We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Manager, Governance Risk and Compliance

Harley-Davidson Motor Company
401(k), relocation assistance
United States, Wisconsin, Milwaukee
Aug 28, 2026

Auto req ID: 59839
Title:Manager, Governance Risk and Compliance
Job Function:Information Technology
Location:JUNEAU
Workplace Category: Onsite
Company:Harley-Davidson Motor Company
Full or Part-Time:Full Time
Shift:SHIFT1

In 1903, out of a small shed in Milwaukee, Wisconsin, four young men lit a cultural wildfire that would grow and spread across geographies and generations. Their innovation and imagination for what was possible on two wheels sparked a transportation revolution that would make Harley-Davidson the most recognizable motorcycle brand in the world. Today, we continue to define motorcycle culture, evoking soul-stirring emotion reflected in every product and experience we deliver - like we have for well over a century and will for generations to come. Are you ready to ride with us?

Harley-Davidson Motor Company, founded in a humble Milwaukee backyard shed in 1903, still calls the city home. Today, its Corporate Campus includes a 4.8-acre public park-a welcoming greenspace open to all. Join our team as aMgr Governance Risk and Compliance.

Job Summary

The Manager of Harley-Davidson, Inc's Technology Governance, Risk and Compliance (GRC) reports to the Chief Information Security and Privacy Officer and leads Harley-Davidson's global information risk management and IT compliance program. The GRC leader is accountable for overseeing and coordinating the IT and cybersecurity program objectives needed to achieve and maintain HDI's compliance with regulatory requirements. The position serves as a key interface among internal and external compliance bodies, auditors, technology teams, and business functions to ensure HDI's IT general control environment is documented and operating effectively, and that information risks are reported to management for decision-making and action when necessary.

Job Responsibilities



  • Build and maintain strong business partnerships across key areas at a senior leadership level, bridging their understanding of GRC concepts and requirements with an understanding of regional and global business practices
  • Develop and implement processes to map IT general controls to established GRC standards and frameworks enabling efficient monitoring and reporting of regulatory compliance and risks.
  • Oversee audit testing of general IT controls, report on identified exceptions and deficiencies, guide the development of management action plans and escalate priority issues.
  • Manage and facilitate a secured process for all HR/Legal/Ethics IT/Security-related Investigations
  • Work with IT Senior Leadership to identify, assess, and bring visibility to the most significant IT security risks across the GIS organization while ensuring the appropriate resources are assigned to remediate risks.


Education Requirements



  • High School Diploma or Equivalent Required



Education Specifications



  • Bachelor's Degree in business management, information systems or a related discipline
  • Master's Degree in related field is Preferred
  • Industry-recognized certification such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent is preferred



Experience Requirements

Required



  • Typically requires a minimum of 8 years of related experience.
  • Subject matter expert in IT compliance and auditing frameworks, practices, policies, standards, and procedures:

    • Sarbanes-Oxley Act of 2002 (SOX)
    • Control Objectives for Information and Related Technologies (COBIT)
    • National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
    • System and Organization Controls (SOC) 1 and 2
    • Payment Card Industry Data Security Standard (PCI DSS)
      ISO 27001/2, or equivalent
    • Three Lines of Defense Model


  • Demonstrated experience working in an enterprise-level Information Security
  • Office with global accountabilities. Direct experience leading GRC processes with business leaders and managers.
  • Ability to define and establish comprehensive procedures that integrate with key business processes to ensure cybersecurity standards and best practices are part of compliance and risk management by design
  • Excellent communication and presentation skills with demonstrated skill in presenting complex detail around regulations clearly and to a variety of audience members
  • Familiarity with data flows and experience with scoping general IT controls to applicable compliance requirements.
  • Experience participating in or overseeing Third Party Risk Management (TPRM) programs, supplier risk assessment processes and vendor scorecards.
  • Proven ability to develop frameworks, strategies and roadmaps and to provide direction across all areas of accountability as well as to work closely with the
  • Corporate Information Security Office (CISO) organization where dependencies exist
  • Strong leadership, organization, communication, and process management skills; ability to lead and manage high-performing teams, and an ability to develop a continuous improvement mentality in all operational activities



Preferred



  • Experience in building and leading a team with a proven ability in developing capabilities, attracting and retaining a core team of collaborative professionals and creating an organization viewed as a highly attractive place to work.
  • Understanding of Payment Card Industry Data Security Standards (PCI DSS) Compliance requirements, the Attestation process, and working with business leaders to redesign business processes as needed



The pay range shown represents the national average pay range for this role. Your pay may be more or less than the stated range and is dependent on your geographic location and level of experience.

We offer an inclusive compensation package for all full-time salaried employees including, but not limited to, annual bonus programs, health insurance benefits, a 401k program, onsite fitness centers and employee stores, employee discounts on products and accessories, and more. Learn more about Harley-Davidson here.

Applicants must be currently authorized to work in the United States.

Direct Reports: Yes
Travel Required: 0 - 10%
Pay Range:$138,100 - $220,900

Visa Sponsorship: This position is not eligible for visa sponsorship or visa transfer
Relocation: This position is eligible for domestic relocation assistance (within posted country)


Applied = 0

(web-665cd84569-mqxkc)