Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Information Security Risk Manager image - Rise Careers
Job details

Information Security Risk Manager

Company Description

Watch here to see what it's like to work at Red Wing Shoe Company.

Red Wing Shoe Company is based in Red Wing, Minnesota, just 40 minutes from St. Paul, where our corporate office sits along the Mississippi River in downtown Red Wing.  We are a global company with 2300 employees around the world, but we maintain a close-knit family atmosphere that comes with being a privately-held company. We’re rich in history and tradition, but innovation drives us to deliver best-in-class product solutions and highly rated customer experiences.  Focus on our employees and company culture results in meaningful employee engagement across the organization. Our Guiding Behaviors of Living our Values, Honoring our Brands, Inspiring our People, Centering on our Customers, and Preserving the long term success and legacy of our Company are the foundation on which we build our future.

Job Description

Red Wing Shoe Company is looking for an experienced Information Security Risk Manager to join our team to manage Governance, Risk, and Compliance (GRC) activities within our Information Security Program. Reporting to the Director of Information Security, this role is focused on developing, maintaining, and managing Red Wing’s Information Security GRC processes and functions. The Information Security Risk Manager will drive information security risk identification, tracking, and remediation efforts internally and with critical third-party vendors and partners.

The Information Security Risk Manager will monitor Red Wing’s compliance with key security regulations and standards and provide risk consulting, guidance, and training to internal business and technical partners on security policies, standards, and regulations related to their business areas and projects.

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Manage the information security risk management process, including identifying, assessing, mitigating, and monitoring risks.
  • Oversee the PCI-DSS compliance program, ensuring payment channels remain compliant, resolving issues, and reporting annually.
  • Build relationships with key business partners to address information security risks and implement effective remediation plans.
  • Lead third-party and vendor risk management programs, ensuring external partner security and compliance are monitored and reported.
  • Collaborate with cross-functional teams to ensure DevSecOps processes adhere to regulatory requirements, security policies, and controls.
  • Develop and deliver user security awareness training and foster a strong security culture.
  • Support vulnerability management, coordinating to identify, prioritize, and remediate security gaps.
  • Establish and maintain security policies and standards aligned with the company’s security strategy.
  • Monitor and report on the Information Security Program’s effectiveness, driving continuous improvement.
  • Stay informed of industry best practices, regulatory requirements, and emerging threats to enhance the company’s security posture.

Qualifications

MINIMUM EDUCATION AND YEARS OF EXPERIENCE:

  • A bachelor's degree in Information Security, Computer Science, or a related field.
  • A minimum of 7 years of experience in information security, with a focus on risk management, GRC, and/or vulnerability management.
  • Relevant professional certifications, such as CISSP, CISM, CRISC, or CISA, are preferred.

REQUIRED KNOWLEDGE, SKILLS, AND ABILITIES:S)

  • Experience managing and/or assessing information security risk management processes, GRC functions, and/or vulnerability management.
  • Strong knowledge of, and experience managing, Payment Card Industry Data Security Standards (PCI-DSS) compliance.
  • Strong knowledge of information security principles, best practices, and industry standards, such as CIS Critical Security Controls, ISO 27001, NIST, and GDPR.
  • Experience performing technical risk analysis using quantitative risk methodologies, such as FAIR (Factor Analysis of Information Risk)
  • Familiarity with third-party and vendor risk management concepts, processes, and tools.
  • Experience developing and delivering security awareness training programs for a diverse audience.
  • Excellent communication skills, with the ability to articulate complex security concepts to both technical and non-technical stakeholders.
  • Strong documentation, planning, negotiation, work prioritization and organizational skills.
  • Team player willing and able to promote a working environment that encourages and increases collaboration, clarity, and innovation.

Additional Information

Red Wing Shoes is an Equal Opportunity Employer.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
Individuals with disabilities needing assistance in completing an application may contact [email protected] or call 651-388-8211.

Please view Equal Employment Opportunity Posters provided by OFCCP at https://www.dol.gov/ofccp/regs/compliance/posters/ofccpost.htm

All offers of employment are contingent on satisfactory results of a background check.

Red Wing Shoe Company, Inc. is a drug-free workplace.

Red Wing Shoe Company will not be using recruitment agencies or firms to fill this position and we will not accept unsolicited resumes or candidate information. No agency calls please.

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)

Average salary estimate

$105000 / YEARLY (est.)
min
max
$90000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Information Security Risk Manager, Red Wing Shoe Company

Red Wing Shoe Company is on the lookout for an experienced Information Security Risk Manager to join our dynamic team in Red Wing, MN! This role is an exciting opportunity for those who thrive on managing Governance, Risk, and Compliance (GRC) activities within a robust Information Security Program. As part of a close-knit family atmosphere driven by innovation, your mission will be to develop, maintain, and manage our Information Security GRC processes. You’ll be instrumental in identifying, tracking, and remediating information security risks for both internal projects and with our critical third-party partners. We want someone who can not only monitor compliance with key security regulations but also provide essential risk consulting and training to our valued business partners. Collaborating with various teams, your expertise will help ensure our DevSecOps processes are aligned with regulatory requirements and best practices. You will play a critical role in fostering a strong security culture through your security awareness programs and will drive ongoing improvements within our Information Security Program. If you have a passion for security, compliance, and building meaningful relationships, we can't wait for you to bring your talents to Red Wing Shoe Company!

Frequently Asked Questions (FAQs) for Information Security Risk Manager Role at Red Wing Shoe Company
What does an Information Security Risk Manager do at Red Wing Shoe Company?

