×
Register Here to Apply for Jobs or Post Jobs. X

Governance, Risk & Compliance Manager; IT

Job in Atlanta, Fulton County, Georgia, 30309, USA
Listing for: Carter's/OshKosh
Full Time position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Consultant, IT Project Manager
Job Description & How to Apply Below
Position: Governance, Risk & Compliance Manager (IT)
** Serving the needs of all families with young children,
** Carter's Inc. is the largest North American apparel retailer exclusively for babies and young children, encompassing Carter's, Osh Kosh B'gosh, Skip
* Hop and Little Planet brands. Meaningful work, constant learning, genuine people, and a community guided by core values that promote inclusion and innovation is in everything we do. There are many reasons to build your career at Carter's.

** How you'll make an impact:*
* As Carter's accelerates its use of AI technologies - including generative AI assistants, AI-enabled SaaS applications, MCP (Model Context Protocol) connectors, and agentic workflows - this role will ensure that AI adoption is governed with the same rigor applied to any other enterprise technology risk. The Manager will balance traditional IT GRC fundamentals with forward-looking AI governance leadership, making this a uniquely strategic position within the IT organization.

** AI Governance & Emerging Technology Risk (YR 1 - approx. 60%)*
* + Lead the development and implementation of Carter's AI Governance Framework, defining policies for acceptable use, data classification, model risk, vendor AI tools, and agentic workflows aligning with the company's ERM program.

+ Maintain a comprehensive inventory of AI tools and connectors deployed across the enterprise, including MCP servers, generative AI platforms, and AI-enabled SaaS integrations (e.g., Atlassian, Microsoft 365, Snowflake, Adobe Analytics).

+ Conduct and oversee AI risk assessments covering data exposure (including PII), identify potential vulnerabilities, unauthenticated access risks, and potential risk exposure in MCP connector packages.

+ Define and enforce controls for AI connector permissions, least-privilege access, credential management, and data loss prevention in AI workflows.

+ Monitor the AI regulatory landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, state AI laws) and translate requirements into actionable controls and policy updates for Carter's.

+ Ensure AI governance aligns with data privacy obligations (e.g., CCPA, COPPA, GDPR) applicable to Carter's customer base, which includes children's products.

+ Provide support to the Carters AI COE team and assist with AI Governance across multiple departments.

** Compliance & Regulatory Management (40%)*
* + Oversee compliance with applicable regulatory frameworks and standards including SOX ITGC, PCI DSS, NIST (Cybersecurity and AI), and CCPA etc.

+ Manage the IT control testing calendar, coordinate evidence collection, and liaise with internal and external auditors throughout audit engagements.

+ Track remediation of audit findings and control deficiencies, providing regular status reporting to the Director of IT GRC and leadership.

+ Support enterprise IT privacy program activities in coordination with the Legal and IT teams, particularly where technology systems process personal data.

** We'd Love to hear from you if: (Requirements section)*
* ** Must have:*
* + At Least a bachelor's degree in a technical field of studies (Mathematics, Computer Science, Accounting, etc.)

+ 7+ years of progressive experience in IT Governance Risk Compliance (GRC), information security, risk management, or a related discipline

+ 7+ years of experience related to building and implementing IT Governance Risk Management programs

+ 2+ years of direct involvement in AI governance, AI risk assessment, or significant responsibility for AI tool security and compliance.

+ Professional certification (CISSP, CISA, CISM, CGEIT, CRISC, AAIA, AAIR or similar)

+ Strong foundational knowledge of IT GRC frameworks: NIST CSF, NIST AI, ISO 27001, COBIT, SOX ITGC, PCI DSS, and SOC 2.

+ Working knowledge of AI technologies, including…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary