Manager, IT Security and Compliance
Authenticbrandsgroup · New York City
About this role
**Manager, IT Security and Compliance** **About Authentic Brands Group** Authentic Brands Group (Authentic) is a global brand and entertainment platform that owns and invests in iconic intellectual property and cultural assets. With a network of 1,700+ licensees and strategic partners across 150 countries, Authentic’s brands drive $38B+ in annual systemwide retail sales worldwide. **Position Justification** As the organization grows and adopts new technologies, the security and compliance function must scale beyond reactive reviews and ad hoc guidance. Business teams increasingly rely on SaaS, APIs, cloud services, integrations, automation, and AI-enabled tools—each introducing risk if access, data protection, vendor oversight, logging, configuration, and control requirements aren’t consistently managed. **Position Overview** Authentic is seeking a **Manager, Security & Compliance** to strengthen cybersecurity, technology risk, and compliance programs. You’ll evaluate security risks, design practical controls, support audit/compliance activities, and partner with business and technology teams to ensure new systems and processes are implemented securely. **What You’ll Do** - Lead security and compliance reviews for new and existing technologies (SaaS, apps, APIs, cloud, integrations, automation, AI-enabled solutions) - Assess risk across initiatives, focusing on data protection, access controls, vendor risk, logging, auditability, and secure configuration - Define and implement practical security controls aligned to business needs, regulations, internal policies, and audit requirements - Partner with application owners and stakeholders to identify security/compliance requirements early - Conduct security and architecture reviews for applications, APIs, integrations, data flows, and third-party platforms - Support compliance activities (evidence collection, control documentation, risk remediation tracking, user access reviews, audit response) - Improve application and network security posture (secure design, vulnerability management, control improvements, remediation planning) - Review third-party technology solutions and support vendor due diligence - Establish guardrails for technology use (acceptable use, data handling, access management, logging/monitoring, approval standards) - Support incident response and investigations involving applications, integrations, vendor platforms, data exposure, or control failures - Track risks/issues/remediation and provide clear reporting to leadership - Help develop lightweight, scalable processes for reviewing and approving new technologies - Stay current on emerging threats, compliance expectations, cybersecurity frameworks, and best practices - Implement and test CI/CD and secure development controls for internally developed applications **What You Bring** - Bachelor’s degree in Computer Science, Information Security, Information Systems, or related field - **7+ years** in cybersecurity, technology risk, IT audit, compliance, application security, or network security - Strong understanding of security/compliance fundamentals (access management, authentication/authorization, data protection, logging, vulnerability management, secure configuration) - Experience reviewing applications, APIs, SaaS platforms, cloud environments, or integration-heavy ecosystems - Familiarity with application security concepts (OWASP, secure SDLC, API security, data protection) - Solid grounding in network security
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.