Skip to content

Open nowPosted 26 days ago

Cybersecurity & IT Compliance Manager

Workable (global search)108,016 open roles

Where
Starkville, MS, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity & IT Compliance ManagerWorkable (global search) · Starkville, MS, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 26 days ago

Workable (global search) median: 7 days open

The posting

Cybersecurity & IT Compliance Manager

Location: Starkville, Mississippi Work Arrangement: Onsite, 5 days per week

The Opportunity

Garan, Incorporated is seeking a Cybersecurity & Compliance Manager to support and strengthen our day-to-day cybersecurity operations and compliance program. Reporting to the Head of Cybersecurity, this is a hands-on individual-contributor role with responsibility for security controls, threat response, vulnerability management, audit support, risk assessments, vendor security, and cybersecurity projects.

As a subsidiary of Berkshire Hathaway, Garan collaborates with the broader Berkshire Hathaway cybersecurity community. In this role, you will work closely with Garan’s IT teams, business stakeholders, executive management, auditors, third-party security providers, and Berkshire Hathaway technology and cybersecurity resources.

The successful candidate will combine strong technical cybersecurity expertise with sound judgment, disciplined execution, and the ability to communicate complex risks clearly to both technical and nontechnical audiences.

Responsibilities

  • Support daily cybersecurity operations and serve as a technical escalation resource for cybersecurity matters.
  • Implement, maintain, assess, and continuously improve security controls across identity, endpoints, cloud services, networks, applications, data, and enterprise systems.
  • Administer and strengthen Microsoft security technologies, including Microsoft 365, Entra ID, Defender, Intune, Conditional Access, multifactor authentication, and privileged access controls.
  • Monitor and investigate cybersecurity threats and coordinate incident response, containment, remediation, documentation, and lessons learned.
  • Coordinate vulnerability-management activities, including identification, risk-based prioritization, remediation tracking, exception management, and reporting.
  • Support internal and external cybersecurity audits through evidence collection, control validation, issue remediation, and compliance tracking.
  • Conduct cybersecurity risk assessments and maintain records of identified risks, corrective actions, owners, and target completion dates.
  • Evaluate cybersecurity risks related to vendors, cloud services, new technologies, system implementations, and significant technology changes.
  • Maintain cybersecurity policies, standards, procedures, control documentation, and supporting evidence.
  • Coordinate cybersecurity awareness and training activities.
  • Work with cybersecurity vendors, consultants, and SOC/MDR service providers to support effective service delivery.
  • Track and report cybersecurity metrics, projects, vulnerabilities, risks, audit findings, and remediation activities.
  • Communicate cybersecurity risks, incidents, and initiatives to executive management and nontechnical stakeholders in clear business terms.
  • Partner across IT and the business to complete cybersecurity projects and improve Garan’s overall security posture.

Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, or a related field—or equivalent professional experience.
  • At least 5 years of progressive experience in cybersecurity, information security, or a closely related field.
  • Strong working knowledge of identity and access management, endpoint security, cloud security, network security, vulnerability management, and incident response.
  • Hands-on experience with Microsoft 365 security, Entra ID, Microsoft Defender, Intune, Conditional Access, and multifactor authentication.
  • Experience supporting cybersecurity audits, compliance requirements, risk assessments, control testing, and remediation activities.
  • Working knowledge of recognized cybersecurity frameworks and practices, including the NIST Cybersecurity Framework and CIS Controls.
  • Experience coordinating technical projects and working across IT and business teams.
  • Strong analytical, problem-solving, documentation, and organizational skills.
  • The ability to translate technical risks and cybersecurity issues into clear, actionable information for executives and nontechnical stakeholders.

Preferred Qualifications

  • Experience with enterprise firewalls, email security, vulnerability-management platforms, privileged access management, SIEM, EDR/XDR, and SOC/MDR services.
  • Knowledge of Zero Trust architecture, public key infrastructure, data protection, cloud security, and SaaS security.
  • Experience working with cybersecurity vendors, consultants, auditors, or managed security providers.
  • CISSP, CISM, CRISC, CCSP, GIAC, Microsoft security certification, or a comparable professional credential.

Additional Requirements

  • This position is based onsite at Garan’s Starkville, Mississippi location five days per week.
  • Relocation assistance is not available.
  • Occasional travel to other company locations may be required.
  • After-hours or weekend availability may be required for significant incidents, critical changes, or other business needs.

Why Garan

This position offers the opportunity to work across a broad cybersecurity environment while gaining exposure to the Berkshire Hathaway cybersecurity community. You will play a visible role in protecting the business, improving security controls, managing cybersecurity risk, and advancing Garan’s security capabilities.

Garan, Incorporated is an equal opportunity employer. Employment decisions are made without regard to legally protected characteristics and in accordance with applicable federal, state, and local laws.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.