Jobs · Finance · Nebraska

Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Conagra Brands · Omaha, NE · 2 wk ago
Finance$125k–$183k/yrFull-time

Key Responsibilities

Lead and develop a team responsible for Cybersecurity GRC, IT Compliance, Third-Party Cybersecurity Risk Management, ERP Security, and Security Awareness.

Establish team priorities, performance goals, and development plans aligned with business objectives.

Foster a culture of accountability, collaboration, and continuous improvement.

Manage resources, budgets, and strategic vendor relationships.

Cybersecurity Governance, Risk Management & Reporting

Lead and advance the organization's cybersecurity governance and risk management programs.

Establish policies, standards, and governance practices aligned with regulatory requirements and industry frameworks.

Drive enterprise cyber risk assessments, mitigation planning, and risk acceptance processes.

Provide meaningful risk reporting, metrics, and insights that support executive decision-making.

Third-Party Cybersecurity Risk Management

Lead the cybersecurity third-party risk management program.

Oversee risk assessments of vendors, suppliers, cloud providers, and business partners.

Partner with Procurement, Legal, Privacy, and business stakeholders to manage and mitigate third-party cybersecurity risks.

IT Compliance & Audit Management

Lead and mature the organization's IT Compliance program, including IT General Controls (ITGCs) and regulatory compliance activities.

Coordinate internal and external audits, including SOX ITGC and cybersecurity-related assessments.

Ensure audit readiness through effective compliance testing, remediation management, evidence collection, and reporting.

ERP Security & Access Governance

Lead ERP security governance across SAP and other enterprise platforms.

Oversee access governance, segregation of duties, privileged access controls, and periodic access reviews.

Partner with ERP, Identity & Access Management (IAM), Internal Audit, and business teams to strengthen security and compliance controls.

Ensure cybersecurity and compliance requirements are embedded in ERP transformation and modernization initiatives.

Security Awareness, Strategy & Program Excellence

Lead the organization's cybersecurity awareness and education program to strengthen security culture and reduce organizational risk.

Develop enterprise-wide awareness campaigns, role-based training, and targeted education initiatives.

Establish strategic roadmaps, success metrics, and maturity goals across assigned programs.

Drive continuous improvement through automation, process optimization, and technology enablement.

Support cybersecurity strategic planning, budget development, and investment prioritization.

Required Qualifications

  • Education: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
  • Experience: 8+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or related disciplines.
  • Team Leadership: 5+ years of experience leading and developing teams in a cybersecurity or technology environment.
  • Program Management: Experience leading cybersecurity governance, risk, compliance, audit, or control programs within a large or complex organization.
  • Stakeholder Collaboration: Experience partnering with business, technology, audit, and risk stakeholders to drive cybersecurity and compliance initiatives.
  • Reporting & Metrics: Experience developing executive-level reporting, cybersecurity metrics, and risk insights.
  • Framework Experience: Experience managing regulatory, audit, or control framework requirements, including IT General Controls (ITGCs), SOX, NIST, or similar frameworks.

Preferred Qualifications

  • Certifications: One or more of the following certifications is preferred: Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP).

Additional Experience

  • Third-Party Risk Management: Experience with third-party cybersecurity risk management programs.
  • SAP Security: Experience with SAP security, ERP governance, access management, or segregation of duties controls.
  • Regulated Organizations: Experience supporting publicly traded or highly regulated organizations.
  • Program Development: Experience implementing or maturing cybersecurity governance, risk management, compliance, or audit programs.
  • Tools & Platforms: Experience with cybersecurity governance, risk, compliance, or audit management platforms and tools.

Similar jobs