Manager, InfoSec Compliance & Governance Job at GAP Inc., San Francisco, CA

TmxJKytoa3Z3U1FQTGVpNHRwSUlxRWVoTVE9PQ==
  • GAP Inc.
  • San Francisco, CA

Job Description

Manager, InfoSec Compliance & Governance About the RoleRole Overview: As a of Mgr InfoSec Governance & Compliance, you will play a critical role in ensuring our organization meets compliance standards and protects sensitive data across our international operations. You will work closely with technical experts, legal counsel, and other global stakeholders, applying analytical and interpersonal skills to bridge operational and technical gaps. You will deliver program activities on-time for successful assessments and audits. What You'll Do Key Responsibilities:

  • Compliance Management: Facilitate audits and assessments to ensure compliance with relevant regulatory standards (e.g., GDPR, CCPA, PCI DSS, SWIFT, SOX). Provide support for compliance activities and ensure compliance program activities are occurring as scheduled and effectively managed.
  • Policy Development: Draft, update, and enforce compliance with IT security policies, procedures, and guidelines in line with global and regional regulations. Collaborate with business units to ensure policies are effectively communicated and implemented.
  • Third Party Risk Management: Evolve and execute vendor security assessment processes. Review vendor security documentation and identify potential risks. Maintain vendor inventory risk ratings. Collaborate with procurement and legal teams on vendor contracts and security requirements.
  • Technical Control Implementation: Work with IT and development teams to validate technical security controls. Evaluate technical solutions for compliance with regulatory requirements. Follow and maintain control testing procedures and schedules.
  • Collaboration: Liaise effectively with both technical teams (e.g., IT operations, cybersecurity), legal (e.g., compliance officers, external counsel) and business teams to align compliance initiatives.
  • Training & Awareness: Develop and deliver training programs to educate employees on security compliance and best practices.
  • Documentation: Maintain accurate and up-to-date records of compliance activities, audits, and risk assessments.
  • Continuous Improvement: Monitor and evaluate the effectiveness of compliance programs and recommend enhancements.
  • Technical Communication: Communicate technical and regulatory specifications and requirements to non-technical personnel in a clear and understandable manner.
Qualifications:
  • Education: Bachelor’s degree or equivalent experience in Computer Science, Information Security, or a related field. Advanced degree preferred.
  • Experience: 4+ years of experience in IT security compliance, preferably in a global retail or eCommerce environment, with a proven track record of creating and reviewing compliance policies.
• Technical Skills:
  • Strong knowledge of compliance standards like GDPR, CCPA, PCI DSS, SOX
  • Familiarity with risk management frameworks such as NIST, ISO 27001.
  • Experience with cloud security platforms (e.g., AWS, Azure, Google Cloud).
  • Proficiency in security tools and technologies (e.g., FW/WAF, SIEM, DLP, IAM).
  • Familiarity with engineering development toolchains and capabilities.
• Soft Skills / Competency:
  • Proactive problem-solver who can identify compliance gaps before they become issues.
  • Exceptional critical thinking and problem-solving abilities to analyze complex compliance issues and propose effective solutions.
  • Strong interpersonal and communication skills to build relationships with diverse stakeholders across technical, legal audiences and business audiences.
  • Adaptability and cultural sensitivity, fostering collaboration in a global environment.
  • Proactive approach to identifying risks and opportunities for improvement.
  • Attention to detail with excellent organizational and time-management skills.
  • Ability to communicate technical specifications and compliance requirements to non-technical personnel in a clear and understandable manner.
Who You Are • Certifications: CISA, CISM, CISSP, or equivalent. • Additional Experience:
  • Experience with Governance, Risk & Compliance (GRC) platforms.
  • Experience with cloud security platforms (e.g., AWS, Azure, Google Cloud).
  • Expertise running IT compliance standard assessments is a plus.
  • Experience with data privacy regulations and frameworks (e.g., CPRA, ISO 27701).
  • Familiarity with DevSecOps practices and tools.

Job Tags

Similar Jobs

J & A Group, Services Inc

Special Event Security Postion Job at J & A Group, Services Inc

Special Event Security Position Overview: We are looking for dedicated and highly capable Special Event Security Guards to ensure the safety and security of attendees, staff, and assets during various special events. The ideal candidate will have strong observational... 

Brio living Services

Resident Care Assistant: Part Time 10:30pm-7am Job at Brio living Services

 ...well-being, reimbursed 120 a year! Competitive Benefits for Part-Time Team Members Enjoy Vision, Mental Health Programs, Legal Plans...  ..., starting on the 1st of the month after 30 days of hire. Retirement Savings Plan Secure your future with employer contributions... 

A Igreja de Jesus Cristo dos Santos dos Últimos Dias

Project Coordinator Job at A Igreja de Jesus Cristo dos Santos dos Últimos Dias

View More Jobs Project Coordinator Salt Lake City, UT, United States (Hbrido) Trending...  ...Project Coordinator is responsible for working with researchers, departments, and areas...  ...week, with the option of working from home when there are not required in-person meetings... 

Eurofins USA Clinical Trial Solutions

Scientific Affairs Liaison Job at Eurofins USA Clinical Trial Solutions

 ...Management to profitably grow the laboratory business. Scientific Affairs Liaison responsibilities include, but are not limited to, the...  ...Qualifications : Bachelor of Science Degree Degree in Medical Technology or Life Sciences preferred Basic Minimum... 

Bethel Farms

Business Analyst Job at Bethel Farms

 ...Bethel Farms is seeking a highly motivated and detail-oriented Business Analyst to join our Analytics and Reporting team in Arcadia,...  ...Business Analyst position is an excellent opportunity for an entry-level to early-career professional eager to develop their analytics...