Skip to main content
Posted August 13, 2026
Joe Gibbs Racing

Information Security & Data Governance Manager

Huntersville, NC, USA Full Time

Position Summary: The Information Security & Data Governance Manager protects JGR’s information assets by leading cybersecurity, data governance, incident response, business continuity, and technology risk initiatives. Reporting to the Director of IT, this role works closely with the Director of IT and Sr. Systems Administrator to implement security controls, strengthen identity and access governance, manage technology risk, and maintain effective security policies and standards.


Key Responsibilities

Cybersecurity Program Governance:

  • Execute the Director of IT’s cybersecurity strategy and roadmap
  • Review MSP vulnerability, threat detection, remediation, and security reporting
  • Administer Conditional Access policies and validate against established standards
  • Coordinate penetration testing and track remediation through completion
  • Manage cybersecurity awareness and training programs
  • Coordinate security assessments and report risks to the Director of IT

Data Governance & Data Security:

  • Manage SharePoint and file share access governance
  • Set data classification standards and enforce compliance
  • Administer Microsoft Purview policies
  • Create data retention and records management policy
  • Lead sensitive data identification and protection controls
  • Run access review processes; drive least-privilege access model
  • Develop and refine internal data security policy


Incident Response & Business Continuity:

  • Manage the Incident Response Plan; work with MSPs in detection and containment
  • Own ransomware response playbook and executive communication procedures
  • Support Business Continuity/Disaster Recovery planning
  • Run cybersecurity tabletop exercises
  • Coordinate with IT, legal, and MSP partners during live incidents
  • Lead post-incident reviews and corrective action tracking


Risk Management, Compliance & Vendor Oversight:

  • Develop the technology risk register and lead risk identification/mitigation
  • Manage the MSP relationship: SLAs, service quality, escalations, and contract alignment with JGR's risk needs
  • Manage cyber insurance compliance requirements and audit preparation
  • Manage security policy development and governance
  • Own annual security strategy and roadmap


Leadership Expectations:

  • Serve as JGR's internal security & governance subject matter expert
  • Communicate security risk in business terms to leadership
  • Build partnerships across departments and with external partners
  • Drive accountability internally and across vendor relationships
  • Influence decision-making without direct authority
  • Balance risk management with operational effectiveness and vendor cost/value


Required Experience

  • 5+ years of progressive IT cybersecurity
  • Experience with compliance frameworks, policy development, and governance practices (SOC 1/2, PCI-DSS, HIPAA, ISO 27001, NIST CSF, or similar)
  • Experience managing vendor/MSP relationships or third-party risk programs
  • Experience with Microsoft 365 security and data governance tools (Purview, Conditional Access, SharePoint governance)
  • Experience coordinating or supporting incident response
  • Strong understanding of risk management frameworks


Preferred Backgrounds

  • Governance, Risk, and Compliance Analyst or Manager
  • IT Risk & Governance professional
  • Security Program Manager (vendor-managed environments)
  • Data Governance / Data Privacy professional
  • IAM or Access Governance professional


Preferred Certifications

  • CRISC
  • Security+
  • Microsoft Security or Purview Certifications
  • Any GRC platform certification (Archer, OneTrust, ServiceNow GRC)

Sign up for Job Alerts