Manager Information Security Governance/Risk/Compliance
![]() | |
![]() | |
![]() United States, California, Modesto | |
![]() 600 Yosemite Boulevard (Show on map) | |
![]() | |
Job Req ID:106278 Job Type:Full-time Work Category:Hybrid Telecommute Application Close Date: 08/22/2025 Sponsorship:Not Available Compensation: $133900- $200900 Gallo Privacy Policy We are GALLO We're a family-owned company with a 90+ year legacy, that's consistently recognized as a Glassdoor "Best Places to Work." We have130+ brands in our total alcohol beverage portfolio including wine, malt, spirits, and ready-to-drink beverages. We're home to the #1 wine and spirits brands in the U.S. - Barefoot Wine & High Noon and are the official sponsors of the NFL, NHL, UFC, and PGA TOUR. View our Corporate Values and Mission Statement here. A Taste Of What You Will Do: Are you a seasoned professional in information security with a knack for governance, risk, and compliance? Join our team as a Manager of Information Security Governance, Risk, and Compliance, where you will drive consistent, repeatable results by aligning security initiatives with industry controls. You will organize information and evidence, measure outcomes, and ensure that our information assets are protected at appropriate levels to withstand threats. Building strong partnerships across the company, you will influence others to mature the program and minimize regulatory and compliance concerns. You will ensure key cybersecurity risks are identified, assessed, communicated, driven to tolerance, and monitored. As a Manager, you will lead a team responsible for building and deploying effective policies, processes, and controls across various technologies, systems, applications, and business operations. You will manage the analysis of detailed specifications and business requirements, and oversee an information security team, including hiring, training, staff development, performance management, and annual reviews. Your role involves planning, prioritizing, and managing resources to ensure compliance with ITGCs, PCI, GDPR, CCPA, and other regulations. You will work with Internal Audit and outside consultants for audit compliance and attestation. Reviewing and updating information security policies and standards, you will ensure continued effectiveness and compliance with applicable laws. You will develop and communicate operational status reports, performance analysis, and ad hoc reporting requirements. Managing the Information Security Risk Assessment Program, you will conduct project risk assessments, vendor security assessments, and new technology assessments. You will oversee the Information Security Awareness Program, create data flows, data maps, and business process mapping. Your responsibilities include assigning, monitoring, and reviewing the progress and accuracy of work, preparing project requests and purchase requisitions, and presenting activities and progress reports. Acting as a liaison with information systems staff and other departments, you will coordinate activities and ensure projects progress on schedule and within budget. We value intrapreneurship and ownership behaviors, encouraging bold thinking, appropriate risks, learning from mistakes, showing initiative, and driving innovation. Setting high expectations, engaging in candid discussions, and holding yourself and others accountable are key to our success. If you are a proactive leader ready to make a significant impact, we invite you to apply. Join us in fostering a culture of excellence and continuous improvement. Apply today to become an integral part of our innovative team! What You Will Need:
How You Will Stand Out:
To view a full job description please click here. Our Benefits & Perks We are committed to providing competitive compensation, perks, and a culture that supports your well-being. Benefits depend on your work category and may include medical and dental coverage, 401k plans, profit sharing, pet insurance, company holidays, access to an employee wine shop, and more! Additional information will be provided before your first interview. The Fine Print
Gallo's policy is to afford equal employment opportunities to all applicants and employees and not to discriminate on the basis of race, traits associated with race, including but not limited to, hair texture and protective hairstyles (such as braids, locks, and twists), color, national origin, ancestry, creed, religion, physical disability, mental disability, medical condition as defined by applicable state law (including cancer and predisposing genetic characteristics), genetic information, marital status, familial status, sex, gender, gender identity, gender expression, sexual orientation (actual or perceived), transgender status, sex stereotyping, pregnancy, childbirth or related medical conditions, reproductive health decision making, age, military or veteran status, domestic violence or sexual assault victim status, or any other basis protected by applicable law. Nor will Gallo discriminate based on a perception that an individual has any of the foregoing characteristics or is associated with a person who has, or is perceived to have, any of those characteristics. Gallo will comply with state and local laws prohibiting discrimination for lawful out-of-work behavior, such as off-duty use of cannabis away from the workplace (subject to federal and state law exceptions), the existence of non-psychoactive cannabis metabolites in hair, blood, urine, or other bodily fluids as determined by a drug screening test (subject to federal and state law exceptions). We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gallo is committed to providing reasonable accommodation for candidates with disabilities in our recruiting process. If you need any assistance or accommodation due to a disability, please let us know at 209.341.7000. Gallo is enrolled in the Department of Homeland Security's E-Verify program and will use the program to verify the employment eligibility of all newly hired employees as required. E-Verify Notice Right to Work Employee Polygraph Protection Act |