Sr Manager, IT Risk Management

13 hours ago


Richmond VA United States Carmax Full time

8116 - Midtown Office - 2220 W. Broad Street, Richmond, Virginia, 23220

CarMax, the way your career should be

Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row? Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical cybersecurity information risk management capabilities?

Do you want to work with a team of talented professionals that have highly advanced technical knowledge and be the subject matter expert in information security risk management, third party risk management, and business continuity?

BRIEF POSITION SUMMARY:

The Information Risk Manager is a critical leadership role that demands a comprehensive blend of technical expertise and strategic relationship management across information risk functions, including information security risk management, third party risk management, privacy operations, and business continuity. This individual is tasked with leading the development, implementation, and continuous refinement of an Information Risk Management framework, aligning with industry standards such as ISO 27001/2 and NIST 80030. Beyond technical responsibilities, this role is pivotal in fostering strong relationships with stakeholders, including business owners, regulatory bodies, third-party vendors, and internal teams, to ensure cohesive risk management strategies. The Information Risk Manager will oversee security policies, conduct risk assessments, manage security awareness training, and lead initiatives in business continuity, third-party security due diligence, and cyber regulatory readiness. This role serves as the information risk subject matter expert and strategic advisor in all facets of information risk management to all levels across the organization.

THE DAY TO DAY

  1. Lead the adoption and adaptation of a comprehensive information risk management framework, integrating privacy operations, security controls design & implementation, and continuous improvement mechanisms, while maintaining strong leadership and stakeholder relationships.
  2. Develop and manage security policies and procedures, ensuring compliance with legal, regulatory, and industry standards.
  3. Conduct thorough risk assessments, identifying potential threats and vulnerabilities, and implement robust security measures to protect organizational assets, with a focus on transparent communication and collaboration with stakeholders.
  4. Oversee the design and delivery of security awareness training and communications programs, enhancing the security culture within the organization and engaging with stakeholders to ensure widespread adoption and understanding.
  5. Manage business continuity risk & resiliency planning, ensuring the organization's ability to operate during and recover from adverse events, while working closely with stakeholders to align continuity plans with business needs.
  6. Conduct third-party security due diligence and vendor risk assessments to safeguard against third-party risks, collaborating with stakeholders to ensure third-party practices align with organizational security standards.
  7. Lead cyber regulatory readiness initiatives, preparing the organization for compliance with current and future security and privacy regulations, and engaging with regulatory stakeholders to ensure alignment and readiness.
  8. Engage in strategic board reporting, providing insights and updates on the organization's security posture and risk management efforts, and fostering strong relationships with leadership to support informed decision-making.
  9. Foster a culture of continuous improvement, regularly reviewing and enhancing security and risk management practices, with a focus on stakeholder feedback and collaboration to drive organizational resilience and security.

EDUCATION AND/OR EXPERIENCE

  1. Bachelor’s degree in Technology, Computer Science, Business, or a related field.
  2. Master’s degree or relevant professional certification (e.g., CRISC, CIA, CIPP, CISM, GIAC, CISSP) is preferred. CRISC and CISA required.
  3. A minimum of 10 years of leadership experience in information risk management or a similar role, with a focus on leadership and stakeholder management.
  4. Proven expertise in information security, information risk management, and compliance frameworks (NIST, CIS, ISO27001/2, etc.).
  5. Demonstrated leadership in privacy operations, security awareness training, business continuity, and third-party risk management, with a track record of successful stakeholder engagement and collaboration.
  6. Strong understanding of cyber regulatory environments and experience in senior leadership reporting and communication, with the ability to build and maintain effective stakeholder relationships.
  7. Extensive experience in information risk assessment, policy development, and incident response management, with a focus on strategic stakeholder communication and collaboration.
  8. Excellent communication skills, with the ability to effectively lead teams, influence stakeholders, and drive organizational change through strong leadership and stakeholder relationships.
  9. Excellent analytical, problem-solving, and decision-making skills; high level of accuracy and attention to detail.
  10. Strong leadership and organizational skills; ability to manage multiple projects and teams in a fast-paced environment.
  11. Exceptional interpersonal and communication skills, both written and verbal, with the ability to explain complex compliance issues to stakeholders at all levels.
  12. Demonstrated leadership - ability to gain consensus across teams without direct reporting responsibility.
  13. Strong leadership skills, with the ability to manage and mentor a team of risk management professionals.
  14. Dedication and commitment to top-quality service and to exceeding customer expectations.
  15. Proven ability to influence without authority the information risk management direction of others.
  16. Ability to build relationships that help overcome obstacles and time constraints to successfully deliver remediation to completion.

WORK ENVIRONMENT

This role operates in a dynamic, fast-paced office setting, reporting directly to the VP, Chief Information Security Officer. The environment demands high levels of focus, collaboration, adaptability, and strategic stakeholder engagement to manage multiple, simultaneous demands and ensure the organization's security risk and compliance posture.

Work Location and Arrangement: This role will be based out of the Richmond, VA Technology Innovation Center and have a Hybrid work arrangement.

Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis.

About CarMax

CarMax disrupted the auto industry by delivering the honest, transparent, and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation’s largest retailer of used cars, with over 200 locations nationwide.

Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For.

Our Commitment to Diversity and Inclusion: CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.

CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.

Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.

#J-18808-Ljbffr

  • Richmond, VA, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • Richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaSr. Manager, EPX Risk LeaderWe are growing! The Enterprise Services Business Risk Office provides risk management support to several lines of business including: Tech, Enterprise Product & Experience, Brand, Enterprise Supplier Management, Capital One Ventures, External Affairs, and Capital One...

