Manager, Second Line GRC

3 months ago


Atlanta GA United States Delta Air Lines, Inc. Full time

How you'll help us Keep Climbing (overview & key responsibilities)
Join Delta IT on our journey to becoming the best IT organization in the airline industry.

Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are looking for team members to help us realize our vision.

Delta IT employees are thinkers, doers, innovators.

We are proactive.

We are collaborative.

We deliver impact to our customers.

Join us on our transformation journey in becoming a world-class IT organization at the world's best airline

YOUR RESPONSIBILITIES IN THIS ROLE:

As a manager, Second Line GRC, you will be responsible for overseeing the Second Line GRC team within the Information Technology area that is focused on monitoring, tracking and reporting risk within the Delta organization. This role will partner with other teams throughout the Delta organization to identify, assess, track, report and validate risks and the implementation of controls throughout the organization. The Manager will balance their time between technical thought-leadership, hands-on solution collaboration, and talent development. This role provides technical guidance and mentoring to the team to achieve high-quality results. The ideal candidate will have excellent organizational, communication, and management skills, along with an ability to lead training sessions and workshops for staff members.

* Develop, maintain, and support an IT Risk management program to include risk identification, measurement/prioritization, mitigation, and reporting (in partnership with the Governance Manager).
* Oversee development and implementation of high-level control architectures, including preventive, detective, and corrective controls.
* Apply assessment data of identified threats in risk decision making.
* Knowledge of industry indicators useful for identifying technology trends. Assess and communicate the potential risk of these trends to Delta. Recommend controls to mitigate the risk.
* Through a close partnership with the Threat Intelligence team, maintain knowledge of current and emerging threats, translate threats to potential risk, and identify possible risk mitigation strategies.
* Acquire and maintain a working knowledge of relevant laws, regulations, policies, standards, and compliance obligations.
* Advise senior leadership of changes affecting Delta’s risk posture.
* Assure successful implementation of Information Security requirements and controls.
* Lead Information Security assessment process, blending industry best practices with Delta’s culture and risk posture.
* Collaborate and partner with other risk organizations at Delta. Align IT Risk’s approach with Delta’s risk tolerance/risk management approach where possible.
* Leverage industry best practices for evaluating, implementing, and disseminating Information Security internal assessments, monitoring, detecting, and remediation.
* Represent the GRC team on internal committees related to key risk areas (like vulnerability management).
* Create auditable evidence of security measures.
* Develop risk mitigation strategies to resolve vulnerabilities and recommend security changes as needed.
* Develop specific countermeasures and risk mitigation strategies.
* Provide guidelines for performance of, and conduct, a risk analysis whenever an application undergoes a major change.
* Tackle "big" problems, provide options, and drive resolution.
* Provide consulting/thought leadership for Information Security, IT, and the business.
* Work as a member of the broader GRC, IT and Delta teams. Do what’s right for Delta.
* Ensure up to date process and procedure documentation for the team.
* Identify process improvement/automation opportunities and innovate new ways of doing things.
* Communicate, and deliver, the value of Information Security throughout all of Delta.
* Lead with integrity and a positive attitude.
* Provide leadership and oversight to a high performing team of Delta Information Security professionals to ensure the confidentiality, integrity, and availability of information.
* Meet with staff on a timely basis to conduct performance evaluations and provide feedback. Provide ongoing coaching, mentoring, and training to develop and encourage employee performance and development.
* Develop strategic and operational plans for the work group, manage execution, drive improvements, and measure results.
* Define metrics to accurately convey risk, team performance and measure against goals.
* Drive awareness and knowledge of security.
* Perform special projects as assigned, while effectively manage time with competing priorities.
* Build highly motivated and result-oriented team.


