> Markdown version of [/jobs/ext/2898327-it-sr-mgr-cyber-security-it-governance-risk-compliance](https://www.wearedevelopers.com/jobs/ext/2898327-it-sr-mgr-cyber-security-it-governance-risk-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Sr Mgr, Cyber Security & IT Governance, Risk & Compliance - **Company:** NPK International Inc. - **Location:** Spring, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Audit Trail, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Network Security, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, Information Technology, Virtual Agents, Vulnerability Analysis - **Published:** September 14, 2026 - **Apply:** https://www.businessworkforce.com/job.asp?id=3390449951&tx=KP5555FFI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (Master's preferred)., * 8+ years of experience in cybersecurity, security governance, or risk management roles. * Minimum 4 years in a leadership or managerial role. * Demonstrated success driving enterprise security, risk, and compliance programs. * Experience collaborating with auditors and managing cross-functional initiatives. Certifications (Preferred): * CISSP, CISM, CRISC, CGEIT or equivalent. * Microsoft SC-100 Skills: * Strong knowledge of cybersecurity frameworks (NIST, ISO 27001, COBIT) and regulatory requirements. * Expertise in network security, cloud security, endpoint protection, SIEM, identity and access management. * Strong analytical, governance, and policy development skills. * Excellent communication, leadership, and stakeholder management skills. * Ability to manage multiple initiatives in a fast-paced environment. * Practical understanding of AI automation, Agentic AI workflows, and responsible AI governance in enterprise security and compliance environments. ## Description The Senior manager, Cybersecurity, is responsible for defining and executing the organization's cybersecurity, security governance, and compliance strategy. This role integrates operational security leadership with enterprise-wide risk management, governance, and audit functions. The manager ensures the confidentiality, integrity, and availability of information assets by overseeing security operations, driving compliance programs, and aligning security initiatives with business and regulatory requirements. This role collaborates closely with IT, business units, internal/external auditors, and compliance teams to establish a unified governance model that addresses risk, data protection, and enterprise security posture maturity., 1. Strategy & Planning 2. Align cybersecurity, governance, and compliance programs with business goals and risk appetite. 3. Develop and institute holistic security, risk, and compliance objectives and performance metrics. 4. Define and enforce enterprise-wide security and compliance policies, standards, and architectures. 5. Review and advise on proposed IT and business projects to identify risks early in the lifecycle. 6. Establish guiding principles for flexible, scalable, and risk-aligned security governance. 7. Classify and valuate enterprise data assets and ensure appropriate protection controls. 8. Develop, communicate, and maintain multi-year cybersecurity and risk mitigation strategies. 9. Security Architecture, Acquisition & Deployment 10. Ensure IT and security technology purchases align with compliance, governance, and risk mandates. 11. Lead the deployment of integrated security toolsets (e.g., SIEM, vulnerability management, identity governance). 12. Oversee security architecture design aligned with frameworks such as NIST, ISO 27001, and Zero Trust. 13. Drive an AI automation mindset by identifying opportunities to use Agentic AI, Copilot, and workflow automation to streamline security operations, compliance monitoring, evidence collection, and risk remediation where appropriate. 14. Operational Security Management 15. Manage daily IT security operations, including security monitoring, threat detection, and incident response. 16. Lead vulnerability assessments, penetration testing, auditing, and remediation activities. 17. Track, measure, and report the organization's security and risk posture. 18. Oversee centralized logging, automation of internal controls, and unified security event management. 19. Plan, manage, and validate risk mitigation and remediation projects. 20. Liaise with internal and external audit teams; schedule and manage periodic audit reviews. 21. Ensure adherence to regulatory requirements (e.g., GDPR, HIPAA, SOX, NIST, ISO 27001). 22. Lead cross-functional incident response activities and oversee lessons-learned documentation. 23. Evaluate and implement Agentic AI use cases for repeatable security tasks such as alert triage, control testing, audit evidence preparation, vulnerability prioritization, and policy compliance reminders. 24. Risk Compliance & Awareness 25. Conduct enterprise risk assessments and drive mitigation plans for emerging risks. 26. Oversee enterprise governance programs, ensuring policy adoption and continuous improvement. 27. Develop and Manage cybersecurity & IT risk/compliance awareness programs, ensuring staff are trained on risks and responsibilities. 28. Establish and monitor governance for Agentic AI systems, including approved use cases, human oversight, data protection, access controls, auditability, and responsible AI guardrails. 29. Leadership, Reporting & Collaboration 30. Lead and mentor a team of cybersecurity and governance professionals. 31. Provide timely and actionable reporting to senior leadership on risks, incidents, KPIs, and program maturity. 32. Partner with IT teams, business units, and executive stakeholders to embed security into all technology initiatives. 33. Manage vendor relationships for security, governance, and compliance tools and services. ## Related Videos - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)