  • Sr Project Manager

    2 weeks ago


    Richmond, United States Vertex Elite LLC Full time

    Dear Sr Project Manager , Vertex Elite is looking for Sr Project Manager. Please share your profile, if you are looking for a job.Job Location : 1220 Bank St, Richmond, VA 23219(Must Need Local Only)(HYBRID,ONSITE)Work Authorization : USC/GC/GC-EAD/H4-EAD/L2EAD/H1BRequired Skills Manage working relationships with key stakeholders, including executive...

  • Sr Project Manager

    2 weeks ago


    Richmond, United States Vertex Elite LLC Full time

    Dear Sr Project Manager , Vertex Elite is looking for Sr Project Manager. Please share your profile, if you are looking for a job.Job Location : 1220 Bank St, Richmond, VA 23219(Must Need Local Only)(HYBRID,ONSITE)Work Authorization : USC/GC/GC-EAD/H4-EAD/L2EAD/H1BRequired Skills Manage working relationships with key stakeholders, including executive...


  • Greendale, WI, United States CarMax Full time

    CarMax Search used cars, research vehicle models, and compare cars, all online at carmax.com. 8116 - Midtown Office - 2220 W. Broad Street, Richmond, Virginia, 23220 Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past...

  • Risk Governance

    4 weeks ago


    Vienna, VA, United States ALTA IT Services Full time

    Risk Governance & Frameworks Risk Analyst If the following job requirements and experience match your skills, please ensure you apply promptly. Location: Vienna, VA or Pensacola, FL Hybrid: 2-3 days a week Pay Rate: Open to Both C2C and W2 options Position Type: Multiyear Contract Responsibilities include: Collaborate in the development and maturation of...

  • Risk Governance

    3 weeks ago


    Vienna, VA, United States ALTA IT Services Full time

    Risk Governance & Frameworks Risk Analyst Apply (by clicking the relevant button) after checking through all the related job information below. Location: Vienna, VA or Pensacola, FL Hybrid: 2-3 days a week Pay Rate: Open to Both C2C and W2 options Position Type: Multiyear Contract Responsibilities include: Collaborate in the development and maturation of...


  • Richmond, California, United States eTek IT Services, Inc. Full time

    About the RoleeTek IT Services, Inc. is seeking a highly skilled Cybersecurity Risk Management Specialist to join our team in Richmond, Virginia. This 12-month contract position offers a high potential for extension and provides an excellent opportunity for professional growth.Job SummaryThe successful candidate will be responsible for supporting the VDOT...

  • Risk Nurse Manager

    4 weeks ago


    Bryant, AR, United States Clinical Management Consultants Full time

    A reputable, short-term acute care hospital in a charming Arkansas suburb actively seeks a dedicated Risk Nurse Manager to join their team.  This comprehensive health facility offers full-service care. The acute care facility is known for its specialization in Emergency Services, Behavioral Health, and Cardiac Care. The Risk Nurse Manager will flourish in...


  • Hicksville, NY, United States Flagstar Bank Full time

    Pay Range: 140K -232K JOB SUMMARY The Senior Operational Risk Manager is a critical role within the 2nd Line of Defense, responsible for supporting the Head of Operational Risk Management in identifying, assessing, and mitigating operational risks across the organization. The Senior Operational Risk Manager will oversee one or multiple teams of risk...


  • , MO, United States Coatue Management L.L.C. Full time

    Lead is a fintech building banking infrastructure for embedded financial products and services. We operate an FDIC-insured bank headquartered in Kansas City, Missouri. Additionally, we have offices in San Francisco, Sunnyvale, and New York City, where our technical, product, design, and legal teams operate. We are built for a constantly evolving financial...


  • Richmond, United States Capital One Full time

    West Creek 1 (12071), United States of America, Richmond, VirginiaSr. Associate, Risk Management - Card ACT TeamRisk Managers at Capital One are highly motivated Risk Management professionals with excellent organizational and communication skills. They have a high level of exposure across lines of business and have the opportunity to work with Executives to...


  • Chicago, IL, United States Northern Trust Full time

    About Northern Trust: Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring...


  • Chicago, IL, United States Northern Trust Full time

    About Northern Trust: Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring...


  • Pendleton, OR, United States Clinical Management Consultants Full time

    A rewarding opportunity has just become available for the Hospital Risk Management Coordinator at a beloved hospital in Northeast Oregon!Nestled in a picturesque region, this 25-bed critical access hospital and community healthcare facility offers a wide range of services designed to meet the needs of its diverse patient population. With a focus on...

  • Sr. Tax Manager

    3 weeks ago


    Richmond, VA, United States Robert Half Full time

    DescriptionWe are on the lookout for a Sr. Tax Manager in Richmond, Virginia, United States. This role involves managing a range of tax-related tasks within the financial services industry. You will be expected to handle tax matters related to individual, corporate, and partnership clients, deliver tax projections, conduct tax research, and engage in special...


  • Seattle, WA, United States Amazon Full time

    Sr. Risk Manager, Global Product and Food Safety Job ID: 2809031 | Amazon.com Services LLC The Regulatory Intelligence, Safety and Compliance (RISC) team's charter is to protect Amazon customers from products that are illegal, illegally marketed, unsafe, or otherwise prohibited by Amazon policies. The Product Safety policy lead will own analysis and risk...