Talent.com
Sr Mgr, Information Security
Sr Mgr, Information SecurityHD Supply • Brookhaven, GA, US
Sr Mgr, Information Security

Sr Mgr, Information Security

HD Supply • Brookhaven, GA, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]



Job Description:

The Senior Manager - Information Security Risk & Compliance is a hands-on leader responsible for executing and operating the organization's information security risk and compliance programs. This role directly performs risk assessments, supports audits, manages GRC tooling, and works closely with technical teams to remediate control gaps. The role balances leadership responsibilities with day-to-day execution and technical depth.
Key Responsibilities
Hands-On Risk Management
- Perform and lead information security risk assessments across applications, infrastructure, cloud environments, and business processes.
- Maintain risk registers, document findings, assign remediation actions, and track closure.
- Conduct threat modeling and control gap analyses in collaboration with engineering and security teams.
- Perform and review third-party/vendor security risk assessments and questionnaires.
Compliance & Audit Execution
- Directly manage compliance efforts for frameworks and regulations such as ISO 27001, SOC 2, PCI DSS, SOX, GDPR, or HIPAA (as applicable).
- Prepare audit evidence, coordinate walkthroughs, and respond to auditor and regulator requests.
- Execute control testing and validate control design and operating effectiveness.
- Track remediation plans and validate corrective actions.
Policy, Standards & Controls
- Draft, update, and maintain information security policies, standards, and procedures.
- Map technical and administrative controls to compliance requirements and business risks.
- Work hands-on with system owners to design and implement security controls.
GRC Tools & Metrics
- Administer and optimize GRC tools (e.g., Varonis, Lighbeam, Tenable, Auditboard etc).
- Build risk dashboards, compliance metrics, and executive-level reporting.
- Automate evidence collection and control monitoring where possible.
Cross-Functional Collaboration
- Work closely with IT, Cloud, DevOps, Security Operations, Legal, Privacy, and Internal Audit teams.
- Provide actionable security guidance during system design, cloud migrations, and vendor onboarding.
- Act as a subject matter expert for security risk and compliance inquiries.
Leadership & Mentorship
- Lead by example with direct execution while mentoring junior risk and compliance staff.
- Review work products, provide hands-on coaching, and ensure quality and consistency.
- Support hiring and onboarding of risk and compliance team members as needed.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, or related field.
- 8-12+ years of experience in information security, risk, compliance, or IT audit roles.
- Strong hands-on experience with risk assessments, audits, and control testing.
- Practical working knowledge of NIST CSF, ISO 27001/27002, SOC 2, and cloud security controls.
- Ability to independently manage multiple assessments and audits end-to-end.
Preferred Certifications
- CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Auditor, or equivalent.
Key Skills & Competencies
- Deep technical understanding of security controls and risk mitigation
- Strong documentation and evidence management skills
- Ability to translate compliance requirements into technical actions
- Comfortable working in fast-paced, hands-on environments
- Strong problem-solving and attention to detail

Job Summary

Manage and coordinate a team of Security Managers and Engineers. Ensure tight rigor and control over Security Operations and Audit processes.

Major Tasks, Responsibilities, and Key Accountabilities

  • Serves as an internal information security consultant to the organization. Effectively leads and or coordinates all internal dedicated security functions including but not limited to - patching, anti-virus, intrusion prevention, CERT response, log file monitoring, cross division security coordination, systems operational security testing, rule set analysis, threat detection and adaptation, as well as advent security related functions.
  • Initiates activities to create information security awareness within the organization.
  • Performs information security risk assessments, and acts as an internal auditor. Evaluates audit findings and drives remediation of identified control deficiencies.
  • Reviews all system-related security planning throughout the network and acts as a liaison to information systems.
  • Monitors compliance with information security policies and procedures, addressing problems with the appropriate department manager or data owner.
  • Oversees the security policy to ensure appropriateness. Provides training and consultation to ensure understanding of and compliance with established security standards and controls. Manages the Computer Security Incident Response Plan.
  • Manages the Risk Program including coordination and follow-up of the semi-annual risk assessment and development and implementation of business unit policies and standards.
  • Manages the business unit's audits and examinations. Works with management to put controls in place needed to comply with SOX and PCI regulatory requirements.

Nature and Scope

  • Solutions require analysis and investigation.
  • Achieves planned results by decisions and actions based on professional methods, business principles, and practical experience. May recommend/make decisions regarding new programs/initiatives that have significant impact to the business and carry consequences in unsuccessful endeavors.
  • Manages a larger team or multiple small teams through direction of subordinate management and/or supervisory staff.

Work Environment

  • Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable.
  • Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles.
  • Typically requires overnight travel less than 10% of the time.

Education and Experience

  • Typically requires BS/BA in a related discipline. Generally 7+ years of experience in a related field. May require certification. Advanced degree may offset less experience in some disciplines.

Our Goals for Diversity, Equity, and Inclusion

We are committed to creating a culture that promotes equity, respect, and advocacy for every HD Supply associate. We value the diversity of our people.

Equal Employment Opportunity

HD Supply is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.



