> Markdown version of [/jobs/ext/1825713-it-sr-mgr-cyber-security-it-governance-risk-compliance](https://www.wearedevelopers.com/jobs/ext/1825713-it-sr-mgr-cyber-security-it-governance-risk-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Sr Mgr, Cyber Security & IT Governance, Risk & Compliance - **Company:** NPK International Inc. - **Location:** The Woodlands, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Network Security, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, Information Technology, Vulnerability Analysis - **Published:** July 8, 2026 - **Apply:** https://dejobs.org/x/x/EDDC82CCC65D4B46A2F16CADB0901B19/job/ ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (Master's preferred)., * 10+ years of experience in cybersecurity, security governance, or risk management roles. * Minimum 4 years in a leadership or managerial role. * Demonstrated success driving enterprise security, risk, and compliance programs. * Experience collaborating with auditors and managing cross-functional initiatives. Certifications (Preferred): * CISSP, CISM, CRISC, CGEIT or equivalent. * Microsoft SC-100 Skills: * Strong knowledge of cybersecurity frameworks (NIST, ISO 27001, COBIT) and regulatory requirements. * Expertise in network security, cloud security, endpoint protection, SIEM, identity and access management. * Strong analytical, governance, and policy development skills. * Excellent communication, leadership, and stakeholder management skills. * Ability to manage multiple initiatives in a fast-paced environment. ## Description The Senior manager, Cybersecurity, is responsible for defining and executing the organization's cybersecurity, security governance, and compliance strategy. This role integrates operational security leadership with enterprise-wide risk management, governance, and audit functions. The manager ensures the confidentiality, integrity, and availability of information assets by overseeing security operations, driving compliance programs, and aligning security initiatives with business and regulatory requirements. This role collaborates closely with IT, business units, internal/external auditors, and compliance teams to establish a unified governance model that addresses risk, data protection, and enterprise security posture maturity., 1. Strategy & Planning * Align cybersecurity, governance, and compliance programs with business goals and risk appetite. * Develop and institute holistic security, risk, and compliance objectives and performance metrics. * Define and enforce enterprise-wide security and compliance policies, standards, and architectures. * Review and advise on proposed IT and business projects to identify risks early in the lifecycle. * Establish guiding principles for flexible, scalable, and risk-aligned security governance. * Classify and valuate enterprise data assets and ensure appropriate protection controls. * Develop, communicate, and maintain multi-year cybersecurity and risk mitigation strategies. 2. Security Architecture, Acquisition & Deployment * Ensure IT and security technology purchases align with compliance, governance, and risk mandates. * Lead the deployment of integrated security toolsets (e.g., SIEM, vulnerability management, identity governance). * Oversee security architecture design aligned with frameworks such as NIST, ISO 27001, and Zero Trust. 3. Operational Security Management * Manage daily IT security operations, including security monitoring, threat detection, and incident response. * Lead vulnerability assessments, penetration testing, auditing, and remediation activities. * Track, measure, and report the organization's security and risk posture. * Oversee centralized logging, automation of internal controls, and unified security event management. * Plan, manage, and validate risk mitigation and remediation projects. * Liaise with internal and external audit teams; schedule and manage periodic audit reviews. * Ensure adherence to regulatory requirements (e.g., GDPR, HIPAA, SOX, NIST, ISO 27001). * Lead cross-functional incident response activities and oversee lessons-learned documentation. 4. Risk Compliance & Awareness * Conduct enterprise risk assessments and drive mitigation plans for emerging risks. * Oversee enterprise governance programs, ensuring policy adoption and continuous improvement. * Develop and Manage cybersecurity & IT risk/compliance awareness programs, ensuring staff are trained on risks and responsibilities. 5. Leadership, Reporting & Collaboration * Lead and mentor a team of cybersecurity and governance professionals. * Provide timely and actionable reporting to senior leadership on risks, incidents, KPIs, and program maturity. * Partner with IT teams, business units, and executive stakeholders to embed security into all technology initiatives. * Manage vendor relationships for security, governance, and compliance tools and services. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)