Manager, Governance Risk and Compliance
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
Select how often (in days) to receive an alert:
Create Alert
Auto req
Title:
Manager, Governance Risk and Compliance
Job Function:
Information Technology
Location:
JUNEAU
Workplace Category:
Onsite
Company:
Harley-Davidson Motor Company
Full or Part-Time:
Full Time
Shift: SHIFT1
In 1903, out of a small shed in Milwaukee, Wisconsin, four young men lit a cultural wildfire that would grow and spread across geographies and generations. Their innovation and imagination for what was possible on two wheels sparked a transportation revolution that would make Harley-Davidson the most recognizable motorcycle brand in the world. Today, we continue to define motorcycle culture, evoking soul-stirring emotion reflected in every product and experience we deliver - like we have for well over a century and will for generations to come.
Are you ready to ride with us?
Harley-Davidson Motor Company, founded in a humble Milwaukee backyard shed in 1903, still calls the city home. Today, its Corporate Campus includes a 4.8-acre public park—a welcoming green space open to all. Join our team as aMgr Governance Risk and Compliance.
Job SummaryThe Manager of Harley-Davidson, Inc’s Technology Governance, Risk and Compliance (GRC) reports to the Chief Information Security and Privacy Officer and leads Harley-Davidson’s global information risk management and IT compliance program. The GRC leader is accountable for overseeing and coordinating the IT and cybersecurity program objectives needed to achieve and maintain HDI’s compliance with regulatory requirements. The position serves as a key interface among internal and external compliance bodies, auditors, technology teams, and business functions to ensure HDI’s IT general control environment is documented and operating effectively, and that information risks are reported to management for decision‑making and action when necessary.
Job Responsibilities- Build and maintain strong business partnerships across key areas at a senior leadership level, bridging their understanding of GRC concepts and requirements with an understanding of regional and global business practices
- Develop and implement processes to map IT general controls to established GRC standards and frameworks enabling efficient monitoring and reporting of regulatory compliance and risks.
- Oversee audit testing of general IT controls, report on identified exceptions and deficiencies, guide the development of management action plans and elevate priority issues.
- Manage and facilitate a secured process for all HR/Legal/Ethics IT/Security-related Investigations
- Work with IT Senior Leadership to identify, assess, and bring visibility to the most significant IT security risks across the GIS organization while ensuring the appropriate resources are assigned to remediate risks.
- High School Diploma or Equivalent Required
- Bachelor's Degree in business management, information systems or a related discipline
- Master's Degree in related field is Preferred
- Industry-recognized certification such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent is preferred
Required
- Typically requires a minimum of 8 years of related experience.
- Subject matter expert in IT compliance and auditing frameworks, practices, policies, standards, and procedures:
- Sarbanes‑Oxley Act of 2002 (SOX)
- Control Objectives for Information and Related Technologies (COBIT)
- National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
- System and Organization Controls (SOC) 1 and 2
- Payment Card Industry Data Security Standard (PCI DSS)
ISO 27001/2, or equivalent - Three Lines of Defense Model
- Demonstrated experience working in an enterprise-level Information Security
- Office with global accountabilities. Direct experience leading GRC processes with business leaders and managers.
- Ability to define and establish comprehensive procedures that integrate with key business processes to ensure cybersecurity standards and best practices are part of compliance and risk management by design
- Excellent communication and presentation skills with demonstrated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).