Cybersecurity & IT Compliance Manager
Garan, Incorporated Starkville, Mississippi, United States
Retail Apparel and Fashion · 1,001-5,000 employees
About the role
The Cybersecurity & IT Compliance Manager will oversee daily cybersecurity operations, including threat monitoring, incident response, and vulnerability management. They will also implement security controls and support internal and external audits to ensure compliance across the organization.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and at least 5 years of progressive experience in cybersecurity or information security. Strong technical proficiency in Microsoft security technologies and experience with risk assessments and security frameworks are required.
Full description
Cybersecurity & IT Compliance Manager
Location: Starkville, Mississippi Work Arrangement: Onsite, 5 days per week
The Opportunity
Garan, Incorporated is seeking a Cybersecurity & Compliance Manager to support and strengthen our day-to-day cybersecurity operations and compliance program. Reporting to the Head of Cybersecurity, this is a hands-on individual-contributor role with responsibility for security controls, threat response, vulnerability management, audit support, risk assessments, vendor security, and cybersecurity projects.
As a subsidiary of Berkshire Hathaway, Garan collaborates with the broader Berkshire Hathaway cybersecurity community. In this role, you will work closely with Garan’s IT teams, business stakeholders, executive management, auditors, third-party security providers, and Berkshire Hathaway technology and cybersecurity resources.
The successful candidate will combine strong technical cybersecurity expertise with sound judgment, disciplined execution, and the ability to communicate complex risks clearly to both technical and nontechnical audiences.
Responsibilities
- Support daily cybersecurity operations and serve as a technical escalation resource for cybersecurity matters.
- Implement, maintain, assess, and continuously improve security controls across identity, endpoints, cloud services, networks, applications, data, and enterprise systems.
- Administer and strengthen Microsoft security technologies, including Microsoft 365, Entra ID, Defender, Intune, Conditional Access, multifactor authentication, and privileged access controls.
- Monitor and investigate cybersecurity threats and coordinate incident response, containment, remediation, documentation, and lessons learned.
- Coordinate vulnerability-management activities, including identification, risk-based prioritization, remediation tracking, exception management, and reporting.
- Support internal and external cybersecurity audits through evidence collection, control validation, issue remediation, and compliance tracking.
- Conduct cybersecurity risk assessments and maintain records of identified risks, corrective actions, owners, and target completion dates.
- Evaluate cybersecurity risks related to vendors, cloud services, new technologies, system implementations, and significant technology changes.
- Maintain cybersecurity policies, standards, procedures, control documentation, and supporting evidence.
- Coordinate cybersecurity awareness and training activities.
- Work with cybersecurity vendors, consultants, and SOC/MDR service providers to support effective service delivery.
- Track and report cybersecurity metrics, projects, vulnerabilities, risks, audit findings, and remediation activities.
- Communicate cybersecurity risks, incidents, and initiatives to executive management and nontechnical stakeholders in clear business terms.
- Partner across IT and the business to complete cybersecurity projects and improve Garan’s overall security posture.
Qualifications
- Bachelor’s degree in cybersecurity, information technology, computer science, or a related field—or equivalent professional experience.
- At least 5 years of progressive experience in cybersecurity, information security, or a closely related field.
- Strong working knowledge of identity and access management, endpoint security, cloud security, network security, vulnerability management, and incident response.
- Hands-on experience with Microsoft 365 security, Entra ID, Microsoft Defender, Intune, Conditional Access, and multifactor authentication.
- Experience supporting cybersecurity audits, compliance requirements, risk assessments, control testing, and remediation activities.
- Working knowledge of recognized cybersecurity frameworks and practices, including the NIST Cybersecurity Framework and CIS Controls.
- Experience coordinating technical projects and working across IT and business teams.
- Strong analytical, problem-solving, documentation, and organizational skills.
- The ability to translate technical risks and cybersecurity issues into clear, actionable information for executives and nontechnical stakeholders.
Preferred Qualifications
- Experience with enterprise firewalls, email security, vulnerability-management platforms, privileged access management, SIEM, EDR/XDR, and SOC/MDR services.
- Knowledge of Zero Trust architecture, public key infrastructure, data protection, cloud security, and SaaS security.
- Experience working with cybersecurity vendors, consultants, auditors, or managed security providers.
- CISSP, CISM, CRISC, CCSP, GIAC, Microsoft security certification, or a comparable professional credential.
Additional Requirements
- This position is based onsite at Garan’s Starkville, Mississippi location five days per week.
- Relocation assistance is not available.
- Occasional travel to other company locations may be required.
- After-hours or weekend availability may be required for significant incidents, critical changes, or other business needs.
Why Garan
This position offers the opportunity to work across a broad cybersecurity environment while gaining exposure to the Berkshire Hathaway cybersecurity community. You will play a visible role in protecting the business, improving security controls, managing cybersecurity risk, and advancing Garan’s security capabilities.
Garan, Incorporated is an equal opportunity employer. Employment decisions are made without regard to legally protected characteristics and in accordance with applicable federal, state, and local laws.
Similar roles
-
Senior Cybersecurity Engineer
Votaw Precision Technologies LLC Santa Fe Springs, California, United States · $125K–$175K/yr
-
Sr. Application Security Engineer
SentinelOne United States · $132K–$160K/yr
-
Cloud Security Engineer - Public Sector, IT Operations
BDO USA, P.C. Mclean, Virginia, United States · $105K–$120K/yr
-
Senior Software Security Engineer
Valar Atomics Torrance, California, United States · $175K–$200K/yr
-
Staff Security Engineer, Product & Platform Security
Nscale San Francisco, California, United States · $190K–$240K/yr
-
Staff Cyber Security Engineer
NBCUniversal New York, New York, United States · $125K–$155K/yr