What you need to succeed (minimum qualifications)
*
Develop, maintain, and support an IT Risk management program to include risk identification, measurement/prioritization, mitigation, and reporting (in partnership with the Governance Manager). * Oversee development and implementation of high-level control architectures, including preventive, detective, and corrective controls.
* Apply assessment data of identified threats in risk decision making.
* Knowledge of industry indicators useful for identifying technology trends.
* Assess and communicate the potential risk of these trends to Delta.
* Recommend controls to mitigate the risk.
* Through a close partnership with the Threat Intelligence team, maintain knowledge of current and emerging threats, translate threats to potential risk, and identify possible risk mitigation strategies.
* Acquire and maintain a working knowledge of relevant laws, regulations, policies, standards, and compliance obligations.
* Advise senior leadership of changes affecting Delta’s risk posture.
* Assure successful implementation of Information Security requirements and controls
* Lead Information Security assessment process, blending industry best practices with Delta’s culture and risk posture.
* Collaborate and partner with other risk organizations at Delta.
* Align IT Risk’s approach with Delta’s risk tolerance/risk management approach where possible.
* Leverage industry best practices for evaluating, implementing, and disseminating Information Security internal assessments, monitoring, detecting, and remediation.
* Represent the GRC team on internal committees related to key risk areas (like vulnerability management).
* Create auditable evidence of security measures.
* Develop risk mitigation strategies to resolve vulnerabilities and recommend security changes as needed.
* Develop specific countermeasures and risk mitigation strategies.
* Provide guidelines for performance of, and conduct, a risk analysis whenever an application undergoes a major change.
* Tackle "big" problems, provide options, and drive resolution.
* Provide consulting/thought leadership for Information Security, IT, and the business.
* Work as a member of the broader GRC, IT and Delta teams.
* Do what’s right for Delta.
* Ensure up to date process and procedure documentation for the team.
* Identify process improvement/automation opportunities and innovate new ways of doing things.
* Communicate, and deliver, the value of Information Security throughout all of Delta.
* Lead with integrity and a positive attitude.
* Provide leadership and oversight to a high performing team of Delta Information Security professionals to ensure the confidentiality, integrity, and availability of information.
* Meet with staff on a timely basis to conduct performance evaluations and provide feedback.
* Provide ongoing coaching, mentoring, and training to develop and encourage employee performance and development.
* Develop strategic and operational plans for the work group, manage execution, drive improvements, and measure results.
* Define metrics to accurately convey risk, team performance and measure against goals.
* Drive awareness and knowledge of security.
* Perform special projects as assigned, while effectively manage time with competing priorities.

*
Consistently prioritizes safety and security of self, others, and personal data.
*
Embraces diverse people, thinking, and styles.
*
Possesses a high school diploma, GED, or high school equivalency.
*
Is at least 18 years of age and has authorization to work in the United States.


What will give you a competitive edge (preferred qualifications)
* B.S. degree in Computer Science, Computer Engineering, Information Assurance, a related field, or equivalent experience.
* Professional certifications such as CISSP, CISM, OSCP and CEH
* Experience with RSA Archer or equivalent GRC tool.
* Experience delivering high quality results using Agile methodology


Benefits and Perks to Help You Keep Climbing
WHY YOU’LL LOVE DELTA

Our culture is rooted in a shared dedication to living our values - Care, Integrity, Resilience, Servant Leadership, and Teamwork - every day, in everything we do. At Delta, our people are our success. At the heart of what we offer is our focus on Sharing Success with Delta employees. Exploring a career at Delta gives you a chance to see the world while earning great compensation and benefits to help you keep climbing along the way:

* Competitive salary, industry-leading profit sharing program, and performance incentives
* 401(k) with generous company contributions up to 9%
* Paid time off including vacation, holidays, paid personal time, maternity and parental leave
* Comprehensive health benefits including medical, dental, vision, short/long term disability and life benefits
* Family care assistance through fertility support, surrogacy and adoption assistance, lactation support, subsidized back-up care, and programs that help with loved ones in all stages
* Holistic Wellbeing programs to support physical, emotional, social, and financial health, including access to an employee assistance program offering support for you and anyone in your household, free financial coaching, and extensive resources supporting mental health
* Domestic and International space-available flight privileges for employees and eligible family members
* Career development programs to achieve your long-term career goals
* World-wide partnerships to engage in community service and innovative goals created to focus on sustainability and reducing our carbon footprint
* Business Resource Groups created to connect employees with common interests to promote inclusion, provide perspective and help implement strategies
* Recognition rewards and awards through the platform Unstoppable Together
* Access to over 500 discounts, specialty savings and voluntary benefits through Deltaperks such as car and hotel rentals and auto, home, and pet insurance, legal services, and childcare



  • Atlanta, GA, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, United States Delta Air Lines, Inc. Full time

    Job DescriptionHow you'll help us Keep Climbing (overview & key responsibilities)Join Delta IT on our journey to becoming the best IT organization in the airline industry.Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative...

  • Manager, GRC

    3 weeks ago


    Overland, MO, United States Clayco Full time

    About UsClayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $5.8 billion in revenue for 2023, Clayco specializes in the "art and science of...


  • San Antonio, TX, United States Insight Global Full time

    Location: San Antonio, TXDuration: 12-Month Contract w/ extensions Required Skills & Experience- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.-Minimum of 3 years of experience in a cybersecurity role with a focus on GRC.- Proficiency in CJIS system configurations and NIST controls.-Strong analytical, problem-solving, and...

