Job Description:
Reporting to the Director, IT Governance, Risk & Compliance, the GRC Manager is responsible for leading governance and compliance initiatives across all properties and the home office, ensuring alignment with privacy regulations, PCI requirements, and internal policies. The ideal candidate will have experience operating in a global enterprise with complex, cross‑functional dependencies, preferably within hospitality or retail PCI environments where multiple locations across various geographic locations and time zones rely on a centralized GRC team for compliance support and guidance. This includes coordinating evidence collection, managing compliance activities across distributed locations, and ensuring consistent adherence to PCI DSS controls. The role requires strong capabilities in PCI, IT, and cybersecurity risk management, including the ability to assess, identify, track, and mitigate risks across diverse business units and operational areas. The GRC Manager should also be skilled in developing risk remediation plans, driving them to completion, and maintaining ongoing compliance in environments. This includes leveraging GRC tooling such as ServiceNow to support workflow management, helpdesk operations, incident and request tracking, evidence collection, and dashboard reporting, as well as demonstrating strong proficiency in the Microsoft Office suite to produce clear documentation, reporting, and stakeholder communications. The primary focus of this role is leading and maintaining PCI Home Office compliance, ensuring continuous alignment with PCI DSS requirements and internal standards. The role also encompasses managing and supporting compliance activities across properties globally, overseeing helpdesk GRC requests, onboarding new properties and teams, delivering targeted training sessions, and maintaining accurate, up‑to‑date compliance statistics and documentation. This position provides broad exposure to current and future GRC initiatives and plays a critical role in sustaining the organization’s overall IT governance, risk, and compliance posture.