Job Summary
The Cybersecurity Governance Manager leads the day-to-day operation and continued development of the enterprise cybersecurity governance program. The role translates cybersecurity strategy, risk tolerance, regulatory obligations, and business priorities into policies, standards, accountability structures, performance measures, and governance routines. The manager works across Cybersecurity, IT, Legal, Privacy, Internal Audit, business units, and manufacturing operations to promote consistent execution and measurable improvement.
Duties and Responsibilities
- Cybersecurity Governance Program: Manage the enterprise cybersecurity governance framework, operating model, and accountability structure. Support initiatives aligned with cybersecurity strategy and business objectives.
- Policy, Standards, and Exceptions: Lead the lifecycle of cybersecurity policies, standards, and governance procedures. Manage security exceptions and risk acceptance through approval, monitoring, and closure.
- Executive Governance and Reporting: Coordinate governance committees, management reviews, and leadership forums. Prepare executive dashboards, scorecards, decisions, and action tracking.
- Metrics and Performance Management: Develop and maintain cybersecurity KPIs and work with Cybersecurity Risk to develop KRIs. Analyze trends and drive accountability for remediation commitments and performance gaps.
- Information Security Management System: Maintain and improve the Information Security Management System. Coordinate management reviews, corrective actions, audits, assessments, and supporting evidence.
- Security Governance Domains: Coordinate governance across identity, data protection, third parties, architecture, cloud, applications, vulnerabilities, security monitoring, incident management, resilience, and technology lifecycle.
- Manufacturing and OT Governance: Partner with manufacturing, engineering, site IT, and OT stakeholders to govern requirements supporting production continuity, safety, product quality, and operational resilience.
- Acquisition Cybersecurity Governance: Oversee governance for cybersecurity due diligence, Day 1 readiness, assessments, integration visibility, remediation, transition arrangements, and risk acceptance for acquisitions.
- Stakeholder Engagement: Collaborate with Cybersecurity, IT, Legal, Privacy, Audit, Risk, Compliance, Procurement, Human Resources, BISOs, and business leaders to promote clear requirements and accountability.
- Leadership and Team Development: Lead and develop governance personnel. Set priorities and establish repeatable processes, templates, reporting practices, and quality expectations.
- Continuous Improvement: Recommend governance improvements based on regulatory change, assessments, incidents, metrics, exceptions, and lessons learned.
Skills - Security Specific and People Skills
- Advanced knowledge of cybersecurity governance principles, operating models, and the relationship among Governance, Risk, and Compliance.
- Strong knowledge of ISO/IEC 27001 and 27002, ISO 62443, NIST Cybersecurity Framework, risk management practices, and relevant regulatory requirements.
- Experience developing policies, standards, governance procedures, exception processes, accountability models, and committee structures.
- Experience establishing KPIs, KRIs, dashboards, maturity measures, and executive cybersecurity reporting.
- Working knowledge of identity, data protection, third-party security, cloud, vulnerabilities, monitoring, incident management, resilience, acquisitions, and manufacturing or OT security.
- Excellent written, verbal, facilitation, negotiation, and executive presentation skills.
- Demonstrated people leadership, program management, prioritization, and change-management capabilities.
- Ability to influence stakeholders across a global, matrixed organization and escalate material issues appropriately.
Education and Experience Requirements
- Required: Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business, Risk Management, or a related field. Equivalent relevant education and experience may be considered.
- Required: 8+ years of progressive experience in cybersecurity, governance, technology risk, compliance, audit, or a related discipline.
- Required: 3+ years leading people, enterprise programs, or cross-functional governance initiatives.
- Required: Experience with policy management, committees, executive reporting, metrics, exceptions, management systems, or control accountability.
- Preferred: Experience supporting a global, matrixed, regulated, or manufacturing organization with enterprise IT and operational technology environments.
- Preferred: Experience with acquisition governance, third-party security, data protection, or manufacturing cybersecurity.
- Preferred: CISSP, CISM, CISA, CRISC, CGEIT, ISO/IEC 27001 Lead Implementer or Lead Auditor, or a comparable credential.
Jabil, including its subsidiaries, is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, age, disability, genetic information, veteran status, or any other characteristic protected by law.

