Manager Cyber Security (ESCR/GRC for Cyber)

Garmin International, Inc.

Olathe, Kansas

JOB DETAILS
JOB TYPE
Full-time
SKILLS
Artificial Intelligence (AI), Budget Management, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Communication Skills, Computer Science, Computer Security, Contract Requirements, External Audit, ISO (International Organization for Standardization), IT Governance, ITSEC - Information Technology Security Evaluation Criteria, Information Architecture, Information/Data Security (InfoSec), Insurance, Internal Audit, Internet Security, Leadership, Legal, Maintain Compliance, Management of Information Systems/Technology (MIS), Metrics, PCI-DSS, Presentation/Verbal Skills, Project/Program Management, Public/Media/Press/Analyst Relations, Regulations, Regulatory Compliance, Relationship Management, Risk, Security Compliance, Strategic Planning, Supplier Relationship Management (SRM), U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Relations, Writing Skills
LOCATION
Olathe, Kansas
POSTED
3 days ago
Overview:

We are seeking a full-time Manager Cyber Security at Garmin's U.S. headquarters in the Greater Kansas City area. In this role, you will be responsible for eading the team responsible for developing and maintaining the organization's cybersecurity policy framework, supporting GRC program execution and ensuring compliance with applicable regulatory and contractual requirements. This role serves as a key interface between the cybersecurity organization, Internal Audit, Legal, and business stakeholders on matters of security governance and compliance.

Responsibilities:

Essential Functions

  • Lead the Cyber and IT Compliance team in executing the cybersecurity compliance and assurance program
  • Own and maintain the enterprise cybersecurity policy framework, standards, and control library
  • Oversee compliance program management across applicable regulatory frameworks (e.g., NIST CSF, PCI DSS, TISAX, SOC 2, ISO 27001)
  • Manage internal and external audit relationships, including evidence preparation and audit remediation tracking
  • Partner with business segments, Legal, HR, and Privacy teams on matters involving regulatory compliance, data protection, and associate security obligations
  • Develop and maintain IT and Security Compliance program metrics and reporting for leadership and board-level audiences
  • Leading the ECSR program
  • Supporting the annual Board of Directors risk presentation content
  • Support the annual KMPG NIST CSF Assessment with the ITSEC Compliance team
  • Support the annual Cyber insurance renewal process with the ITSEC Compliance team
  • Take a leading role and key contributor in the emerging Cyber AI Strategy initiative
  • Take a leadership role in overseeing Cyber Architecture Review Board and process integration with TPRM, AI Governance and IT Architecture Review Board
  • Key contributor and Cyber governance delegate in monthly Legal/Regulatory meeting
  • Shadow and support Compliance as it relates to ECSR priorities and preparation for meetings
Qualifications:

Basic Qualifications

  • Bachelor's Degree in Management Information Systems, Computer Science, or another technical related field AND a minimum of 7 years of relevant experience in cyber security AND a minimum of 2 years of leadership experience
  • Demonstrated ability to manage, develop, and retain technical PM's
  • Strong understanding of cybersecurity principles, frameworks, and industry practices
  • Experience managing budgets, vendor relationships, and resource planning
  • Excellent written and verbal communication skills, including the ability to convey technical requirements and trade-offs to executive and board-level stakeholders, with strong influencing and stakeholder management skills
  • Deep knowledge of multiple compliance and regulatory frameworks
  • Experience managing relationships with external auditors, regulators, and business stakeholders
  • Familiarity with GRC platforms

Desired Qualifications

  • Relevant certifications (e.g., CISM, CRISC, CISA, CISSP)


Garmin International is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, veteran's status, age or disability.

This position is eligible for Garmin's benefit program. Details can be found here: Garmin Benefits

About the Company

G

Garmin International, Inc.