DICK'S Sporting Goods

YOU LIVE AND BREATHE SPORTS. SO DO WE.

Senior Manager, Information Security Risk Management

Security EngineerSecurity EngineerFull TimeRemoteTeam 10,001+Since 1948H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

7 days ago

Salary

$95.2K - $158.8K / year

Bachelor Degree7 yrs expEnglishAWSAzureCloudCyber SecurityGoogle Cloud PlatformService Now

Job Description

• Build and lead a high-performing GRC/risk team (analysts, engineers, control owners). • Own the selection, implementation, configuration, and continuous improvement of the GRC platform (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate, MetricStream, similar). • Establish a risk-based control testing and continuous control monitoring (CCM) program. • Design, implement, and mature an enterprise Information Security Risk Management (ISRM) program aligned to business strategy and regulatory requirements. • Act as a trusted advisor to senior leaders on risk appetite, emerging risks, and investment trade-offs. • Coordinate audit readiness and responses (internal audit, external audit, regulatory inquiries); ensure defensible evidence management.

Job Requirements

  • 7-10 years progressive experience in Information Security, Risk, or Audit with 3–5+ years leading teams and/or owning a GRC platform.
  • Bachelor's Degree: Information Systems, Computer Science, Cybersecurity, or related; or equivalent experience.
  • Strong knowledge of risk and control frameworks and regulations: NIST CSF/800-53, ISO 27001, SOC 2, SOX/ITGC, PCI DSS, HIPAA, CIS, and data protection/privacy (e.g., GDPR, CCPA/CPRA).
  • Hands-on experience designing automated workflows, building dashboards, and integrating GRC with IT/security tooling.
  • Security or audit certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CISA.
  • Experience with risk quantification approaches (e.g., FAIR) and board-level reporting.
  • Background in cloud and modern engineering environments (AWS/Azure/GCP, DevSecOps, SaaS).

Benefits

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Professional development opportunities
  • Remote work options

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1-10Since 1999H1B No Sponsor

Information Assurance Engineer implementing security controls in DoD environments

AzureCloudCyber Security
United States

Content Marketing Writer – Cybersecurity, Developer

DXC Technology

Delivering excellence for our customers and colleagues

Security Engineer8 days ago
Full TimeRemoteTeam 10,001+Since 2017H1B Sponsor

Content Marketing Writer focusing on developer-centric security content

United States

Senior Technical Consultant

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Security Engineer8 days ago
Full TimeRemote

This role offers the opportunity to be a key contributor in deploying, optimizing, and enhancing advanced cybersecurity platforms for a diverse client base. The Senior Technical Consultant will work hands-on with Palo Alto XSIAM, Cortex XDR, and XSOAR, implementing complex config...

Palo Alto XSIAMCortex XDRXSOARSIEMSOAREDRXDRXQLCrowdStrikeCiscoPythonPowerShellLinuxWindowsMacOSCloud SecurityNetwork SecurityIncident ResponseThreat IntelligencePlaybook DevelopmentLog ParsingData NormalizationSOC Operations
United States

Chief Product Security Officer

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Security Engineer8 days ago
Full TimeRemote

This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Chief Product Security Officer - REMOTE. In this pivotal role, you will drive the global product security strategy to protect the digital framework of the power industry, including...

Embedded SystemsIndustrial Control SystemsSaaS SecurityCISSPCISMCSSLPProduct Lifecycle ManagementVulnerability ManagementIncident ResponseRegulatory Compliance
United States