[job_alerts.create_a_job]

Sr Mgr, Information Security • Brookhaven, GA, US

[internal_linking.similar_jobs]

Director, Intelligence Project Atlanta, GA; Jackson, MS; Miami, FL; Montgomery, AL; New Orleans, LA; Washington D.C.; Remote

Southern Poverty Law CenterAtlanta, GA, United States
[filters.remote]
[job_card.full_time]

Director, Intelligence ProjectThe SPLC is seeking a Director of Intelligence Project who is committed to dismantling white supremacy!The Intelligence Project (IP), perhaps SPLC's most well-known in...[internal_linking.show_more]

 • [job_card.promoted]

Cyber Security Program Manager II: 24-02439

Akraya IncAtlanta, Georgia, United States
[job_card.full_time]
[filters_job_card.quick_apply]

Primary Skills: Data Analytics, Cyber Threats, Graphic Design, Presentation skills, Security, Campaigns,.Duration: 12 Months (Possible Extension).Location Atlanta, GA (3LI-Hybrid).Pay Range: $70 - ...[internal_linking.show_more]

Sr. Compliance Officer

Telepathy, Inc.Atlanta, GA, United States
[job_card.full_time]

The Investment Compliance team is a department with a global function responsible for ensuring compliance with regulatory, prospectus, client-directed, and internal investment and operational restr...[internal_linking.show_more]

 • [job_card.promoted]

Information Security Communications Analyst (Remote)

Wallman Unlimited CompanyAtlanta, GA, United States
[filters.remote]
[job_card.full_time]

Job DescriptionJob DescriptionOur client, a highly regarded Am Law 100 firm, is seeking an Information Security Communications Analyst to support its enterprise-wide security awareness and training...[internal_linking.show_more]

 • [job_card.promoted]

Information Security Reporting & Analytics Consultant

ProEdit, Inc.Atlanta, Georgia, United States
[job_card.full_time]
[filters_job_card.quick_apply]

Information Security Reporting & Analytics Consultant.Contract Duration: 6 months, with possible extension.Location: Remote - Must be located and cleared to work in the U.ProEdit’s client, a global...[internal_linking.show_more]

Director of IT Security & Risk Strategy

CarolinaPowerTucker, GA, United States
[job_card.full_time]

A leading energy solutions provider in Tucker, Georgia is seeking a Director of IT-Security to develop and lead the IT Security function.Responsibilities include managing security strategy, oversee...[internal_linking.show_more]

 • [job_card.promoted]

Director Of Information Technology Operations

Jobright.aiAtlanta, GA, United States
[job_card.full_time]

Director Of Information Technology Operations.Director Of Information Technology Operations.Director Of Information Technology Operations.Director Of Information Technology Operations.Jobright is a...[internal_linking.show_more]

 • [job_card.promoted]

University Safety Operations Center Specialist

Savannah College of Art and DesignAtlanta, Georgia, US
[job_card.full_time]

As a university safety operations center specialist, you will monitor the CCTV system, focusing on university facilities and buildings, and oversee intrusion alarms.You will retrieve camera footage...[internal_linking.show_more]

 • [job_card.promoted]

Risk Analysis Sr. Manager

Bank of AmericaAtlanta, GA, United States
[job_card.full_time]

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.We do this by driving Responsible Growth and delivering for our clien...[internal_linking.show_more]

 • [job_card.promoted]

Azure Solutions Architect - Cloud Strategy & Security Lead

CIYIS LLCAtlanta, GA, United States
[job_card.full_time]

A technology solutions provider in Atlanta is seeking an Azure Solution Architect to join their dynamic team.This role involves designing, building, and deploying SaaS solutions within a Microsoft ...[internal_linking.show_more]

 • [job_card.promoted]

Senior Project Manager- Electronic Security

Diversified Foods and Seasonings, LLCAtlanta, GA, United States
[job_card.full_time]

Senior Project Manager In Electronic Security Systems (ESS).As a Senior Project Manager in Electronic Security Systems (ESS), you oversee all aspects of project executionincluding scope, schedule, ...[internal_linking.show_more]

 • [job_card.promoted]

Lead Security Control Assessor (REMOTE)

Armavel, LLCAtlanta, GA, United States
[filters.remote]
[job_card.full_time]

Job DescriptionJob DescriptionArmavel, LLC is offering an opportunity to be a part of a growing, forward-thinking team in an engaging, fast-paced environment.As a Lead Security Control Assessor, yo...[internal_linking.show_more]

 • [job_card.promoted]

Sr. Information Management Specialist

CetechsAtlanta, GA, US
[job_card.full_time]
[filters_job_card.quick_apply]

Position Overview The Information Management Specialist provides critical information management, data analysis, reporting, and operational support to the CDC Division of Global HIV & TB (DGHT), Of...[internal_linking.show_more]

Sr Analyst, Hybrid IA Compliance

OsaicAtlanta, Georgia, United States
[job_card.full_time]

Current Employees and Contractors Apply Here.Senior Analyst for Regulatory Services Opportunity in Financial Services.Senior Analyst, Hybrid IA Compliance.Atlanta: 2300 Windy Ridge Pkwy SE, Suite75...[internal_linking.show_more]

 • [job_card.promoted]

Director of IT Security & Risk Strategy

MetroPowerTucker, GA, United States
[job_card.full_time]

A leading energy company seeks a Director of IT-Security to develop and implement its IT Security strategy.Responsibilities include overseeing security awareness programs, managing risk assessments...[internal_linking.show_more]

 • [job_card.promoted]

Sr. Project Manager/Information Architect

Delaware Nation IndustriesAtlanta, GA, US
[job_card.full_time]
[filters_job_card.quick_apply]

We are seeking an experienced Sr.Project Manager/Information Architect to support large-scale, mission-critical systems within a federal public health environment.This role is ideal for a seasoned ...[internal_linking.show_more]

Information Security Project Manager

Atria Group LLCAtlanta, GA, United States
[job_card.full_time]

We specialize in Staffing, Consulting, Software Development, and Training along with IT services to small to medium size companies.AG's primary objective is to help companies maximize their IT reso...[internal_linking.show_more]

 • [job_card.promoted]

Senior Lead Cloud Security Architect

Cox AutomotiveNorcross, GA, US
[job_card.full_time]

The Senior Lead Cybersecurity Architect is responsible for defining the principles, standards, and design patterns to build secure products and enterprise tools for all of Cox Automotive's multi-cl...[internal_linking.show_more]