efficiency and accuracy.


  • Develop KPIs and KRIs for the security organization and maintain tactical and strategic dashboards to monitor risk and compliance efforts.


Management & Collaboration:

  • Oversee GRC team operations, assigning work, setting priorities, and ensuring effective collaboration.


  • Partner with senior leadership and business stakeholders to align GRC efforts with enterprise goals.


  • Foster a high-performing, collaborative team culture through coaching, accountability, and career development.


Business Continuity and Disaster Recovery (BC/DR):

  • Lead collaboration with IT and business leaders to identify mission-critical applications and conduct comprehensive BIA, define RTO/RPO, and recovery procedures.


  • Develop dependency mappings for critical systems with application and infrastructure teams.


  • Oversee documentation of recovery procedures, including technical and business continuity procedures.


  • Lead tabletop exercises and failover/failback recovery testing with IT and business users.


  • Identify gaps in the BC/DR program and take ownership of remediation.


  • Ensure business continuity objectives are effectively aligned with IT capabilities to support organizational resilience during disruptions.


  • Contribute to recovery planning efforts and facilitate coordination among IT and business teams to ensure effective response during disruptions.


Vendor Risk Management:

  • Partner with the procurement and legal teams to integrate cybersecurity function into the overall process, mitigating supply chain risks for the company.


  • Manage third-party risk processes, including assessments and reviews. Continuously identify opportunities for improvement to enhance its effectiveness and efficiency


  • Escalate high-risk vendor issues to leadership and work with business stakeholders to develop and execute mitigation plans.


  • Oversee monthly reporting on security assessments of AI vendors, provide expert analysis to leadership on AI-related risks and recommend strategic actions to resolve identified issues.


  • Establish and manage a comprehensive set of criteria and assessment questions to support third-party risk management activities.


Managed Security Service Provider (MSSP) and Third-Party Security Incidents:

  • Own vendor incident response governance program and playbooks.
  • Ensure vendors provide formal evidence of incident containment and remediation and ensure compliance with security requirements before closing a third incident.
  • Consolidate third party incident and GRC-owned MSSP results into executive dashboards.
  • Embed incident response obligations into contracts and procurement.


Audit and Compliance:

  • Oversee internal/external audit readiness and evidence collection.


  • Ensure compliance with SOX, PCI, and privacy frameworks.


  • Serve as audit liaison for the GRC function.


  • Act as the primary contact for internal audit and take ownership of recreating risk and compliance assessment findings.


Policy Implementation:

  • Manage the policy lifecycle from creation through enforcement.


  • Ensure policies align with frameworks like NIST and PCI DSS.


  • Ensure the organization adheres to all relevant policies and standards.


Cybersecurity Education:

  • Manage company-wide security training programs.


  • Strategically identify education and awareness needs based on enterprise-wide cybersecurity threats and business priorities.


  • Establish metrics to evaluate the success of training initiatives, including trends in knowledge retention, behavior changes, and overall effectiveness of the security culture.


  • Oversee continuous improvement of the training curriculum, ensuring it evolves to address new threats and compliance requirements.


You'll Come With

  • 8+ years in security governance, risk, or compliance roles.


  • Demonstrated success in leading cross-functional projects.


  • Deep understanding of controls, audits, and frameworks.


  • Maintain relevant certifications such as CISM, CISSP, or CISA.


  • Communicate effectively with technical and non-technical stakeholders.


  • Resolve conflicts and drive consensus across teams.
  • Provided leadership and oversight for a cybersecurity team of 3+ members
  • Mentor team members and model professional behavior.


  • Bachelor's degree in Information Systems, Cybersecurity or related field required; Master's preferred.
  • Target Pay Range: $115,000 - $167,500 annually


This position has a target starting salary range of $115,000 - $167,500 annually. Actual pay is determined by a variety of factors, including but not limited to, qualifications, education, job-related skills, relevant experience, and geographic location.

#LI-JL2

About Burlington Stores

Burlington Coat Factory is a leading off-price apparel and home product retailer. They operate 567 stores in 45 states and Puerto Rico, where you’ll find a large assortment of current, high-quality, designer and name-brand merchandise at up to 65% off other retailers' prices. Choose from a large selection of coats, clothing, and shoes for the entire family. And don’t forget their great assortment of linens and home décor. In Baby Depot, you’ll find everything you need for baby, from baby bottles to cribs.

Burlington Stores Careers

Join the vibrant team at Burlington Stores, a national leader in retail, where your career journey is as promising as our commitment to innovation and diversity. At Burlington, you're not just taking a job; you're stepping into a world of opportunities that foster growth, leadership, and professional fulfillment.

Work You'll Do

At Burlington Stores, we're more than just a retail company; we're a place where you can make a real impact. Whether you're looking for a position in sales, management, or corporate roles, we offer a variety of job opportunities to match your skills and ambitions. Our team is dedicated to providing a supportive and dynamic environment where everyone’s contribution is valued.

Join Our Market-Leading Team

Being part of Burlington Stores means being part of a culture that values diversity and innovation. Our leadership is committed to fostering a workplace where ideas thrive and where every team member is empowered to reach their full potential. With Burlington, you will collaborate with talented professionals who are passionate about redefining the retail experience.

Innovative Work and Career Growth

Embrace the chance to do innovative work with Burlington Stores, where we push the boundaries of what retail can be. With over 700 stores nationwide, the scale of our challenges offers limitless opportunities for career growth. Dive into roles that challenge you to think big, whether in store management, supply chain logistics, or corporate strategy.

Internship and Employment Opportunities

Kickstart your career with an internship at Burlington Stores, where you can gain invaluable industry experience. Our internships provide a robust platform for learning and networking, setting the stage for a successful transition to full-time employment. We are committed to hiring interns who are curious, driven, and ready to make an immediate impact.

Benefits and Professional Development

Choosing a career at Burlington Stores means enjoying competitive benefits and comprehensive diversity training programs designed to help you grow at every stage of your professional life. Our benefits package includes health, dental, and vision insurance, employee discounts, and much more. Moreover, we support your continuous improvement through professional development courses and leadership training.

Explore Burlington Stores Jobs

Ready to advance your career in a company that prides itself on growth, innovation, and a positive work culture? Explore the job opportunities at Burlington Stores today. Tailor your resume, prepare for your interview, and join a team that’s committed to redefining retail.

Stay Connected

Join Our Team Search open positions that match your skills and interests. We look for passionate, creative, and solution-driven team players who are ready to lead and inspire. SEARCH BURLINGTON STORES JOBS Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at Burlington Stores.
Learn more about Burlington Stores
Size
14,803 employees
Market Cap
$12.8 billion
Industry
Net Income
-$216.5 million
Founded
1972
5 Year Trend
+10.8%
Revenue
$5.7 billion
NASDAQ

Similar Jobs

More Jobs at Burlington Stores

More Information Technology Jobs

Find similar Manager, IT Security, Governance, Risk and Compliance jobs: