Demo

Manager, Information Security Risk Management

Hearst
Charlotte, NC Full Time
POSTED ON 2/22/2025
AVAILABLE BEFORE 3/21/2025
Job Description

Hearst Technology, Inc, Information Security Office seeks a Manager, Information Security Risk Management. The Manager, Information Security Risk Management is responsible for assessing risk and managing risk information for the organization and key business units. This position assesses information security risk within essential technology functions, key business processes, documentation, and collaborates with key business leaders to assist in reducing risk and maturing the overall control environment. This position will also support Audit and Compliance functions within Hearst, focusing on PCI and HIPAA.

Team Alignment: Governance, Risk, and Compliance (GRC) Team. The GRC Team is multi-faceted and focuses on driving business value. Our mission is to establish an integrated program that ensures the overall effectiveness of capabilities that impact information security across business units globally.

  • Perform security risk reviews, risk assessments and gap assessments on key business processes and new and existing technologies. Subsequently, work with various business units, as needed, to ensure controls are adequate, appropriate, and effective and that mitigation and remediation plans are in place.
  • Maintain the IT risk register and risk dashboard keeping risks, and their response plans up to date; will be required to work with cross-functional teams and businesses.
  • Prepare detailed recurring risk management reports with associated metrics.
  • Support the implementation of a risk program including enhancing processes supporting accountability, exception requests, and overall risk reduction in accordance with NIST and COBIT Cybersecurity frameworks.
  • Support vendor due-diligence process and help define overall third-party risk management efforts.
  • Support risk-focused governance entities such as forums and steering committees.
  • Support internal and external audit processes for relevant compliance areas including NIST CSF, NIST 800-53, PCI-DSS, HIPAA, SOX, and other external and internal requirements.
  • Support key capabilities and processes across the GRC function in support of the Hearst Information Security Office using an Agile methodology approach to delivering work products and key services.
  • Work collaboratively with regional and global partners in other functional units; ability to navigate a complex organization; to influence and lead people across cultures at a senior level. Collaboratively interface with global IT and business partners to provide guidance and support.
  • Design and implement improvements in risk-related documentation.
  • Other related duties as assigned.

Who You Are: As a mid-level position, comfort and experience with all aspects of governance, risk, and compliance is required.

Technical Skills

  • Experience with IT governance, risk, and compliance management in a large global environment, while working with geographically dispersed, multidisciplinary teams.
  • Experience conducting risk assessments and managing risk across departments and functions.
  • Strong foundation in PCI and HIPAA compliance requirements and testing.
  • Familiarity with an integrated risk management platform.
  • Familiarity with security frameworks, particularly NIST and COBIT Cybersecurity Frameworks and HITRUST.
  • Basic understanding and knowledge of technical fundamentals such as networking concepts, cloud computing, application development, and security best practices.
  • Proficiency with Word, Excel, PowerPoint, JIRA, SharePoint.
  • Experience with GRC and risk management platforms such as Prevalent and TruOps is desired.

Soft Skills

  • Strong work ethic with attention to detail and demonstrated analytical abilities.
  • Attention to detail, verbal and written communication, and initiative; able to apply constructive feedback to enhance managing risk.
  • Strong presentation skills with the ability to articulate complex problems and solutions through concise and clear messaging.
  • Self-motivated with excellent planning and organizational skills; and the ability to prioritize tasks to meet deadlines and effectively manage changing priorities.
  • Professional customer orientation with a strong commitment to providing a high standard of customer satisfaction.
  • Ability to deliver client-ready documentation and participate in relevant client meetings; able to work across teams effectively and efficiently.
  • Working understanding of project management principles, processes, and documentation.
  • Ability to collaborate with internal and external stakeholders.

Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, or equivalent.
  • Minimum 5 years of relevant experience in a risk management role with at least 2 years of practical experience in Audit and Compliance.
  • Industry standard certification such as CISA, CRISC, CISM, ARM, CISSP, ISO 27001, ISO 27005 is desired.

About Us

Hearst is one of the nation’s largest global, diversified information, services and media companies.

Hearst has been innovating for more than a century, leading with purpose, integrity and a culture of care, with a mission to inform audiences and improve lives.

The company’s diverse portfolio includes global financial services leader Fitch Group; Hearst Health, a group of medical information and services businesses; Hearst Transportation, which includes CAMP Systems International, a major provider of software-as-a-service solutions for managing maintenance of jets and helicopters; ownership in cable television networks such as A&E, HISTORY, Lifetime and ESPN; 35 television stations; 24 daily and 52 weekly newspapers; digital services businesses; and more than 200 magazines around the world.

Hearst is always moving forward, investing in healthcare solutions to improve patient outcomes and technology that curbs emissions; providing vital analysis, data and software to the global financial services industry; delivering important service and investigative journalism; and inspiring audiences with sports and entertainment programming.

With a commitment to maintaining the highest quality in its products and services, Hearst is dedicated to serving the communities it operates in, both civically and philanthropically.

Hearst is an Equal Employment Opportunity employer. We do not discriminate in hiring on the basis of race, color, national origin, religion, creed, sex or gender, gender identity, gender expression, sexual orientation, age, physical or mental disability, military or veteran status, or any other characteristic protected by federal, state, or local law.

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Manager, Information Security Risk Management?

Sign up to receive alerts about other jobs on the Manager, Information Security Risk Management career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$101,856 - $146,479
Income Estimation: 
$73,266 - $131,599
Income Estimation: 
$148,382 - $214,197
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Hearst

Hearst
Hired Organization Address Oklahoma, OK Full Time
Job Description KOCO-TV is looking for an organized, detail-oriented team player with exceptional written and verbal ski...
Hearst
Hired Organization Address Greenville, SC Full Time
Job Description Local News Traffic Anchor Reporter WYFF 4, the NBC affiliate in Greenville, SC, is now hiring a Traffic ...
Hearst
Hired Organization Address Carmel, IN Full Time
Job Description In Some Jobs You Take Orders. In This One, You Write History. Join the healthcare information technology...
Hearst
Hired Organization Address Tampa, FL Full Time
Job Description The DevOps Engineer will be instrumental in bridging the gap between development and operations, ensurin...

Not the job you're looking for? Here are some other Manager, Information Security Risk Management jobs in the Charlotte, NC area that may be a better fit.

Manager, Information Security Risk Management

Hearst Media Services, Charlotte, NC

Business Data Steward Manager- Risk and Finance

Information Technology Senior Management Forum, Charlotte, NC

AI Assistant is available now!

Feel free to start your new journey!