Sr. Manager, IT Security - GRC
Listed on 2026-04-30
-
IT/Tech
Cybersecurity, Information Security
Who is Swire Coca-Cola? We are a family‑owned bottling company with a story spanning over two centuries. We are one of the largest bottlers of Coca‑Cola in North America and distribute more than 50 beverage brands and flavors creating joy for our customers every day. Our 8,000+ driven employees work hard as part of a team that delivers refreshment to over 30 million consumers across 13 states.
Begin a journey with us at Swire Coca‑Cola and belong to a community of dedicated team members who think big and believe in winning together.
Why you’ll love working at Swire Coca‑Cola:
Swire Coca‑Cola is committed to providing balance to support you in all aspects of your life, both at work and beyond. We offer the benefits you need for physical, financial, and emotional well‑being.
- Health coverage (3 medical options, dental and vision). 401(k) Retirement Plan w/company match
- Health Savings Accounts w/company match
- FREE virtual primary care, acute care and physical therapy
- FREE Employee Assistance Program
- Company paid (vacation, holidays, sick time, bereavement, jury duty, maternity/parental, disability leave and volunteer time)
- Discounted & free product
- Tuition reimbursement
- Opportunities for career advancement
Note:
Enrollment in a Swire Medical Plan is required for some benefits.
Job Level: 7
What does the Sr. Manager, Governance, Risk & Compliance (GRC) – Cybersecurity do at Swire Coca‑Cola?Swire Coca‑Cola is seeking a Sr. Manager, IT Security – GRC to lead and mature our cybersecurity governance, risk management, and compliance programs. This role is responsible for ensuring cybersecurity risks are identified, managed, and communicated effectively while aligning security controls with regulatory, contractual, and business requirements. The GRC Manager partners closely with IT Infrastructure, Security Operations, Legal, Internal Audit, and business leaders to enable secure and compliant operations across the enterprise.
This role requires a strong balance of cybersecurity expertise, risk management discipline, and business acumen, with the ability to translate technical security risks into clear business impact for executive and senior leadership audiences.
- Lead and mature the enterprise cybersecurity governance, risk, and compliance (GRC) program, including policies, standards, procedures, and metrics
- Maintain and align cybersecurity frameworks with industry standards such as NIST CSF, ISO 27001, CIS, and SOC 2
- Mature and oversee security risk tolerance, exception management, and control ownership processes
- Ensure cybersecurity governance aligns with enterprise risk management (ERM) objectives
- Lead cybersecurity risk assessments, control gap analyses, and third‑party risk assessments
- Maintain the enterprise cyber risk register, including risk scoring, treatment plans, and remediation tracking
Partner with technical and business teams to ensure risks are mitigated, transferred, or formally accepted - Translate technical threats and vulnerabilities into clear, business‑focused risk statements
- Manage cybersecurity compliance initiatives for regulatory, industry, and contractual obligations (e.g., SOC 2, ISO, SOX, HIPAA, PCI, privacy frameworks)
- Act as primary liaison for internal and external audits, coordinating evidence collection and remediation activities
- Support customer security assessments, due diligence requests, and RFP responses
- Monitor regulatory changes and assess organizational impact
- Develop and maintain cybersecurity risk and compliance metrics for leadership
- Create dashboards and reports that clearly communicate risk posture, trends, and remediation status
- Present risk assessments, recommendations, and program updates to senior leadership
- Lead, mentor, and develop GRC engineers, analysts or contributors
- Collaborate with Security Operations, Engineering, Legal, Internal Audit, and Procurement teams
- Promote risk‑aware decision‑making and a culture of security accountability
- Bachelor’s Degree in Information Security, Information Technology, Risk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).