At Red Wing Shoe Company, an Information Security Risk Manager is responsible for managing the Governance, Risk, and Compliance (GRC) activities within our Information Security Program. This includes identifying and tracking information security risks, monitoring compliance with key security regulations, and providing training and guidance to internal and external stakeholders.

Join Rise to see the full answer
What qualifications do I need to become an Information Security Risk Manager at Red Wing Shoe Company?

To become an Information Security Risk Manager at Red Wing Shoe Company, you need a bachelor's degree in Information Security or a related field, along with at least 7 years of experience in information security focusing on risk management and compliance. Relevant professional certifications like CISSP or CISM are highly preferred.

Join Rise to see the full answer
What security regulations should an Information Security Risk Manager be familiar with at Red Wing Shoe Company?

An Information Security Risk Manager at Red Wing Shoe Company should be familiar with regulations such as PCI-DSS for payment security, GDPR for data protection, and have knowledge of industry standards like ISO 27001, NIST, and CIS Critical Security Controls.

Join Rise to see the full answer
How does Red Wing Shoe Company support the Information Security Risk Manager in their role?

Red Wing Shoe Company supports its Information Security Risk Manager by providing a cooperative work environment, access to industry-leading tools, and encouraging professional development. The company values continuous improvement and offers opportunities for collaboration across teams to enhance security processes.

Join Rise to see the full answer
What skills are essential for an Information Security Risk Manager at Red Wing Shoe Company?

Essential skills for an Information Security Risk Manager at Red Wing Shoe Company include strong knowledge of risk management processes, excellent communication abilities for conveying complex security concepts, organizational skills, and a proficiency in developing security awareness training programs.

Join Rise to see the full answer
What is the company culture like for an Information Security Risk Manager at Red Wing Shoe Company?

The company culture for an Information Security Risk Manager at Red Wing Shoe Company emphasizes collaboration and innovation, where employees are encouraged to inspire one another. The close-knit, family-oriented atmosphere makes it an engaging place to work and grow.

Join Rise to see the full answer
What kind of career growth opportunities exist for an Information Security Risk Manager at Red Wing Shoe Company?

As an Information Security Risk Manager at Red Wing Shoe Company, there are abundant career growth opportunities. With continual training and development programs, you can advance into higher management roles or specialize further in various aspects of information security.

Join Rise to see the full answer
Common Interview Questions for Information Security Risk Manager
Can you explain how you would manage the information security risk assessment process?

An effective response would involve your methodology for identifying, assessing, and mitigating risks. Discuss techniques like risk management frameworks, collaboration with stakeholders, and regular reviews to ensure comprehensive evaluations.

Join Rise to see the full answer
What experience do you have with PCI-DSS compliance?

Share any specific experiences you have with PCI-DSS, detailing instances where you ensured compliance, managed issues that arose, and how you communicated compliance status to stakeholders, aligning with regulatory requirements.

Join Rise to see the full answer
How would you approach third-party risk management?

Address how you would assess the security posture of third-party vendors, methods of monitoring compliance, and your strategies for building strong relationships while implementing effective remediation efforts.

Join Rise to see the full answer
What are your strategies for fostering a strong security culture within an organization?

Describe your approach to conducting user security awareness training, developing engaging materials, and the importance of ongoing communication about security policies and practices at all levels of the company.

Join Rise to see the full answer
How do you stay informed about the latest security threats and regulations?

Mention how you regularly engage in professional development, participate in industry forums, subscribe to security newsletters, and attend conferences to stay informed about current trends and regulatory changes.

Join Rise to see the full answer
Can you provide an example of a time you identified a significant security risk?

Share a specific situation, outlining how you identified the risk, the steps you took to assess its impact, and how you collaborated with stakeholders to mitigate the issue effectively.

Join Rise to see the full answer
Describe your experience with developing security policies and standards.

Discuss your previous roles where you created or updated security policies, explaining your process of gathering input from various stakeholders, aligning with industry standards, and ensuring policies are regularly reviewed and updated.

Join Rise to see the full answer
How would you communicate complex security concepts to non-technical stakeholders?

Outline your communication strategy, emphasizing the importance of simplifying terminology, using relatable examples, and ensuring that the information is actionable and tailored to the audience's level of understanding.

Join Rise to see the full answer
What tools or frameworks do you use for risk analysis?

Discuss specific tools or methodologies you've utilized, such as FAIR or other quantitative risk assessment frameworks, and how you've applied them in your previous roles to enhance your company's risk management efforts.

Join Rise to see the full answer
What do you believe are the top three challenges in information security today?

Identify the top challenges including emerging cyber threats, compliance with evolving regulations, and the need for continuous employee education. Provide examples of how you've handled these challenges in the past.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
CLEAR - Corporate Remote New York, New York, United States
Posted 11 days ago
Photo of the Rise User
RF-SMART Hybrid Jacksonville, Florida, United States
Posted 5 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Auria Hybrid No location specified
Posted 2 days ago
Weee! Inc Hybrid Clifton, New Jersey, United States
Posted 6 days ago
Photo of the Rise User
Rad AI Remote No location specified
Posted 7 days ago
Mission Driven
Social Impact Driven
Inclusive & Diverse
Collaboration over Competition

Founded in 1905, Red Wing Shoes is an American footwear company that carries a full line of work boots for all industries and work sites. Red Wing is headquartered in Red Wing, Minnesota.

23 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
November 24, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!