Manager, Second Line GRC

2 months ago


Atlanta, United States Delta Air Lines, Inc. Full time

How you'll help us Keep Climbing (overview & key responsibilities)
Join Delta IT on our journey to becoming the best IT organization in the airline industry.

Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are looking for team members to help us realize our vision.

Delta IT employees are thinkers, doers, innovators.

We are proactive.

We are collaborative.

We deliver impact to our customers.

Join us on our transformation journey in becoming a world-class IT organization at the world's best airline

YOUR RESPONSIBILITIES IN THIS ROLE:

As a manager, Second Line GRC, you will be responsible for overseeing the Second Line GRC team within the Information Technology area that is focused on monitoring, tracking and reporting risk within the Delta organization. This role will partner with other teams throughout the Delta organization to identify, assess, track, report and validate risks and the implementation of controls throughout the organization. The Manager will balance their time between technical thought-leadership, hands-on solution collaboration, and talent development. This role provides technical guidance and mentoring to the team to achieve high-quality results. The ideal candidate will have excellent organizational, communication, and management skills, along with an ability to lead training sessions and workshops for staff members.

* Develop, maintain, and support an IT Risk management program to include risk identification, measurement/prioritization, mitigation, and reporting (in partnership with the Governance Manager).
* Oversee development and implementation of high-level control architectures, including preventive, detective, and corrective controls.
* Apply assessment data of identified threats in risk decision making.
* Knowledge of industry indicators useful for identifying technology trends. Assess and communicate the potential risk of these trends to Delta. Recommend controls to mitigate the risk.
* Through a close partnership with the Threat Intelligence team, maintain knowledge of current and emerging threats, translate threats to potential risk, and identify possible risk mitigation strategies.
* Acquire and maintain a working knowledge of relevant laws, regulations, policies, standards, and compliance obligations.
* Advise senior leadership of changes affecting Delta’s risk posture.
* Assure successful implementation of Information Security requirements and controls.
* Lead Information Security assessment process, blending industry best practices with Delta’s culture and risk posture.
* Collaborate and partner with other risk organizations at Delta. Align IT Risk’s approach with Delta’s risk tolerance/risk management approach where possible.
* Leverage industry best practices for evaluating, implementing, and disseminating Information Security internal assessments, monitoring, detecting, and remediation.
* Represent the GRC team on internal committees related to key risk areas (like vulnerability management).
* Create auditable evidence of security measures.
* Develop risk mitigation strategies to resolve vulnerabilities and recommend security changes as needed.
* Develop specific countermeasures and risk mitigation strategies.
* Provide guidelines for performance of, and conduct, a risk analysis whenever an application undergoes a major change.
* Tackle "big" problems, provide options, and drive resolution.
* Provide consulting/thought leadership for Information Security, IT, and the business.
* Work as a member of the broader GRC, IT and Delta teams. Do what’s right for Delta.
* Ensure up to date process and procedure documentation for the team.
* Identify process improvement/automation opportunities and innovate new ways of doing things.
* Communicate, and deliver, the value of Information Security throughout all of Delta.
* Lead with integrity and a positive attitude.
* Provide leadership and oversight to a high performing team of Delta Information Security professionals to ensure the confidentiality, integrity, and availability of information.
* Meet with staff on a timely basis to conduct performance evaluations and provide feedback. Provide ongoing coaching, mentoring, and training to develop and encourage employee performance and development.
* Develop strategic and operational plans for the work group, manage execution, drive improvements, and measure results.
* Define metrics to accurately convey risk, team performance and measure against goals.
* Drive awareness and knowledge of security.
* Perform special projects as assigned, while effectively manage time with competing priorities.
* Build highly motivated and result-oriented team.


What you need to succeed (minimum qualifications)
*
Develop, maintain, and support an IT Risk management program to include risk identification, measurement/prioritization, mitigation, and reporting (in partnership with the Governance Manager). * Oversee development and implementation of high-level control architectures, including preventive, detective, and corrective controls.
* Apply assessment data of identified threats in risk decision making.
* Knowledge of industry indicators useful for identifying technology trends.
* Assess and communicate the potential risk of these trends to Delta.
* Recommend controls to mitigate the risk.
* Through a close partnership with the Threat Intelligence team, maintain knowledge of current and emerging threats, translate threats to potential risk, and identify possible risk mitigation strategies.
* Acquire and maintain a working knowledge of relevant laws, regulations, policies, standards, and compliance obligations.
* Advise senior leadership of changes affecting Delta’s risk posture.
* Assure successful implementation of Information Security requirements and controls
* Lead Information Security assessment process, blending industry best practices with Delta’s culture and risk posture.
* Collaborate and partner with other risk organizations at Delta.
* Align IT Risk’s approach with Delta’s risk tolerance/risk management approach where possible.
* Leverage industry best practices for evaluating, implementing, and disseminating Information Security internal assessments, monitoring, detecting, and remediation.
* Represent the GRC team on internal committees related to key risk areas (like vulnerability management).
* Create auditable evidence of security measures.
* Develop risk mitigation strategies to resolve vulnerabilities and recommend security changes as needed.
* Develop specific countermeasures and risk mitigation strategies.
* Provide guidelines for performance of, and conduct, a risk analysis whenever an application undergoes a major change.
* Tackle "big" problems, provide options, and drive resolution.
* Provide consulting/thought leadership for Information Security, IT, and the business.
* Work as a member of the broader GRC, IT and Delta teams.
* Do what’s right for Delta.
* Ensure up to date process and procedure documentation for the team.
* Identify process improvement/automation opportunities and innovate new ways of doing things.
* Communicate, and deliver, the value of Information Security throughout all of Delta.
* Lead with integrity and a positive attitude.
* Provide leadership and oversight to a high performing team of Delta Information Security professionals to ensure the confidentiality, integrity, and availability of information.
* Meet with staff on a timely basis to conduct performance evaluations and provide feedback.
* Provide ongoing coaching, mentoring, and training to develop and encourage employee performance and development.
* Develop strategic and operational plans for the work group, manage execution, drive improvements, and measure results.
* Define metrics to accurately convey risk, team performance and measure against goals.
* Drive awareness and knowledge of security.
* Perform special projects as assigned, while effectively manage time with competing priorities.

*
Consistently prioritizes safety and security of self, others, and personal data.
*
Embraces diverse people, thinking, and styles.
*
Possesses a high school diploma, GED, or high school equivalency.
*
Is at least 18 years of age and has authorization to work in the United States.


What will give you a competitive edge (preferred qualifications)
* B.S. degree in Computer Science, Computer Engineering, Information Assurance, a related field, or equivalent experience.
* Professional certifications such as CISSP, CISM, OSCP and CEH
* Experience with RSA Archer or equivalent GRC tool.
* Experience delivering high quality results using Agile methodology


Benefits and Perks to Help You Keep Climbing
WHY YOU’LL LOVE DELTA

Our culture is rooted in a shared dedication to living our values - Care, Integrity, Resilience, Servant Leadership, and Teamwork - every day, in everything we do. At Delta, our people are our success. At the heart of what we offer is our focus on Sharing Success with Delta employees. Exploring a career at Delta gives you a chance to see the world while earning great compensation and benefits to help you keep climbing along the way:

* Competitive salary, industry-leading profit sharing program, and performance incentives
* 401(k) with generous company contributions up to 9%
* Paid time off including vacation, holidays, paid personal time, maternity and parental leave
* Comprehensive health benefits including medical, dental, vision, short/long term disability and life benefits
* Family care assistance through fertility support, surrogacy and adoption assistance, lactation support, subsidized back-up care, and programs that help with loved ones in all stages
* Holistic Wellbeing programs to support physical, emotional, social, and financial health, including access to an employee assistance program offering support for you and anyone in your household, free financial coaching, and extensive resources supporting mental health
* Domestic and International space-available flight privileges for employees and eligible family members
* Career development programs to achieve your long-term career goals
* World-wide partnerships to engage in community service and innovative goals created to focus on sustainability and reducing our carbon footprint
* Business Resource Groups created to connect employees with common interests to promote inclusion, provide perspective and help implement strategies
* Recognition rewards and awards through the platform Unstoppable Together
* Access to over 500 discounts, specialty savings and voluntary benefits through Deltaperks such as car and hotel rentals and auto, home, and pet insurance, legal services, and childcare



  • Atlanta, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, United States Delta Air Lines, Inc. Full time

    Job DescriptionHow you'll help us Keep Climbing (overview & key responsibilities)Join Delta IT on our journey to becoming the best IT organization in the airline industry.Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative...


  • Atlanta, GA, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, GA, United States Delta Air Lines, Inc. Full time

    How you'll help us Keep Climbing (overview & key responsibilities) Join Delta IT on our journey to becoming the best IT organization in the airline industry. Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are...