  • GRC Platform Lead

    3 weeks ago


    New York, NY, United States Solomon Page Full time

    Our direct global corporate financials client is seeking to add a dynamic GRC Platform Product Lead to their team in a long term contract consulting capacity (possibility of conversion to FTE down the line for the right candidate). This role requires a hands-on leader who is equally comfortable driving execution, managing projects, and engaging with...


  • atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • Atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...

  • IT GRC Manager OH

    5 days ago


    Columbus, OH, United States Creative Financial Staffing Full time

    IT GRC Manager Position Overview: We are looking for a proactive and experienced IT Governance, Risk, and Compliance (GRC) Manager to become a key member of our team. In this position, you will oversee and enhance the organization's IT GRC program, with an emphasis on SOX compliance, application and data transfer controls, the accuracy and completeness of...

  • IT GRC Manager WI

    7 days ago


    Madison, WI, United States Creative Financial Staffing Full time

    IT GRC Manager Position Overview: We are looking for a proactive and experienced IT Governance, Risk, and Compliance (GRC) Manager to become a key member of our team. In this position, you will oversee and enhance the organization's IT GRC program, with an emphasis on SOX compliance, application and data transfer controls, the accuracy and completeness of...

  • GRC Analyst

    3 weeks ago


    Shelton, CT, United States Ovise Full time

    Ovise is exclusively partnered with one of the largest restaurant and franchisee brands in the world! They are looking to build out their GRC function, and as a GRC analyst, you will be directly involved with this initiative.The GRC Analyst will be responsible for assessing, managing, and mitigating risks related to an organization's information assets. This...


  • Ashburn, VA, United States Infinitive Full time

    *Candidates must be local to the Washington D.C. metro area. About Infinitive:Infinitive is a data and AI consultancy that enables its clients to modernize, monetize and operationalize their data to create lasting and substantial value. We possess deep industry and technology expertise to drive and sustain adoption of new capabilities. We match our people...


  • McLean, VA, United States Convergenz Full time

    Risk / GRC Analyst - Capital Markets and Mortgage RequiredEnsuring they are compliant with Mortgage and Capital Markets guidelines. Risk assessments on a quarterly bases, issue remediation- helping team on incident write ups, operational breakdown, control testing, adhoc projects- process documentation, helping with Gap Assessments. More on compliance /...

  • SAP Security Lead

    3 weeks ago


    Atlanta, United States Norfolk Southern Full time

    Requisition 38026: B4 SAP Security Lead (S/4HANA, GRC, IDM) A resume helps you stand out to hiring managers and recruiters; your resume communicates your experience and your brand. While it is not required, we encourage you to include an up-to-date resume along with a completed job application to give you the best opportunity to be considered. A complete...


  • Atlanta, United States OneTrust Full time

    Job DescriptionJob DescriptionStrength in Trust OneTrust unlocks the full potential of data and AI, securely and responsibly. Our platform enforces the secure handling of company data, empowering organizations to drive innovation responsibly while mitigating risks. With a comprehensive suite of solutions spanning data and AI security, privacy, governance,...


  • , FL, United States Second Avenue Full time

    About the Role:The Community Compliance Manager will oversee a team of specialists responsible for ensuring the company’s single-family rental properties comply with HOA and municipality regulations. This key leadership role requires a strategic thinker who can set goals, mentor team members, and collaborate with various departments to enhance operational...


  • Atlanta, United States OneTrust Full time

    Job DescriptionJob DescriptionStrength in Trust OneTrust unlocks the full potential of data and AI, securely and responsibly. Our platform enforces the secure handling of company data, empowering organizations to drive innovation responsibly while mitigating risks. With a comprehensive suite of solutions spanning data and AI security, privacy, governance,...

  • GRC Architect

    4 weeks ago


    Chicago, IL, United States Cognizant Full time

    Job Title : GRC Architect Location-Chicago, IL Roles and Responsibilities 1. Must have hands on experience in Security Domain. 2. Single point of contact for Compliance Requirement. 3. Delivery progress measurement, Weekly Dashboard and status reporting on project health to Client and Cognizant Leadership. 4. Perform security and compliance assessments on...


  • Chicago, IL, United States Request Technology, LLC Full time

    ***We are unable to sponsor for this permanent full-time role******Position is bonus eligible***Prestigious Financial Institution is currently seeking a GRC Compliance Monitoring Manager, preferably with RSA Archer experience. Candidate will provide execution and oversight for the programs that oversee compliance with regulatory and internal control...