> Markdown version of [/jobs/ext/809229-compliance-manager-information-security](https://www.wearedevelopers.com/jobs/ext/809229-compliance-manager-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Compliance Manager, Information Security - **Company:** Kontoor Brands - **Location:** United States - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Identity and Access Management, Information Technology Audit, IT Management, SAP (Applications), SAP GRC, Software Vulnerability Management, Data Management - **Published:** June 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f331ae0aff12bdd5 ## About the Role Do you have experience in Vulnerability Remediation?, Do you have a Bachelor's degree?, * Strong leadership, project and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments. * Ability to identify risks associated with business processes, operations, information security programs and technology projects. * Ability to develop working relationships with the business, and a broad understanding of business processes to translate technical issues into business-related decision points. * Strong critical thinking and analytical skill. * Ability to drive tasks forward with limited direction. * Exceptional communication and presentation skills with diverse audience., * InfoSec certifications including CISSP, CISA, and CISM are desired * Bachelor's degree in an IT, Information Security or Audit related field of study, or equivalent experience * Working in information security and/or IT audit * Experience as a PCI Qualified Security Assessor (QSA) is preferred * Working knowledge of key industry standards and security regulatory frameworks (SOC 1, SOC 2, SOX, PCI, COBIT 5, ISO, NIST, etc.) is desired * Practical experience supporting Sarbanes-Oxley (SOX) compliance * Experience working in a company using SAP (knowledge of Access Management/GRC within SAP) * Experience in a global retail environment is preferred * Drive privacy impact analysis, record of processing activities, with applications and data management solutions * Working knowledge of EU, US and other regional Privacy and Financial regulations Leadership Competencies Expected for this Role Evolving Leader Global Agility - Leads diverse teams, adapts amidst ambiguity Purposeful Integrity - Leads with values, earns team's trust, handles conflicts ethically ## Description The Information Security Compliance Manager will report to the Director of Security Governance and develop IT compliance programs focused on SOX, PCI and Privacy regulations; oversees assessments and collaborates with cross-functional teams to maintain a strong compliance posture. Coordinates work of GRC analysts and cross functional IT teams to perform required reviews (access, Segregation of Duties, etc.), ensures processes are in place to address Privacy operations and provides requirements for data protection program., * Support Controller of Accounting & Reporting to develop and supply requirements for SAP GRC Rules (including mitigating controls) to IT IdAM Operations * Performs or oversees information security assessment/analysis, mitigation and remediation. Advise in implementing solutions and mitigation plans for control deficiencies; regulatory and compliance gaps and make recommendations for process efficiencies. * Conducts ongoing security compliance monitoring activities in coordination with the organization's other compliance and operational assessment functions. * Partners with Information Security Awareness to oversee, develop and provide compliance training to the workforce. Educate and coach internal Technology teams on technology risk, audit, and control principles. * Ensures timely completion of User Access, Privileged Access and Segregation of Duties and other control reviews. * Collaborate cross-functionally with teams including Legal, Privacy, Internal Audit, IT Risk Management, IT Security, external consultants and auditors on assessments, process improvements, documenting standards and procedures, and ensuring deadlines are achieved. * Support IT risk, audit, and compliance reporting via consolidated dashboards to aid in executive management decision making process. Identify and report metrics to IT leadership on monthly basis * Maintain current knowledge of appliable global, federal, and state information security laws and accreditation standards. * Maintain required administrative processes such as meetings, training, budgeting, status reporting, etc. * Oversees work of GRC analysts to ensure timeliness and accuracy ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)