  • Atlanta, Georgia, United States OneTrust Full time

    Job Title: Information Security GRC ManagerOneTrust is seeking a highly skilled Information Security GRC Manager to join our team. As a key member of our InfoSec GRC team, you will be responsible for performing various governance, risk, and compliance activities, including customer assurance, risk management, audits, and policy development.About the RoleThis...

  • GRC Security Lead

    4 weeks ago


    Atlanta, Georgia, United States GSquared Group Full time

    Job Title: OneTrust GRC Security LeadJob Type: Contract Location: Atlanta area (Hybrid - 3 days in office) Job Description:GSquared Group is seeking a highly skilled OneTrust GRC Security Lead to partner with one of our key enterprise clients, a leading healthcare system in the Southeast, to assess and upgrade their existing OneTrust GRC environment.Key...

  • IT Risk Manager

    1 month ago


    Atlanta, Georgia, United States Delta Air Lines, Inc. Full time

    Job Title: Manager, Second Line GRCJob SummaryWe are seeking a highly skilled Manager, Second Line GRC to join our team at Delta Air Lines, Inc. This role will be responsible for overseeing the Second Line GRC team, which focuses on monitoring, tracking, and reporting risk within the Delta organization.Key ResponsibilitiesDevelop, maintain, and support an IT...


  • Atlanta, Georgia, United States OneTrust Full time

    Job Title: Information Security GRC ManagerOneTrust is seeking a highly skilled Information Security GRC Manager to join our team. As a key member of our InfoSec GRC team, you will be responsible for performing various governance, risk, and compliance activities, including customer assurance, risk management, audits, policies, and more.Key...

  • SAP GRC Director

    4 days ago


    Atlanta, Georgia, United States KPMG Full time

    About the Role:KPMG is seeking a highly skilled Director to lead our SAP Governance, Risk, and Compliance (GRC) practice. As a key member of our team, you will be responsible for providing expert guidance and oversight to clients on SAP GRC, SAP security, and SAP controls.Key Responsibilities:Support proposal and business development activities by...


  • Atlanta, Georgia, United States Diverse Lynx Full time

    We promote a diverse workforce across all levels in our company, Diverse Lynx LLC, which is an Equal Employment Opportunity employer.All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the...


  • Atlanta, Georgia, United States OneTrust Full time

    About the RoleWe are seeking a highly skilled Information Security GRC Manager to join our team at OneTrust. As a key member of our InfoSec GRC team, you will be responsible for performing various governance, risk, and compliance activities, including customer assurance, risk management, audits, and policy development.Key ResponsibilitiesDevelop and...


  • Atlanta, Georgia, United States GSquared Group Full time

    Job Title: OneTrust GRC Security LeadJob Summary:We are seeking a highly skilled OneTrust GRC Security Lead to join our team at GSquared Group. The ideal candidate will possess extensive knowledge of the OneTrust platform and a strong understanding of governance, risk management, and compliance (GRC) frameworks.Key Responsibilities:Conduct comprehensive...

  • SAP GRC Director

    4 days ago


    Atlanta, Georgia, United States KPMG Full time

    About the Role:KPMG is seeking a highly skilled Director to lead our SAP Governance, Risk, and Compliance (GRC) practice. As a key member of our team, you will be responsible for providing oversight and leadership to our professionals, ensuring the delivery of high-quality services to our clients.Key Responsibilities:Support proposal and business development...


  • Atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • Atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • Atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • atlanta, United States GSquared Group Full time

    Title: OneTrust GRC Security LeadTerms: 6 Month Contract + ExtensionsLocation: Atlanta area (Hybrid - 3 days in office)Role Details:GSquared Group is currently partnered with one of our key enterprise clients, one of the largest healthcare systems in the Southeast, to identify a highly skilled OneTrust GRC Security Lead with a strong technical background in...


  • Atlanta, Georgia, United States GSquared Group Full time

    Job Title: OneTrust GRC Security LeadJob Summary:We are seeking a highly skilled OneTrust GRC Security Lead to join our team at GSquared Group. The ideal candidate will possess extensive knowledge of the OneTrust platform, coupled with a robust understanding of governance, risk management, and compliance (GRC) frameworks.Key Responsibilities:Assessment &...

  • IT Risk Manager

    1 week ago


    Atlanta, Georgia, United States Delta Air Lines, Inc. Full time

    Job SummaryDelta Air Lines, Inc. is seeking a highly skilled IT Risk Manager to join our team. As a key member of our Information Technology department, you will be responsible for overseeing the Second Line GRC team and ensuring the effective management of IT risk within the organization.Key Responsibilities* Develop and maintain an IT Risk management...