Manager Information Security Governance/Risk/Compliance
![]() | |
![]() | |
![]() United States, California, Modesto | |
![]() 600 Yosemite Boulevard (Show on map) | |
![]() | |
Job Req ID:106278 Job Type:Full-time Work Category:Hybrid Telecommute Application Close Date: 08/22/2025 Sponsorship:Not Available Compensation: $133900- $200900 Gallo Privacy Policy We are GALLO We're a family-owned company with a 90+ year legacy, that's consistently recognized as a Glassdoor "Best Places to Work." We have130+ brands in our total alcohol beverage portfolio including wine, malt, spirits, and ready-to-drink beverages. We're home to the #1 wine and spirits brands in the U.S. - Barefoot Wine & High Noon and are the official sponsors of the NFL, NHL, UFC, and PGA TOUR. View our Corporate Values and Mission Statement here. A Taste of What You'll Do Are you a seasoned professional in information security with a talent for governance, risk, and compliance? Join our team as a Manager of Information Security Governance, Risk, and Compliance, where you will drive consistent, repeatable results by aligning security initiatives with industry controls, organizing information and evidence, measuring outcomes, and ensuring our information assets are protected at appropriate levels to withstand threats. You will build strong partnerships across the company, influencing others to mature the program and minimize regulatory and compliance concerns. Your role will ensure that key cybersecurity risks are identified, assessed, communicated, managed to tolerance, and monitored. As a Manager, you will lead a team responsible for building and deploying effective policies, processes, and controls across various technologies, systems, applications, and business operations. Your responsibilities include managing the analysis of detailed specifications and business requirements, and overseeing an information security team, including hiring, training, staff development, performance management, and annual reviews. You will plan, prioritize, and manage resources to ensure compliance with ITGCs, PCI, GDPR, CCPA, and other applicable regulations. Collaborating with Internal Audit and outside consultants, you will ensure audit compliance and attestation. Reviewing and updating information security policies and standards, you will ensure continued effectiveness and compliance with relevant laws. Developing and communicating operational status reports, performance analysis, and ad hoc reporting requirements, you will manage the Information Security Risk Assessment Program, project risk assessments, vendor security assessments, and new technology assessments. You will oversee the Information Security Awareness Program, create data flows, data maps, and business process mapping. Your role involves assigning, monitoring, and reviewing the progress and accuracy of work, preparing project requests and purchase requisitions, and presenting activities and progress reports. Acting as a liaison with information systems staff and other departments, you will coordinate activities and ensure projects progress on schedule and within budget. We value intrapreneurship and ownership behaviors, encouraging bold thinking, appropriate risk-taking, learning from mistakes, showing initiative, and driving innovation. Setting high expectations, engaging in candid discussions, and holding yourself and others accountable are key to our success. If you are a proactive leader ready to make a significant impact, we invite you to apply. Join us in fostering a culture of excellence and continuous improvement. Apply today to become an integral part of our innovative team! What You'll Need
How You'll Stand Out
To view the full job description, please click here. Our Benefits & Perks We are committed to providing competitive compensation, perks, and a culture that supports your well-being. Benefits depend on your work category and may include medical and dental coverage, 401k plans, profit sharing, pet insurance, company holidays, access to an employee wine shop, and more! Additional information will be provided before your first interview. The Fine Print
Gallo's policy is to afford equal employment opportunities to all applicants and employees and not to discriminate on the basis of race, traits associated with race, including but not limited to, hair texture and protective hairstyles (such as braids, locks, and twists), color, national origin, ancestry, creed, religion, physical disability, mental disability, medical condition as defined by applicable state law (including cancer and predisposing genetic characteristics), genetic information, marital status, familial status, sex, gender, gender identity, gender expression, sexual orientation (actual or perceived), transgender status, sex stereotyping, pregnancy, childbirth or related medical conditions, reproductive health decision making, age, military or veteran status, domestic violence or sexual assault victim status, or any other basis protected by applicable law. Nor will Gallo discriminate based on a perception that an individual has any of the foregoing characteristics or is associated with a person who has, or is perceived to have, any of those characteristics. Gallo will comply with state and local laws prohibiting discrimination for lawful out-of-work behavior, such as off-duty use of cannabis away from the workplace (subject to federal and state law exceptions), the existence of non-psychoactive cannabis metabolites in hair, blood, urine, or other bodily fluids as determined by a drug screening test (subject to federal and state law exceptions). We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gallo is committed to providing reasonable accommodation for candidates with disabilities in our recruiting process. If you need any assistance or accommodation due to a disability, please let us know at 209.341.7000. Gallo is enrolled in the Department of Homeland Security's E-Verify program and will use the program to verify the employment eligibility of all newly hired employees as required. E-Verify Notice Right to Work Employee Polygraph Protection Act |