> Markdown version of [/jobs/ext/2118777-it-governance-risk-compliance-manager](https://www.wearedevelopers.com/jobs/ext/2118777-it-governance-risk-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Governance, Risk & Compliance Manager - **Company:** Alkegen - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Computer Networks, Disaster Recovery, Cryptographic Protocols, IT Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Information Technology - **Published:** August 19, 2026 - **Apply:** https://alkegen.wd5.myworkdayjobs.com/alkegen/job/US---Tonawanda-CHQ/IT-Governance--Risk---Compliance-Manager_R12468 ## About the Role * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. * 5+ years of experience in network security or a related area, with a focus on security architecture design and implementation. * Proven expertise in designing and implementing firewalls, intrusion detection systems, and other network security tools. * In-depth knowledge of security frameworks, data protection standards, and compliance regulations (e.g., ISO 27001, NIST, GDPR, etc.). * Experience with security assessment and penetration testing tools. * Relevant certifications such as CISSP, CISM, CEH, or equivalent are strongly preferred. ## Description Security Monitoring and Analysis: * Monitor and analyze the organization's network and system activities to detect and prevent security breaches, attacks, and vulnerabilities. * Continuously test and assess the effectiveness of security measures and propose improvements based on identified threats or vulnerabilities. Incident Response and Intrusion Detection: * Perform intrusion detection by analyzing network traffic and identifying abnormal activities or signs of breaches. * Act as the first line of defense in responding to cyber security incidents, including identifying and mitigating penetration attempts by malicious actors. * Assist in incident response and disaster recovery planning and execution to ensure swift recovery from security incidents. Cyber Security Event Investigation: * Investigate security events, alarms, and alerts to determine the source and potential impact of cyber security issues. * Document and report findings, while providing recommendations for remediation and risk mitigation. Policy and Procedure Development: * Assist in the development, documentation, and maintenance of security policies, procedures, and standards. * Help ensure that security protocols align with industry best practices and regulatory requirements. Collaboration and Support: * Work closely with IT, network, and security teams to ensure effective coordination and timely resolution of security issues. * Provide input on system and network security configurations, including firewalls, encryption protocols, and antivirus solutions. Security Enhancements: * Analyze potential threats and vulnerabilities, offering suggestions for continuous security improvements and implementing new security technologies as needed. * Ensure security tools, systems, and configurations are up-to-date and functioning effectively. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)