Garan logo

Cybersecurity & IT Compliance Manager

Garan

On-siteStarkville, MSseniorPosted 3h ago

Job description

Cybersecurity & IT Compliance Manager

Location: Starkville, Mississippi

Work Arrangement: Onsite, 5 days per week

The Opportunity

Garan, Incorporated is seeking a Cybersecurity & Compliance Manager to support and strengthen our day-to-day cybersecurity operations and compliance program. Reporting to the Head of Cybersecurity, this is a hands-on individual-contributor role with responsibility for security controls, threat response, vulnerability management, audit support, risk assessments, vendor security, and cybersecurity projects.

As a subsidiary of Berkshire Hathaway, Garan collaborates with the broader Berkshire Hathaway cybersecurity community. In this role, you will work closely with Garan’s IT teams, business stakeholders, executive management, auditors, third-party security providers, and Berkshire Hathaway technology and cybersecurity resources.

The successful candidate will combine strong technical cybersecurity expertise with sound judgment, disciplined execution, and the ability to communicate complex risks clearly to both technical and nontechnical audiences.

Responsibilities

  • Support daily cybersecurity operations and serve as a technical escalation resource for cybersecurity matters.

  • Implement, maintain, assess, and continuously improve security controls across identity, endpoints, cloud services, networks, applications, data, and enterprise systems.

  • Administer and strengthen Microsoft security technologies, including Microsoft 365, Entra ID, Defender, Intune, Conditional Access, multifactor authentication, and privileged access controls.

  • Monitor and investigate cybersecurity threats and coordinate incident response, containment, remediation, documentation, and lessons learned.

  • Coordinate vulnerability-management activities, including identification, risk-based prioritization, remediation tracking, exception management, and reporting.

  • Support internal and external cybersecurity audits through evidence collection, control validation, issue remediation, and compliance tracking.

  • Conduct cybersecurity risk assessments and maintain records of identified risks, corrective actions, owners, and target completion dates.

  • Evaluate cybersecurity risks related to vendors, cloud services, new technologies, system implementations, and significant technology changes.

  • Maintain cybersecurity policies, standards, procedures, control documentation, and supporting evidence.

  • Coordinate cybersecurity awareness and training activities.

  • Work with cybersecurity vendors, consultants, and SOC/MDR service providers to support effective service delivery.

  • Track and report cybersecurity metrics, projects, vulnerabilities, risks, audit findings, and remediation activities.

  • Communicate cybersecurity risks, incidents, and initiatives to executive management and nontechnical stakeholders in clear business terms.

  • Partner across IT and the business to complete cybersecurity projects and improve Garan’s overall security posture.

Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, or a related field—or equivalent professional experience.

  • At least 5 years of progressive experience in cybersecurity, information security, or a closely related field.

  • Strong working knowledge of identity and access management, endpoint security, cloud security, network security, vulnerability management, and incident response.

  • Hands-on experience with Microsoft 365 security, Entra ID, Microsoft Defender, Intune, Conditional Access, and multifactor authentication.

  • Experience supporting cybersecurity audits, compliance requirements, risk assessments, control testing, and remediation activities.

  • Working knowledge of recognized cybersecurity frameworks and practices, including the NIST Cybersecurity Framework and CIS Controls.

  • Experience coordinating technical projects and working across IT and business teams.

  • Strong analytical, problem-solving, documentation, and organizational skills.

  • The ability to translate technical risks and cybersecurity issues into clear, actionable information for executives and nontechnical stakeholders.

Preferred Qualifications

  • Experience with enterprise firewalls, email security, vulnerability-management platforms, privileged access management, SIEM, EDR/XDR, and SOC/MDR services.

  • Knowledge of Zero Trust architecture, public key infrastructure, data protection, cloud security, and SaaS security.

  • Experience working with cybersecurity vendors, consultants, auditors, or managed security providers.

  • CISSP, CISM, CRISC, CCSP, GIAC, Microsoft security certification, or a comparable professional credential.

Additional Requirements

  • This position is based onsite at Garan’s Starkville, Mississippi location five days per week.

  • Relocation assistance is not available.

  • Occasional travel to other company locations may be required.

  • After-hours or weekend availability may be required for significant incidents, critical changes, or other business needs.

Why Garan

This position offers the opportunity to work across a broad cybersecurity environment while gaining exposure to the Berkshire Hathaway cybersecurity community. You will play a visible role in protecting the business, improving security controls, managing cybersecurity risk, and advancing Garan’s security capabilities.

Garan, Incorporated is an equal opportunity employer. Employment decisions are made without regard to legally protected characteristics and in accordance with applicable federal, state, and local laws.