- Company Name
- Lowe's Companies, Inc.
- Job Title
- Sr Manager, Information Security - Risk
- Job Description
-
Job title: Senior Manager, Information Security – Risk
Role Summary: Lead a global team to identify, monitor, and mitigate information security risks, serve as a strategic risk advisor, and embed risk‑aware decision‑making into enterprise initiatives.
Expactations: Deliver end‑to‑end risk governance, oversee risk assessments and remediation actions, build executive‑level dashboards, and guide the adoption of emerging risk frameworks (e.g., AI). Act as the primary escalation point for complex security issues and influence executive leadership.
Key Responsibilities
- Manage and mentor cross‑regional teams (U.S. & India) to foster accountability and professional growth.
- Own the risk identification, monitoring, and reporting cycle, ensuring alignment with regulatory and industry standards.
- Develop, operationalize, and continuously improve enterprise risk frameworks and GRC processes.
- Partner with technical teams to remediate findings while balancing agility and security.
- Produce and present dashboards and executive reports to communicate posture, metrics, and remediation status.
- Lead or contribute to PCI‑DSS, SOX, and other compliance assessments and audits.
- Drive security best‑practice adoption across strategic initiatives and technology deployments.
- Maintain oversight of emerging risks (e.g., AI, marketplace integrations) and integrate them into risk methodology.
- Ensure audit readiness and governance for all security-related controls.
Required Skills
- Deep expertise in information security risk management and GRC tools.
- Strong project management and the ability to lead multiple concurrent initiatives.
- Advanced analytical and reporting capabilities with executive‑level communication.
- Demonstrated leadership in global teams, change management, and mentoring.
- Knowledge of multi‑platform environments (network, servers, cloud) and associated security considerations.
- Ability to translate regulatory requirements into actionable risk controls.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Assurance, Engineering, or related field (or equivalent experience).
- 8+ years IT experience, including 4+ in security tools/practices and 3+ in team or project leadership.
- Master’s degree and/or certifications (CISSP, CISM, CISA, CRISC, PCI‑ISA, CEH, OSCP, GPEN) are strongly preferred.
- Experience in retail technology ecosystems, PCI‑DSS assessments, and SOX compliance is an advantage.